NEWS Helpdesks and technical support workers pose a serious threat to internal corporate security. Speaking at the 'Turning IT On' security event in London held by London First , Richard Hollis, managing director of security consultancy Orthus, claimed nearly 70 per cent of all internal breaches can be traced back to the support desk. He said: "These guys have access to your network 24 hours a day, they know every single one of the company's passwords. They are highly skilled technically, but often unmotivated because of lack of career prospects. "They might even feel unrewarded and bored, all of which makes them commit attacks." Hollis added that technical support workers often have emotional problems. He said: "They might want to do damage because of emotional issues with their bosses or might have a desire to embarrass their target and show off their techie skills as a revenge." Most IT professionals are generally aware of the fact that internal security breaches cause more damage than external hacks, but few companies know how to protect against them. Hollis gave strict guidelines to IT managers on how to protect the corporate network from internal breaches. He told silicon.com: "Identify potential hackers and protect the targets, report any suspicious behaviour to management immediately and develop strong internal policies."
Hello helpdesk, can I hack you?
Seven out of 10 internal hack attacks come from helpdesk staff...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Software stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Defining your data demands in simple steps
Businesses have seen a deluge of data, with more devices, more platforms and more access -- and, of course, more ways...
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
The virtual presenter's handbook
Web seminars -- or webinars -- are online seminars or presentations used to engage remote audiences with any content...
Popular Software stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
Senior Marketing Executive - Poole - £30,000
I am representing a market leading company based in the Bournemouth / Poole area that are urgently looking for...
-
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000SAP Senior PC Product...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





Comments
There is 1 comment. Join the discussion
1. pascal olin
After my (late) reading of this article, I want to make some comments.
1) "These guys have access to your network 24 hours a day"
R) Does this mean you have helpdesk staff online 24/24 while your users are home or does this mean that your business is running unprotected from say 17h00 'till 08h00 ? I believe you should hire a security officer and the relevant tools...
2) "they know every single one of the company's passwords"
R) Why have the helpdesk been given any password apart from their own account(s). There is a plethoric number of ways to allow Helpdesk staff to perform their duty without having to have any kind of special accounts ( from scripts to Sudo, to rights delegation.
3) "but often unmotivated because of lack of career prospects.(...) They might even feel unrewarded and bored, all of which makes them commit attacks.""
R) Do you mean that you employ unreliable staff or contracts? if this is the case, it is your company's policy that needs revising.
R2) A good helpdesk staff has got a lot of career prospects, if they don't, they are not good, so why are you hiring them?
R3) If Mr Hollis implies that unrewarded and bored workers are prone to commit attacks, I wonder how he is not afraid of living in London, with so many Civil servants, bank employees accountants... these all are (usually) bored and unrewarded , are they committing any attacks ?
4) "They might want to do damage because of emotional issues with their bosses or might have a desire to embarrass their target and show off their techie skills as a revenge."
R) I fail to see the rational behind this. why would they become emotional ?. HD staff are doing their job and are trained for this, including dealing with some difficult customers, additionnaly "showing off their techie skills" is not a hacker practise, if you show off, you show yourself off, and get fined for this. Mr Hollis seems to have a lot to learn about the psychology of hackers.
5) "Most IT professionals are generally aware of the fact that internal security breaches cause more damage than external hacks, but few companies know how to protect against them."
R) Most IT professionals are also aware that the most damages are done by users using the wrong tools, ignoring security advices and downloading unscanned software to their computers.
R2) Most It professional know how to deal with these issues ( portscanning, Centralised antivirus system, automated response to threats, up to date systems patching, Global and group policies, etc etc)
6) "Identify potential hackers and protect the targets, report any suspicious behaviour to management immediately and develop strong internal policies"
R) Maybe Mr Hollis could let us understand how he himself identifies the "potential hackers" and how he intends to protect the targets. Apart from making the management understand the issues, the IT professionals have little choice but to adopt standard and rigid behaviours and implement policies that may not be adhered to by the company's management.
R2) The IT security is an issue for all of us, the overall security of any company must be part of the company policy. IT security is one of these aspects and must be taken as part of the whole security issue.
Finally: for all the replies given above, I believe this article by Mr Hollis is pointing in the wrong direction, simply pointing fingers and making unexplained statements is certainly not the right way to ensure the application of standards and ethics that WE, IT professionals, are constantly faced with.
Pascal Olin
IT Manager.