Advertisement
Promo

Online business Toolkit

Instant messaging could land bosses in jail

Dan Ilet ZDNet.co.uk

Published: 15 Oct 2004 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK companies are fretting that employees using IM applications could be breaking compliance laws.

Lawyers said this week that more companies are consulting them over the use of IM because they are unsure of its legal implications.

"People are coming to us worried about it," said Mark Smith, a solicitor for Olswang. "There are two problems -- unauthorised use of IM, and from a legal perspective all the [compliance] issues that apply to email apply to IM too."

Many companies use IM in the belief that it is exempt from compliance laws, such as Sarbanes-Oxley and Basel II. These regulations demand that companies store all their data for at least seven years. If companies fail to deliver on the regulations, chief executive officers and chief financial officers could be liable to go to jail.

"A lot of employees use it [IM] as a way of communicating without using the content filters," said Smith. "Because IM is more informal than email, people say things on it they sometimes shouldn't. Where corporations use it, if they don't have the correct system implemented, there are loads of issues with monitoring and retention of data."

Smith added that security testers have discovered hundreds of unauthorised IM clients running on some corporate networks.

IM runs over port 80, the default channel for Web traffic. This often regarded as a trusted port and left open to allow users to surf.

"People use IM as a way of getting stuff in and out of the business, bypassing the security infrastructure," said Jason Hart, security director for Whitehat UK. "It's easy to run it without anyone knowing about it and people often use it as a way of getting around compliance laws."

Hart said that 40 percent of firms have banned the use of IM. "But that doesn't guarantee that people won't use it. It causes time-wasting viruses, possible use of spyware and cannot be detected by most firewalls."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
105 out of 182 people found this useful


Full Talkback thread

1 comment

  1. What a strangely paranoid perspective on such an i... Dennis B. Smith

Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters