But computer forensics is on the case...
By Ron Coates
Published: 20 August 2004 17:23 BST
The use of instant messaging is booming in the City and so is its use to evade the long arm of compliance regulation.
Despite the imminent arrival of tighter legislation such as Sarbanes-Oxley, many traders and financial workers appear to still be 'making hay while the sun shines' - or rather leaking data while the holes exists to do so.
Adrian Palmer, UK managing director of data recovery specialist KrollOntrack, said: "It's been a progressive trend. We are getting cases where confidential information is being leaked and the most likely form is MSN Messenger or another IM system. Company officials are looking for support that something was said to a particular person at a particular time."
People working at financial institutions who have phone calls and emails monitored may think IM is invisible to management. But everything leaves a trace, according to Kroll senior forensic engineer Robert Weston.
He said: "We can look at the register and we can recover fragments of the text. We are getting an increased number of requests to do this. But, of course, the more people use it, the more people will use it as a device to do something they shouldn't.
IT staff can set up sophisticated data capture devices on servers to keep track of IM and record it. There are various techniques for monitoring traffic and most involve a keyword search. According to Palmer, this can be tailored to the individual and Weston points out that keyword lists can be very "dynamic" - that is, frequently updated.
In the UK, employers are obliged to notify employees if they have this sort of monitoring system - and post compliance deadline all will need to - or they will need to outlaw any IM applications which cannot be archived and audited.
Although IM can be a security risk, banning it is not the answer, said Weston.
"Organisations which have tried to ban it can see a loss of efficiency. It makes a great difference when you can see that a colleague is on line, ask the question you need to and get an answer. With email, you may never get one.
"But while most people are aware of the vulnerability of email [to surveillance] and prefer IM, they will find that it might come back and bite them."
Back to Compliance Special Report
I have just set up blocks on Border Manager to sto...
Howard Knopler
There's plenty of products around such as Cryoserv...
Thomas Bailey
I believe Websense blocks IM and P2P out of the bo...
Paul Kitchen
Forgot to mention the reason why you are not block...
Paul Kitchen
Decision on Microsoft antitrust fine to take "weeks"
€2m-per-day penalty on hold
Are compliance headaches only just beginning?
Financial services IT managers, get ready...
Gartner: SOX is boosting IT spend
'Budgets to increase by 10 to 15 per cent next year'
CIO Agenda, part 1: The 2006 IT shopping list
IT governance and compliance steal security's top spot
IT the key to cutting SOX costs
The compliance work isn't over yet...
Stories from around the web...
Relief from Sarbanes-Oxley on the way? CNET News.com
Chief risk officer: A valuable addition to the C-suite Globe and Mail
IT complexity confounds financial sector compliance Accounting and Finance 365 - registration required
The secret to success LegalWeek
Sarbox: The appliance of compliance Accountancy Age
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
For more about the Research Panel and how to join, click here
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page