Businesses are ill-prepared for the security risk introduced by temporary workers Businesses are ill-prepared for the security risk introduced by temporary workers - RSS feed from Security Park
(27/11/2007)

According to new research released today by Websense, Inc., temporary workers are unwittingly exposing businesses of all sizes to information security breaches. The findings indicate that organisations may be unnecessarily putting their data at risk by granting temporary staff access to confidential information at the same levels as permanent employees.

The survey highlights that 87.7% of respondents were able to access documents from the company network drive, 52% had used a co-worker's e-mail account and 80.7% had unlimited access to the Internet from their work PC. A worrying level of apathy amongst businesses toward basic data security processes is leaving them wide open to the risk of accidental or deliberate data breaches - only 21.1% of temporary workers had signed any type of PC or Web use policy

As businesses gear up for the busy Christmas period, the UK's 3.1% (or 770,000) temporary staff will balloon to nearly 900,000. However, businesses are evidently ill-prepared for the security risk this introduces. The survey identifies three key issues propagating this security risk:

1. INFORMATION LEAKAGE

The most prominent theme to emerge from the survey results shows that temporary workers are exposing businesses to potentially large-scale information leakage where confidential data is allowed out of the organisation, either by mistake or through malicious intent. Key findings include:
o 87.7% of respondents were able to access documents from the company network drive or electronic folders that permanent staff use on a day to day basis
o 62.4% had used someone else's login details to access a work PC
o 57.5% admitted sending work documents to the wrong person
o 91.2% were able to print any work document they liked
o 36.8% were given access to passwords for company systems (i.e. invoicing, procurement, payroll)
o 52% used someone else's e-mail account or a general company e-mail address
o 42.1% were able to connect a personal device (iPod, USB key, PDA) to their work PC

2. LACK OF BASIC DATA SECURITY MANAGEMENT

Underpinning the data leakage risk is a worrying degree of apathy amongst businesses towards basic data security management. The survey indicates that the majority of businesses are failing to put business processes in place for temporary staff to protect against security breaches.

78.9% of temporary workers said they did not have to sign a PC or Internet use policy before starting a temporary assignment. And 97% said they either didn't understand or had never heard of the Computer Misuse Act. This includes the 'unauthorised access offence' where a person is 'committing an offence if he or she causes a computer to perform any function with intent to secure unauthorised access to or modification of any program or data held in a computer'.

3. EXPOSURE TO EXTERNAL THREATS

The survey also reveals that temporary workers are opening the doors to allow external threats such as Internet viruses or botnets to infect businesses, through a lack of automated Internet and email management. There is also strong evidence that businesses are failing to manage the use of social networking sites and Web 2.0 technologies, which are a haven for cyber criminals.

Key findings include:
o 67% of temporary workers used social networking sites like Facebook during working hours
o 80.7% had unlimited access to the Internet from the work PC
o 80.7% could access POP e-mail like Hotmail
o 21.1% accessed peer to peer sites like Kazaa
o 37.2% used instant messaging to chat with friends
o 25.5% accessed download sites during work hours

"Many businesses across the UK rely on temporary staff to help see them through the busy Christmas period. But business managers need to secure the critical data that is unwittingly being put at risk by temporary staff,' said Johanna Severinsson, senior marketing director, Websense. "Organisations must start managing what access their temporary staff has to confidential data so they can focus on maximising profits during the festive period rather than dealing with security holes."

Related topics:  Computer and PC Security   Data management and data security   Internet and Web security   Network Security   Security management and policies 


print versionPrint version | email this to a friendEmail to a friend | related articlesRelated articles


Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.


Other Security news and resources


Security News Suppliers Directory Jobs forum Classifieds Knowledge base White papers Research library Security books Special reports Security interviews Security companies Security events Security links Security market

Product channels

Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products

IT Security white papers and research library

Access Control  Authentication  Data Management  Data Security  Digital Signatures  Email Security  Identity Management  Internet Security  Intrusion Prevention  Network Security  Remote access security  Security Management  Security Policies  Security Software  Security Threats  Virus Detection Software  Virus Protection  VPN  Vulnerability Assessment  Wireless Security 

Security books, guides, standards and toolkits

RFID and Smart Cards books, guides and reference documents  Biometric books, guides and reference documents  CCTV books, guides and reference documents  Intruder alarms and intrusion detection systems books, guides and reference documents  Monitoring and surveillance books, guides and reference documents  IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits  Fire, Health & Safety books, guides and reference documents





Ensure that you conduct an effective information security risk assessment that is in line with ISO 27001 by purchasing vsRisk™ Risk Assessment Tool

Need a
Security reference book?
Find it on Amazon
Security books

Article search

Directory search


add your company
Google

ISO 18028 (Network Security Management)
Home | About | Contact | Submit article | Advertise | Newsletter | RSS | Search