Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Employees Still Flouting Security Policies, Study Says

Three in 10 enterprises say their business' security is being compromised by personal use of corporate systems

Sep 22, 2008 | 05:25 AM

By Tim Wilson
DarkReading

Many companies believe their data is at risk because they can't stop employees from using unauthorized Web services and applications, according to a study published today.

Three out of 10 organizations report that their business' Web security has been compromised by employees' use of personal Webmail accounts, social networking sites, and online video, according to Webroot, the security software vendor that conducted the research.

More than a third of respondents estimate that employees spend more than an hour a day on non-work-related sites, according to the study. Only 15 percent of the 648 companies surveyed gave their enforcement of Internet usage policies an "A" on a conventional "report card" grading scale.

"Businesses are taking measures to protect against email-based threats, but they are not yet attuned to the greatest threat vector today: Web-based threats driven by employee Web use," says Mike Irwin, COO of Webroot. "We found that Web-borne malware increased over 500 percent in 2007, as cybercriminals developed new ways to attack on-site and remote employees through personal Web mail accounts, social networking sites and other Web 2.0 applications."

One out of four businesses reported that a Web-based threat had compromised their confidential information, threatened online transactions, or caused a Web server outage. Yet nearly 30 percent of those surveyed said they did not know whether their organization or its employees are using Web 2.0 applications.

— Tim Wilson, Site Editor, Dark Reading

  • Webroot Software Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)