Rising IM use poses corporate security risk

Porn, viruses and lack of compliance are a threat, warns Gartner

By Andy McCue, 1 June 2006 15:05

NEWS

Uncontrolled and insecure instant messaging (IM) use by staff is leaving corporate networks and data exposed to the threat of hackers and virus writers, according to Gartner.

The analyst house claims attackers are shifting their focus from well-protected email systems to IM as its use by employees within organisations increases.

Viruses are the main threat and Gartner says IT managers who do not adequately protect public IM will experience 80 per cent more IM-related security incidents than those who do put in stronger defences.

The main risks of uncontrolled IM use include a lack of regulatory compliance involving the retention and auditing of communications; the lack of encryption to protect confidential data being exposed in IM; and the danger that staff will use IM to circumvent email usage policies and to play games and send pornography, according to Gartner.

Peter Firstbrook, research director for Gartner's Information Security and Privacy research group, said in a statement: "Lack of visibility and control means that IT cannot manage the use of IM or enforce safe policies. As with the web, IM can be a productivity improver and a time waster. Lack of visibility makes it difficult to ascertain what is happening."

IM viruses are usually transmitted using social engineering tactics to get victims to click on executable file attachments or hyperlinks in IM messages that link through to malicious web servers.

Security experts have been warning for two years about hackers exploiting IM to carry out attacks on networks.

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ