Instant messaging
Enterprises must have the ability to log, archive and retrieve IM communications

Enterprises urged to plug IM security holes

A quarter of all staff admit to sending sensitive material by IM

Written by Clement James

One in four employees has used instant messaging to send information about company plans, finances or password/login credentials, security experts have warned.

FaceTime Communications said that enterprises need to wake up to the use of real-time communications in the workplace and ensure that they have the ability to log, archive and retrieve the communications.

Advertisement

A review of thousands of pages of IM conversations in the recent Société Générale trading scandal revealed that the rogue trader may not have acted alone.

The reports note that much of the trading scheme was discussed over instant messaging, as opposed to more traditional email channels. Société Générale's ability to retrieve these messages provided a clear trail for investigators.

"The financial sector has long led the way in the use of technology, and its adoption of instant messaging is no exception," said Nick Sears, EMEA vice president at FaceTime.

"Employees frequently believe that their IM conversations are private, as the Société Générale case shows.

Employees frequently believe that their IM conversations are private

Nick Sears EMEA vice president, FaceTime Communications

"By and large the employees are correct as many businesses do not even recognise that real-time communications are being used on their systems, let alone monitor it."

FaceTime added that IM is not the only real-time communication tool that organisations should be wary of when it comes to information leakage and employee collusion.

"Even if you ignore the fact that you cannot scan for malware using traditional security tools, encrypted VoIP is still a major headache for companies in terms of data leakage," said Sears.

"It is not just conversations that go unmonitored. Most VoIP clients allow you to exchange files too, allowing confidential documents to slip easily in and out of the organisation before you can say 'regulatory investigation.'"

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

21 Nov 2008

9.11 MBPodcast Special: Views from the Valley More...

Podcast

20 Nov 2008

9.43 MBComputing podcast: Europol's data sharing woes; credit card protection at Cotton Traders More...

Shaun Nichols and Iain Thomson

14 Nov 2008

7.73 MBPodcast Special: Views from the Valley More...

Poll

Data breaches

Data breaches

What is the best way to ensure firms take data breaches seriously?

Previous poll results

Spotlight

Google Chrome

Google may pre-install Chrome browser

Search giant investigating OEM deals   More...

phil muncaster

Video: vnunet.com weekly debrief

Phil Muncaster and BusinessGreen.com editor James Murray discuss the week's...  More...

Ofcom HQ

UK leading European technology charge

Ofcom report reveals convergence trend   More...

CA World 2008

vnunet.com analysis: CIOs outline IT spending priorities

IT chiefs advise looking for high-value projects rather than suspending...  More...

Primary Navigation