
Like we didn't already know...
Published: 16 February 2006 09:45 GMT
An experiment carried out within London's square mile has revealed that employees in some of the City's best known financial services companies don't care about basic security policy.
CDs were handed out to commuters as they entered the City by employees of IT skills specialist The Training Camp and recipients were told the disks contained a special Valentine's Day promotion.
However, the CDs contained nothing more than code which informed The Training Camp how many of the recipients had tried to open the CD. Among those who were duped were employees of a major retail bank and two global insurers.
The CD packaging even contained a clear warning about installing third-party software and acting in breach of company acceptable-use policies - but that didn't deter many individuals who showed little regard for the security of their PC and their company.
Rob Chapman, CEO of the Training Camp, who carried out the stunt to promote a course in security for non-IT professionals, said: "Fortunately these CDs contained nothing harmful. No personal or corporate data was transmitted due to the actions of these individuals but the fact remains that this could have been someone wanting to cause havoc in the City."
Chapman claimed the "potential outcome could have been disastrous".
Effectively the employees, by carrying the CD into the company and putting it straight into their PC, had by-passed much of their company's security. Chapman said: "Employees have to recognise they are the first and easiest route into a company's network."
Just last year Japanese bank Sumitomo Mitsui in the City fell victim to a spyware infection which almost ended with the theft of £220m. That case should have highlighted the threat posed by applications entering the enterprise through unofficial channels and yet it appears few companies have taken note.
If no corporate details were gathered during this ...
Anonymous
It's interesting to say that 'Employees Don't Care...
Mark Nicholas
Excuse me, but it's not the responsibility of any ...
Merlin
Users generally don't care about security because ...
fatman
Dear Merlin. You've obviously missed the point. So...
Mark Nicholas
Bringing a plethora of skills and a wealth of experience to this role, you'll be given responsibility as a Business Partner for ensuring the full ...
With its close location to Birmingham, Halesowen is easily accessible and a busy route to the motorways and the South West beyond. As a small portion ...
Security Cleared; (Note - can commence on a BC level of clearance if necessary. Sending your CV via both channels in no way speeds up the application ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...