IE 11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

Threat Index Reveals Use of Remote Access and Rogue VoIP Protocols

Exposure occurs despite federal and state privacy laws and on-going publicity about the risks of identity theft, says firm

Reconnex yesterday released its latest Insider Threat Index for the first quarter of 2006, which reveals the extensive use of remote access protocols as well as the growing use of rogue VoIP protocols such as Skype, and discusses the risk they pose to the corporation. Leakage of Social Security numbers (SSN) and credit card numbers (CCN) continues to be a problem, said the firm; 89 percent of corporations assessed exposed SSNs and 67 percent exposed CCNs. This exposure occurs despite federal and state privacy laws and on-going publicity about the risks of identity theft.

Reconnex compiled the current index from more than 1.1 terabytes of raw data gathered from 48-Hour eRisk Rapid Assessments conducted from January to March 2006 in a variety of industries, including healthcare, finance, technology and manufacturing. The e-Risk Rapid Assessment allows corporations to quickly assess the insider threat and conduct immediate forensic investigations to determine the sources of threats and the motivations behind them.

Leading Risk Indicators Widespread in Latest Analysis
Organizations are still at high risk of having personal and confidential information leaving their networks undetected. Here are some examples from the research:
  • Webmail -- 89 percent of companies assessed had Webmail running over their networks.
  • SSN -- 89 percent of companies leaked Social Security numbers.
  • CCN -- 67 percent of companies exposed credit card numbers.
  • Instant Messenger (IM) -- Because IM can easily leave the network without detection, most organizations forbid its use, yet 78 percent of companies had IM on their networks.
  • Peer-to-Peer (P2P) -- P2P file sharing protocols, banned by most companies because they pose grave risks to corporate security, were found in 78 percent of companies, compared to 35 percent in all of 2005.
  • Remote access protocols -- These were present in 66 percent of companies.
  • Rogue VoIP protocols -- 22 percent of organizations had Skype on their networks.