Advertisement
Promo

Security threats Toolkit

Businesses failing to understand Web 2.0 risks

Julian Goldsmith silicon.com

Published: 01 Feb 2008 09:03 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Web 2.0 presents a barely understood risk to companies embracing social-networking and instant-messaging technology as business tools, and could force a change in corporate IT security and greater use of encryption.

Almost two-thirds (65 percent) of US companies do nothing to block third-party collaboration tools, such as real-time communications and information sharing, according to research from Yankee Group.

Tom Raschke, senior analyst at Forrester Research, said 25 percent of US chief information officers in a recent survey admitted adoption of Web 2.0 tools would be a priority in 2008, even though the strategy could potentially increase areas of attack and infrastructure complexity, in addition to the fact that the return on investment is not clear.

Raschke warned that traditional security tools, such as firewalls, do not go deep enough into rich content to determine whether it is a security risk — either incoming, as malware, or outgoing, as data leakage.

Essentially, what is needed is a shift in focus from securing the infrastructure through which data moves to securing the data itself, said Raschke.

The group head of information security at Standard Chartered Bank, John Meakin explained that the banking industry is embracing Web 2.0 tools in two ways.

Read this

Feature
Feature: Cracking open the cybercrime economy

Hacking for fun has evolved into hacking for profit, and created a business model that is nearly as sophisticated as that of legal software

Read more +

Externally, banks are responding to customer demands that interactions with their bank mirror the other interactions they are used to on the internet. Internally, banks are using Web 2.0 tools to communicate and collaborate across their large organisations and many business units spread around the globe.

Meakin told silicon.com: "Banks are under pressure to operate more efficiently. Web 2.0 applications help people collaborate, which, as businesses, we would be foolish to look away from. At the same time, we have to be clear we are not introducing risk into the process; our businesses are based fundamentally on trust."

Meakin noted that embracing Web 2.0 tools may mean competitive data residing outside the organisation.

Meakin said: "Banks will have to make sure they haven't lost complete control over the integrity of their data if they use Web 2.0. One way to do this is to make sure the data is encrypted. This is a limited solution because it doesn't take into account the way the security status of data can change. Financial reports, for instance, are sensitive until the day they are announced, when they [enter the] public domain. A better approach is to make sure that, even if data is accessed through something like Facebook, the data still resides within your organisation."

Meakin and Raschke were speaking at a seminar attended by financial analysts and global banks, and organised by security specialist WorkLight.

Credit: Web 2.0 security risks being ignored from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters