ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Instant messaging could land bosses in jail

Dan Ilet ZDNet.co.uk

Published: 15 Oct 2004 13:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK companies are fretting that employees using IM applications could be breaking compliance laws.

Lawyers said this week that more companies are consulting them over the use of IM because they are unsure of its legal implications.

"People are coming to us worried about it," said Mark Smith, a solicitor for Olswang. "There are two problems -- unauthorised use of IM, and from a legal perspective all the [compliance] issues that apply to email apply to IM too."

Many companies use IM in the belief that it is exempt from compliance laws, such as Sarbanes-Oxley and Basel II. These regulations demand that companies store all their data for at least seven years. If companies fail to deliver on the regulations, chief executive officers and chief financial officers could be liable to go to jail.

"A lot of employees use it [IM] as a way of communicating without using the content filters," said Smith. "Because IM is more informal than email, people say things on it they sometimes shouldn't. Where corporations use it, if they don't have the correct system implemented, there are loads of issues with monitoring and retention of data."

Smith added that security testers have discovered hundreds of unauthorised IM clients running on some corporate networks.

IM runs over port 80, the default channel for Web traffic. This often regarded as a trusted port and left open to allow users to surf.

"People use IM as a way of getting stuff in and out of the business, bypassing the security infrastructure," said Jason Hart, security director for Whitehat UK. "It's easy to run it without anyone knowing about it and people often use it as a way of getting around compliance laws."

Hart said that 40 percent of firms have banned the use of IM. "But that doesn't guarantee that people won't use it. It causes time-wasting viruses, possible use of spyware and cannot be detected by most firewalls."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
104 out of 180 people found this useful


Full Talkback thread

1 comment

  1. What a strangely paranoid perspective on such an i... Dennis B. Smith

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Quality Lead - Unilever - Level C-00055185

Quality Lead - Unilever - Level C-00055185 Description Quality Lead Port Sunlight, Wirral, Cheshire Up to 42,000 plus comprehensive benefits This is ...

SAN Systems Administrator

Storage Management Team Responsibilities:- SAN Configuration Zoning / Masking / Switch & port configuration Storage Allocation Port allocation ...

Enterprise Applications Finance Oracle - Manager - London

We provide consultancy services to some the strongest brand names globally, plus a variety of small and dynamic mid-market firms. Job Title: ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains