IT Reseller Magazine
Article Search: Go To: Keyword 
 
   

FREE Subscription to IT Reseller Magazine






Channel Talk
Views and opinions from within the channel


UK Businesses Blind to the Data Breach Risks of Temporary Staff
13 December 2007  by Websense

Survey reveals new data security risk: over 80% of temporary staff have the same level of access to company documents as permanent staff but without the same accountability

Research released by Websense, Inc. (NASDAQ:WBSN) has revealed that temporary workers across the UK are unwittingly exposing businesses of all sizes to information security breaches. In the Information Open Access survey of more than 100 temporary staff, the findings indicate that organisations may be unnecessarily putting their data at risk by granting temporary staff access to confidential information at the same levels as permanent employees. 

The survey highlights that 87.7% of respondents were able to access documents from the company network drive, 52% had used a co-worker's e-mail account and 80.7% had unlimited access to the Internet from their work PC.  A worrying level of apathy amongst businesses toward basic data security processes is leaving them wide open to the risk of accidental or deliberate data breaches - only 21.1% of temporary workers had signed any type of PC or Web use policy

As businesses gear up for the busy Christmas period, the UK's 3.1% (or 770,000) temporary staff will balloon to nearly 900,000. However, businesses are evidently ill-prepared for the security risk this introduces. The survey identifies three key issues propagating this security risk:

1. INFORMATION LEAKAGE
The most prominent theme to emerge from the survey results shows that temporary workers are exposing businesses to potentially large-scale information leakage where confidential data is allowed out of the organisation, either by mistake or through malicious intent. Key findings include:

87.7% of respondents were able to access documents from the company network drive or electronic folders that permanent staff use on a day to day basis
62.4% had used someone else's login details to access a work PC
57.5% admitted sending work documents to the wrong person
91.2% were able to print any work document they liked
36.8% were given access to passwords for company systems (i.e. invoicing, procurement, payroll)
52% used someone else's e-mail account or a general company e-mail address
42.1% were able to connect a personal device (iPod, USB key, PDA) to their work PC
 

2. LACK OF BASIC DATA SECURITY MANAGEMENT
Underpinning the data leakage risk is a worrying degree of apathy amongst businesses towards basic data security management. The survey indicates that the majority of businesses are failing to put business processes in place for temporary staff to protect against security breaches.  78.9% of temporary workers said they did not have to sign a PC or Internet use policy before starting a temporary assignment. And 97% said they either didn't understand or had never heard of the Computer Misuse Act. This includes the 'unauthorised access offence' where a person is 'committing an offence if he or she causes a computer to perform any function with intent to secure unauthorised access to or modification of any program or data held in a computer'.

3. EXPOSURE TO EXTERNAL THREATS
The survey also reveals that temporary workers are opening the doors to allow external threats such as Internet viruses or botnets to infect businesses, through a lack of automated Internet and email management. There is also strong evidence that businesses are failing to manage the use of social networking sites and Web 2.0 technologies, which are a haven for cyber criminals.

Key findings include:

67% of temporary workers used social networking sites like Facebook during working hours
80.7% had unlimited access to the Internet from the work PC
80.7% could access POP e-mail like Hotmail
21.1% accessed peer to peer sites like Kazaa
37.2% used instant messaging to chat with friends
25.5% accessed download sites during work hours
 
"Many businesses across the UK rely on temporary staff to help see them through the busy Christmas period. But business managers need to secure the critical data that is unwittingly being put at risk by temporary staff,' said Johanna Severinsson, senior marketing director, Websense.  "Organisations must start managing what access their temporary staff has to confidential data so they can focus on maximising profits during the festive period rather than dealing with security holes."


About Websense, Inc.

Websense, Inc. (NASDAQ: WBSN) protects more than 42 million employees from external and internal computer security threats.  Using a combination of pre-emptive ThreatSeeker(tm) malicious content identification and categorisation technology and information leak prevention technology, Websense helps make computing safe and productive.  Distributed through its global network of channel partners, Websense software helps organisations block malicious code, prevent the loss of confidential information and manage Internet and wireless access. 


Channel News
SMEs urged to unlock the secrets of the web through free events
Smaller businesses across the UK are being invited to discover how they can harness the full potential of the internet through a series of free events.
Paul Callow to lead Lexmark channel revamp
Paul Callow has been appointed as Lexmark's ISD & channel director, UK & Ireland, to re-energise the company's channel.
Avnet awarded new contract to distribute full Avaya product portfolio
Avnet Technology Solutions, the solutions distributor and an operating group of Avnet, Inc., has been awarded a new contract by Avaya International Sales Limited to distribute its full product portfolio in the UK.
Mint Wireless becomes part of Motorola value chain for payments
Mint Wireless Ltd. (Mint) has entered into a partnership arrangement with Motorola Inc.
Box Technologies' staff get on their bikes for charity
Box Technologies, a fast-growing technology services provider and distributor for Toshiba, has been putting the final touches to the planning of its 500-mile grueling charity bike ride.
Torex puts new product manager in the multi-channel driving seat
Torex Retail Holdings Limited (Torex), the global provider of integrated technology solutions to the extended retail marketplace, has appointed Roy Patrick as Multi-Channel Product Manager.

More >>

advertisements





Related Articles



Let the news come to you!
Subscribe to our weekly newsletter and the digital edition of IT Reseller Magazine!

Email Address:   



© Copyright 2006, IBC - Interactive Business Communications

Help | Contact Us | PrivacyRSS Feeds | Site Map | Advertise
YourTechTV.com Only Technology Videos