You are here: silicon.com > Software > Security Strategy

Security Strategy

City banks fail security test

Using IM and turning a blind eye to compliance...

Tags: compliance, sarbanes-oxley, im

By Will Sturgeon

Published: 28 July 2004 14:05 BST

A large number of financial institutions in the City are failing to tighten their security policies to rule out the threat from instant messaging and compliance failure.

More than half (54 per cent) of the execs from City businesses surveyed at a recent Microsoft and FaceTime enterprise IM event said their organisations are using IM and yet almost half of those (46 per cent) said they could not vouch for who was using it, or what they were using it for.

IM provides one of the most direct routes onto the desktop and evades many defences, such as the corporate firewall. It currently provides one the biggest security headaches for system administrators and is one of the greatest 'unknown quantities' in terms of network security. Users could be introducing spyware, viruses or other illegal content, such as copyrighted material, onto their work PCs and onto the network without the IT department and bosses being aware of it.

Many companies using IM are also still failing to heed warnings about the use of consumer applications that offer insubstantial audit trails, archiving and security measures - which are soon to be a requirement of compliance laws such as Sarbanes-Oxley.

Speaking to silicon.com earlier this year about the issue of compliance, Kailash Ambwani, CEO of secure IM provider FaceTime, said: "IM is mission critical to these guys, but they don't normally have in place the necessary security, accountability, logging or archiving to make those IM sessions compliant."

Of those organisations surveyed that use IM, 63 per cent said they use consumer applications from the likes of AOL, MSN and Yahoo!

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...

Security/Quality Analyst-00055189

Quality Coordinate Accentures IT Sarbanes Oxley compliance and provide the client with support as appropriate. Quality Act as the primary point of ...

Quality Lead - Unilever - Level C-00055185

The Quality and Process Improvement programme (QPI), Sarbanes Oxley (SOX) Compliance and Security are highly visible subject matter on this ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: