In a white paper released last November by RSA, research from ordinary person-on-the street interviews with random office workers revealed troubling trends for those concerned with information security. Sometimes in an honest effort to finish their work from home or while traveling, sometimes through simple carelessness, but in either case without intending to put secure information at risk, employees from all sectors of the workplace admitted to behaviors which do, in fact, put secure information at risk.
In interviews conducted in Boston and Washington, D.C., employees from both the public and the private sector answered "frequently," "sometimes," or "never" to questions probing their own customary behavior and also to questions asking what they had observed in their workplace. Employers with international networks full of proprietary and confidential private information, including social security numbers and other personally identifying information, were reported by nearly 20% of private enterprise employees as routinely leaving networks set up for conference room and guest use open and available, without a password, to anyone who might walk in.
Employees themselves, with their own logins and passwords, accessed their work-network at home, in airports, in hotel and restaurant hot-spots, and even, at times, on public access hotel or internet cafe-type computer terminals. In fact, the number of workers who retrieved their work e-mail from a public access computer was slightly higher than the number who used their own laptop but at a public wireless hotspot. Both numbers, however, were over 50%. Since well over 80% of workers reported that they "frequently" or "sometimes" conduct business over some kind of network away from their workplace, one can conclude that perhaps 30% of employees access work from a home computer, either by modem high speed internet connection.
More knowledge of security protocols will not solve the problem, according to RSA. Almost all employees confirm that they have been trained in their employer's security policies and that they are familiar with those policies. Nevertheless, they hold doors to secure areas open for persons they don't recognize, they notice people they don't know working in empty offices without comment, and they find themselves with access to parts of the network they know they have no need to see.
Perhaps most troubling, a full third of all employees surveyed answered "yes" to the question, "Do you ever feel that you need to work around your company's established security policies and procedures just to get your job done."
RSA concluded its report, provocatively titled "The Confessions Report," with a summary of its findings and a set of "Recommendations for Managing Information Risk." The recommendations call for a "holistic, information-centric security strategy [that] takes people, processes and technology into account and has a feedback mechanism." Clearly, an alert has been sounded.
Christopher is an Information Security Consultant for Lexan Systems LLC. You are welcome to reproduce this article on Computer Security related web site, as long as you reproduce the article in full, including this resource box and link to our website.
We all understand what it is like to have our secrets spread far and wide when we do not want them to be. Indeed, for companies, this is a much worse situation since their secrets could cost them a lot of income in the end. What some companies are doing nowadays is to get security certification so that employees realize that they should not talk too freely about what goes on at work, and should also not gossip across departments either. Security training covers all kinds of aspects and this is very serious business indeed.
Most companies will be connected to the internet via desktop computers throughout the different departments. However, in these days of cyber hacking, it is a dangerous idea to think that no one is spying on what the company does. Sensitive information is very easy to glean if firewalls and other safety measures are not in place.
This becomes very apparent when a company is developing some new gadget or idea which they usually spend enormous amounts of money on. All it takes is an information leak, from unruly employees or clever hackers, and the company could lose out on the income that this new idea should have generated. Therefore, all key personnel should be trained to not leak information to anyone, not even people that they know well.
The media is very often the culprit when information is leaked. They just love to spread scandals about the place, if stories in the press are to be believed. They usually pay big money for such stories too since this is what makes people buy the newspapers so it is well worth the risk when spies want to make some cash. This could well be stories of a personal nature or secrets that the company will certainly not want to leak out. For example, some companies will dispose of waste materials in the wrong fashion just to save cash and this they like to keep under cover. However, this is possibly illegal and this is just the type of scandal that the media pays big bucks for.
It is clear then that most companies have secrets, legal or illegal, that they want to keep to themselves. Of course, most companies have the scruples not to get mixed up in illegal actions, so it is these which value their privacy in connection to new products etc which are about to hit the market.
This third-party company will come in and monitor the flow of information from one department to another, and how each individual section of the workforce handles the information that pertains to them. Since most departments do not really need to know what goes on elsewhere in the company, it may be a good idea to keep them in the dark about what goes on elsewhere. By clamping down on gossip and cross talking between departments, the company has at least a chance of keeping new products under cover until the launch date arrives which will certainly make it the market leader for this particular product.
Stewart Wrighter recently studied new security certification sites online while conducting research for an article. He also studied new security training sites online while conducting research for an article.