You are here: silicon.com > Financial Services > News

Web 2.0 security risks being ignored

Fundamental shift in security needed, say experts

Tags: web 2.0, security, banking, banks

By Julian Goldsmith

Published: 31 January 2008 16:49 GMT

Web 2.0 presents a barely understood risk to companies embracing social networking and instant messaging technology as business tools and could force a change in corporate IT security and greater use of encryption.

Almost two-thirds (65 per cent) of US companies do nothing to block third-party collaboration tools, such as real-time communications and information sharing, according to research from Yankee Group.

Tom Rashke, senior analyst at Forrester, said 25 per cent of US CIOs in a recent survey admitted adoption of web 2.0 tools would be a priority in 2008, even though the strategy would potentially increase potential areas of attack, increase the complexity of infrastructure and the return on investment (ROI) was not clear.

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

Rashke warned traditional security tools - such as firewalling - did not go deep enough into rich content to determine whether it was a security risk - either incoming as malware or outgoing as data leakage.

Essentially, what is needed is a shift in focus from securing the infrastructure, through which data moves, to the data itself, said Rashke.

Group head of information security at Standard Chartered Bank, John Meakin explained the banking industry is embracing web 2.0 tools in two ways.

Externally, banks are responding to customer demands that their interactions with their bank mirror the other interactions they are used to on the internet while internally banks are using web 2.0 tools to communicate and collaborate across their large organisations and many business units spread around the globe.

He told silicon.com: "Banks are under pressure to operate more efficiently. Web 2.0 applications help people collaborate, which as businesses, we would be foolish to look away from. At the same time, we have to be clear we are not introducing risk into the process - our businesses are based fundamentally on trust."

Meakin noted that embracing web 2.0 tools may mean competitive data residing outside the organisation.

He said: "Banks will have to make sure they haven't lost complete control over the integrity of their data if they use web 2.0. One way to do this is to make sure the data is encrypted. This is a limited solution, because it doesn't take into account the way the security status of data can change. Financial reports, for instance are sensitive until the day they are announced, when they become public domain. A better approach is to make sure that even if data is accessed through something like Facebook, the data still resides within your organisation."

Meakin and Rashke were speaking at a seminar attended by financial analysts and global banks organised by security specialist Worklight.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

silicon.com Financial Services
Get the latest financial services news straight to your inbox. Sign up for the FS newsletter today!


Security Consultant Ethical Hacking / Penetration Testing - London

For further information please visit our website: www.net2s.co.uk In London, NET2S has a team of 75 consultants spread across 19 of the top 20 ...

S50829: Market Data Desktop Operations Support Analyst1

With broad global resources and deep technical know-how, we collaborate with clients to cultivate ideas and deliver results. Market Data Desktop ...

Java/Oracle Snr dev reqd for a top tier banks risk team - London

One of the worlds largest banks are recruiting and they are looking for a senior developer with an established server-side development background.

Carol Wheatcroft
Will consumers always want free banking?
Targeted, bundled services will be the way to profit...

Steve Boyle
Are rogue traders an inevitable evil?
Opinion: Managers must increase diligence to beat fraud

Julian Goldsmith
Profile: Nottingham Building Society head of IT Jack Cutts
'On the wide accountancy'...

Steve Boyle
Why you should be outsourcing your data centres
Concentrate on the core business...

Bob McDowall
Fixed-income electronic trading faces bleak 2008
Trading platforms likely to draw in their horns for downturn

Steve Boyle
Banking can execute change in real-time
Opinion: Tools and techniques now exist to make it possible

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.




Quick Sitemap Links: