Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/15/2010
08:23 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Industry Poll Shocker: Employees Bypass IT Policies

A poll released today by Harris Interactive found that a good portion of workers admit that they knowingly violate IT policies so that they can get their work done. My take: those workers that didn't admit that they violate corporate compliance and security policies are liars.

A poll released today by Harris Interactive found that a good portion of workers admit that they knowingly violate IT policies so that they can get their work done. My take: those workers that didn't admit that they violate corporate compliance and security policies are liars.According to the poll of 1,347 employed adults ages 18 and up showed that 12 percent admitted to breaking policy. The poll was conducted online by Harris Interactive between February 2 and 4, and funded by mobility service provider Fiberlink.

Here's the quote from CEO of Fiberlink, from the company's statement announcing the poll:

"We see this as a mobility wake-up call for all IT managers," said Jim Sheward, CEO of Fiberlink. "IT departments nationwide spend a lot of time and money on their compliance, usage, and access policies, but they only work if people follow the rules. Without extensive and effective compliance tools that ensure that IT policies are being followed, companies could face dangerous breaches that include the loss of sensitive data, competitive intelligence, or customers' private information."

First, these poll results could apply to just about any IT security and policy compliance issue: passwords, encryption, rogue wireless access points, shutting down anti-malware when it becomes inconvenience, and the list goes on. But Fiberlink sells mobility management services, so that's their spin. Too bad the poll (or at least it wasn't communicated in the release) didn't focus on actual mobile compliance issues.

Second, enterprises need to spend on the controls that make the most sense for their tolerance to risk and need to mitigate that risk.

Third, Sheward was too tame in one of his remarks: enterprises that rely too heavily on their employees to make the right decisions when it comes to security and compliance will lose sensitive data, intelligence, customers' private information, or suffer some significant incident. It's really just a matter of time.

I think the 88 percent of respondents who said they don't bypass policies to get work down are either lying outright, or are fooling themselves. Who hasn't broken a corporate policy to expedite workflow?

Such things could include using a simpler password that is more easily remembered, or even writing down a complex password on paper. It could include copying unencrypted data to a USB drive, using home PCs to work on company files, using wireless connections with their corporate issued notebook. Users who click on links or open attachments from people they don't know, or access certain Web sites are probably violating policy. And the list could go on indefinitely. While few break all of the rules all of the time, fewer still follow all of the rules all of the time.

That's why companies that rely on end users to do the right thing and always follow security policy are heading for trouble. A certain percentage of users, no matter how small it is, will click on links they shouldn't, they'll visit Web sites they shouldn't, they'll use passwords they know are inadequate, and they'll check e-mail from the corner coffee shop wireless connection.

All of those actions jeopardize not only the end user doing them, but the security and compliance posture of the entire organization. And enterprises that don't use technological controls to thwart these behaviors are just asking for trouble.

For my security and technology observations throughout the day, follow me on Twitter.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.