Compliance

You are here: silicon.com > Research > Special Reports > Compliance

Compliance

IM the prime suspect in City leaks

But computer forensics is on the case...

By Ron Coates

Published: 20 August 2004 17:23 BST

The use of instant messaging is booming in the City and so is its use to evade the long arm of compliance regulation.

Despite the imminent arrival of tighter legislation such as Sarbanes-Oxley, many traders and financial workers appear to still be 'making hay while the sun shines' - or rather leaking data while the holes exists to do so.

Adrian Palmer, UK managing director of data recovery specialist KrollOntrack, said: "It's been a progressive trend. We are getting cases where confidential information is being leaked and the most likely form is MSN Messenger or another IM system. Company officials are looking for support that something was said to a particular person at a particular time."

People working at financial institutions who have phone calls and emails monitored may think IM is invisible to management. But everything leaves a trace, according to Kroll senior forensic engineer Robert Weston.

He said: "We can look at the register and we can recover fragments of the text. We are getting an increased number of requests to do this. But, of course, the more people use it, the more people will use it as a device to do something they shouldn't.

IT staff can set up sophisticated data capture devices on servers to keep track of IM and record it. There are various techniques for monitoring traffic and most involve a keyword search. According to Palmer, this can be tailored to the individual and Weston points out that keyword lists can be very "dynamic" - that is, frequently updated.

In the UK, employers are obliged to notify employees if they have this sort of monitoring system - and post compliance deadline all will need to - or they will need to outlaw any IM applications which cannot be archived and audited.

Although IM can be a security risk, banning it is not the answer, said Weston.

"Organisations which have tried to ban it can see a loss of efficiency. It makes a great difference when you can see that a colleague is on line, ask the question you need to and get an answer. With email, you may never get one.

"But while most people are aware of the vulnerability of email [to surveillance] and prefer IM, they will find that it might come back and bite them."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Compliance News

Decision on Microsoft antitrust fine to take "weeks"
€2m-per-day penalty on hold

Are compliance headaches only just beginning?
Financial services IT managers, get ready...

Gartner: SOX is boosting IT spend
'Budgets to increase by 10 to 15 per cent next year'

CIO Agenda, part 1: The 2006 IT shopping list
IT governance and compliance steal security's top spot

IT the key to cutting SOX costs
The compliance work isn't over yet...

Compliance Extra

Stories from around the web...

Relief from Sarbanes-Oxley on the way? CNET News.com

Chief risk officer: A valuable addition to the C-suite Globe and Mail

IT complexity confounds financial sector compliance Accounting and Finance 365 - registration required

The secret to success LegalWeek

Sarbox: The appliance of compliance Accountancy Age

RELATED RESEARCH

Make your voice heard

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: