Advertisement
Promo

Security threats Toolkit

CIOs 'recognising the threat of IM'

Munir Kotadia ZDNet Australia

Published: 17 Feb 2005 12:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The recent flaw plugged by Microsoft in its MSN Messenger software highlights a serious security threat to enterprise security, according to analysts.

Last Friday, Microsoft forced its millions of MSN Messenger users to download a new version of the software to plug a security vulnerability. The mandatory upgrade began after a security company posted information that would help a would-be attacker exploit the vulnerability. MSN Messenger users were then greeted with a notice to upgrade before they could open their instant messaging clients.

Analyst firm Gartner commended Microsoft for acting so quickly to control the problem by locking out vulnerable clients but it warned that future threats may not be so easily dealt with and enterprises may have to take the matter into their own hands.

"Next time an IM exploit emerges, Microsoft or another IM provider may not be able to respond as quickly or as effectively. Enterprises must take responsibility for ensuring that the use of IM does not compromise their security. If necessary, they must be able to temporarily shut it down when a serious security threat emerges," said Gartner analyst Lawrence Orans in an advisory.

Foad Fadaghi, senior industry analyst at Frost & Sullivan Australia, said that although some companies have set up security policies for IM, many have got so comfortable using the free consumer version they could find themselves in trouble if they are forced to shut the service down because of security issues.

"A lot of companies have left themselves quite exposed by using public IM software but as you see more threats happening to IM, more companies are setting up policies and secured systems. However, IM is a primary communications method and if they start talking about turning it off they will damage their business," said Fadaghi.

Fadaghi said one good thing to come from the MSN Messenger vulnerability is that the security threat from IM has been highlighted.

"It wasn't on the list of things that the CIO was worried about. If anything, the CIOs out there may now start seeing IM as a serious threat to corporate security," said Fadaghi.

Gartner’s Orans said that IM’s popularity is making it unrealistic for a company to block the service completely, which leaves administrators with a number of options.

"In many enterprises, one or more business units can make a compelling case for the need to use IM. Enterprises have three options: implement an enterprise IM solution, deploy a solution that makes it possible to build policies around public IM services, or do both," said Orans.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
77 out of 158 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters