IT manager slumber party

The IT manager who’s convinced his or her network is totally secured is just that much more likely to be the next headline, in the tradition of Monster.com, TK Maxx, Barclays and Nationwide to name but a few, writes Alex Raistrick, director Northern Europe at ConSentry Networks

Written by Alex Raistrick

The clamour from the House of Lords and throughout the UK for data breach disclosure laws is just one piece of evidence that people have lost faith in companies to protect their private data. In view of this rising concern and the rising breaches, enterprises need to do everything they can to reduce the chances of being a victim of such breaches. The key to this? Implementing internal controls.

Companies have long protected their perimeters but the perimeter is now long gone and protection from within is now the essential security frontier. IT managers need to find a way to control from within the campus, by ironing out who can get onto their networks, and more importantly, what users can do once they’re already on the LAN. They also need to protect against malware being unleashed – either accidentally or intentionally – that can aid in breaching privacy.

IT managers who think that passwords, anti-virus software, firewalls, or other security techniques already in place are sufficient should speak to those who lost their jobs at Barclays, Nottingham Hospital, and TK Maxx.

In this day and age of contractors, outsourcing, joint development projects, and remote working, companies can be far less certain of who’s on their LAN. As a result, they need technologies that can help them segment the users, identify the users and their roles, and limit their LAN access based on that role.

In one recent case, a LAN assessment showed what a worker coming in on a Saturday was actually doing. The worker had requested permission for overtime work because he was too overloaded to complete a project. The request was approved, because the project was time critical, but it turned out that he spent many hours that Saturday copying his recent vacation pictures from his laptop to an internet-based photo-sharing web site, adding captions along the way.

The reality is that businesses have had very limited resources for learning about user activity on the LAN. Typically, a company can at best authenticate whether a user belongs on the LAN. But only recently has IT had the ability to track and control what users can do after they’re on the LAN. Businesses shouldn't despair that they don’t have these controls in place now – they just shouldn't delude themselves that they don’t need them.

reader comments

related articles

2007 Roundup: Data loss hits the headlines

Nationwide, Halifax, TK Maxx, HMRC and many, many more to blame 24 Dec 2007

Review 2007: IT security and e-crime

Computing's review of the year looks back at the top IT security and cybercrime stories 20 Dec 2007

TJX settles data breach lawsuits

Company agrees to compensate and insure customers 26 Sep 2007

latest news

Resellers hit by delivery disruption as Amtrak fails

UK courier company Amtrak has entered receivership due to financial difficulty 29 Aug 2008

Dell’s profits plunge 17 per cent

PC vendor's net profit takes a tumble as turf war with HP in EMEA hurts bottom line 29 Aug 2008

Avnet upgrades and expands Bracknell demo centre

Distributor refurbishes five-year-old centre to provide vastly expanded proof-of-concept opportunities 29 Aug 2008

poll

A new Linksys era?

A new Linksys era?

Will the Linksys brand fizzle out when Cisco folds it into its SME operation?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories