Surfing a bigger risk than spam to company networks

By Matthew Broersma, ZDNet UK
Monday, September 18, 2006 09:40 AM

Company networks are now more likely to pick up malicious software via employee Web surfing than from e-mail attachments, according to a new study.

Nearly 40 percent of the 200 Danish companies surveyed said their systems had been infected by a virus or worm, despite the fact that 75 percent had implemented a security policy, IDC Denmark said in its report, released Wednesday. But the malicious software in question is no longer primarily making its way through e-mail, as in the past.

"There is a common misconception that e-mail [messages] constitute the biggest security threat from the Internet," Per Andersen, IDC Denmark's managing director, said in a statement. "But the survey shows that up to 30 percent of companies with 500 or more staff have been infected as a result of Internet surfing, while only 20 to 25 percent of the same companies experienced viruses and worms from e-mail [messages]."

The risk of infection is about five times greater for companies that allow Internet usage by staff to go on unhindered and unmonitored, Andersen said.

The problem doesn't go away for companies that ban private Internet use, because often such policies aren't enforced, IDC found: About 30 percent of managers at such companies said staff accessed the Internet for personal use during working hours.

IDC believes that banning personal Internet use isn't realistic, particularly as a long-term solution. Instead, the research firm recommends closer monitoring of employees' Internet use and using tools that give management an overview of time spent and behavior patterns online.

"It can certainly be done in such a way that it does not constitute outright monitoring of the actions of every member of staff," Andersen said.

Attacks can come from relatively innocuous online sources, Andersen said. He cited the case of a poker Web site that placed a Trojan horse on users' PCs when they downloaded the site's help program.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary - part three: Topic intention comparisons

Web Development

Justin James chronicles his process of using Hapax's OpenAmplify Web service to create an application that can match documents with content that is similar or identical to the source document.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




What Y2K can teach us about 2012

Blog thumbnail

Dec. 21, 2012. It's a big day on the calendar, particularly because some believe it marks the last day of the world as we know it. The apocalypse. Armageddon.

The..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web