ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Consumer-tech use threatens corporate security

Andy McCue silicon.com

Published: 18 Jun 2007 08:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The use of consumer-based technology such as web email, instant messaging, smartphones and games consoles by employees is one of the most significant threats to corporate IT security.

Analyst companies Forrester and Gartner have both warned this week that the entrance of consumer technologies into the enterprise is impossible to eliminate and challenges traditional security models.

Consumer-based communications tools such as Hotmail, instant messaging and VoIP are used by most employees, often from work and also as a way to transfer work materials to and from their PCs at home.

In a report, Gmail, iPhones and Wiis: Preparing Enterprise Security for the Consumerisation of IT, Gartner research vice president Rich Mogull said: "Most organisations will find themselves unable to completely block these services, for cultural, if not technical reasons, but security options are available to limit the risks that consumer communications services create."

Blogs, social-networking tools and other Web 2.0 technologies are another risk for information leaks or as channels for malicious software and viruses.

Gartner advises organisations to configure content management and data loss prevention tools to monitor and block the release of sensitive content over HTTP and peer-to-peer network traffic and also configure the web gateway to block any services such as social networking not deemed suitable in the workplace.

The emergence of increasingly sophisticated media-centric consumer mobile handsets such as the iPhone can also be managed without a complete enterprise ban.

Security options for these devices include restricting the ability for unapproved devices or storage to connect to managed PCs and laptops, deploying an SSL (secure sockets layer) VPN to enable secure thin-client remote access to enterprise systems, and encrypting all approved mobile devices with access to sensitive data in case of loss or theft.

Forrester senior analyst Bill Nagel, speaking at the Forrester IT Forum in Edinburgh this week, added: "Not all information needs to be protected. Only put high-levels of security around data you cannot afford to lose. Consumer technology is very useful and is not going to go away."

Forrester highlighted Bluetooth, insecure home wireless networks and "evil twin" malicious public Wi-Fi hotspots as particular security risks to corporate IT security.

Nagel said: "Bluetooth is a security nightmare. Bluetooth traffic is rarely encrypted. One big problem is people just leave the security enabled by the phone, which is usually nothing. It is very easy to sniff Bluetooth traffic."

But Forrester said the use of consumer-based technology by employees also has many advantages and can lead to equipment cost savings, better backup of corporate data, more flexible work conditions and improved collaboration.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

248980JD Messaging Engineer Poole, Dorset

248980JD Messaging Engineer Poole, Dorset We are looking for a Messaging Analyst to work in the Messaging and Collaborative Services team. They ...

Server Support - AD, Exchange, Messaging, IIS, SAN, , Essex 45k

Server Support - AD, Exchange, Messaging, IIS, SAN,SQL Clustering Essex 45k My UK market-leading client is looking to recruit a Server Engineer to be ...

2nd/3rd Line Messaging Specalist East London Contract

My client requires someone urgently to with strong Messaging Experience at Commercial level. Rates ranging from 17-25 per hour pendant on experience ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation