Risk
7/13/2010
01:10 PM
50%
50%

Social Networking Weakens Enterprise Security

Trend Micro survey finds 24% of employees access social networks from their business computers.

A new study finds that the use of social networking in the workplace has risen from 19% in 2008 to 24% in 2010, with the biggest surges coming in Germany and Britain.

That finding comes from a Trend Micro survey of 1,600 people who regularly use the Internet at work, drawn equally from Germany, Japan, the United Kingdom, and the United States.

Using social networking tools at work isn't the only quasi-personal-time activity on the rise. Comparing the 2010 survey results with a similar Trend Micro survey conducted in 2008, workers in the United States are now 66% more likely to write personal e-mails at work, 39% more likely to conduct personal banking or online bill-paying, and 29% more likely to watch or listen to streaming audio or video.

But in a good turn for information security, the study also found that from 2008 to 2010, workers in all countries but Japan were also much less likely to download executable files onto their business PC.

At the same time, however, laptop users now appear to be practicing risky information protection habits. According to the Trend Micro study, "for all countries surveyed in 2010, laptop users who can connect to the Internet outside of company network are more likely to share confidential information via instant messenger, webmail, and social media applications than those who are always connected to a company's network."

Perhaps that's because employees' Internet habits apparently differ when they're connected to the corporate LAN at work, versus on the go. For example, laptop users are much more likely than desktop users to visit social networking sites. From 2008 to 2010, social networking usage via laptops increased by 10% in the United States. For desktop users, however, rates stayed about the same.

What should organizations do about safeguarding social networking use, especially in light of laptop users' more risky habits?

In general, security experts recommend that rather than blocking social networking sites outright, organizations create security policies governing their use, and then monitor and enforce those polices to safeguard employees as well as sensitive data.

According to the Trend Micro study, "trying to just prevent users accessing social networks from work could potentially increase the risk to an organization, as users look for ways around computer security, possibly increasing the chance of exposure to security threats."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2382
Published: 2014-11-20
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.

CVE-2014-3625
Published: 2014-11-20
Directory traversal vulnerability in Pivitol Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVE-2014-8387
Published: 2014-11-20
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

CVE-2014-8493
Published: 2014-11-20
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

CVE-2014-8767
Published: 2014-11-20
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR frame.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?