Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Survey: IT pros admit to peeking inside confidential data files

Survey into trust, security and passwords
By Dave Kearns , Network World , 06/13/2007
Kearns

As long as it’s just the two of us talking, you can tell me – don’t you sometimes go snooping inside the storage servers? Not to be nosy, of course. But, perhaps, to see just what those disk hogs (you know, the ones who seem to need 10 times the storage space) are squirreling away? Well, evidently, you aren’t alone.

The recently released results of a survey by Cyber-Ark Software show that one out of every three IT employees admit to taking a peek at confidential data including private files, wage data, personal e-mails and HR’s employee background information. The research was carried out at last month's Infosecurity Exhibition Europe as part of the company's annual survey into "Trust, Security and Passwords" (check out some of last year’s results).

Cyber-Ark, if you aren’t familiar with it, develops Enterprise Password Vault for securing and managing privileged passwords. A privileged password is defined by the company as the passwords for non-personal accounts “…that exist in virtually every device or software application in an enterprise.” Not your systems, of course – you did change the “Administrator” password on your servers, didn’t you?

In other results of this eye-opening survey, more than a third of IT professionals admit they could still access their company's network once they'd left their job! (See: “E-provisioning true stories 2003”) You, of course, have a de-provisioning scheme in place to prevent that, don’t you? Even more shocking, over one-quarter of respondents knew of another IT staff member who still had access to sensitive networks even though they'd left the company long ago.

Other key findings:

* 20% of all organizations admitted that they rarely changed their administrative passwords with 7% saying they never change administrative passwords.

* 8% of the IT professionals revealed that the manufacturer’s default admin password on critical systems had never been changed (which remains the most common way for hackers to break into corporate networks).

* More than half of respondents admitted to using Post-It notes to store administrative passwords.

Cyber-Ark wants you to know all this so that you’ll be more receptive to installing its Enterprise Password Vault, of course. But even while you’re still evaluating that and similar products, you should be tightening up your own policies and procedures – it’s never too late to start being secure.

Partner Content
CA logo

CA Network & Voice Resource Center

Comprehensive Network & Voice Management Visit CA Network & Voice Management Resource Center and get insights into industry best practices, information that helps you to address your challenges.

CA Network & Voice Management Resource Center

whitepaper

Managing Voice Over IP for Successful Convergence

Voice over IP (VoIP) has much to offer in cost savings but some customers have concerns about VoIP call quality compared to the quality of traditional voice services. This white paper will help you learn how to take the right steps so that voice quality is assured.

Managing VoIP for Successful Convergence

whitepaper

The Changing Face of Network Management

Managing your network is serious business. This paper discusses the benefits of integrating configuration change-awareness into your network fault management solution

Download Whitepaper

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Sun Microsystems: The Green Tide Is Coming. Pressure Builds for an Energy-Efficient Data Center

It's safe to say that most companies, if presented with hard numbers on their energy consumption...

Secure Wireless Printing Options

Discover how you can reduce the TCO of your wireless printers in this whitepaper. Learn how to...

Tuning ERP and the Supply Chain for Profitable Growth

The supply chain is, of course, the primary processing mechanism of every manufacturing company....

Webcasts

Direct from Microsoft: Tips for Integrating Exchange 2007 and Double-Take Software

Double-Take (r) Software and Microsoft are teaming up on September 9, 2008 for a webinar focusing...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The New Network/System Management Challenges

Increasingly popular technologies such as virtualization, wireless networking and data center...

Virtualization Reality Check

Find out why analysts say approaching virtualization with an ounce of caution is wise. And also why...

Closing the Loop: Extending Wireless LAN Security to Wireless Printers

Enterprises cannot overlook wireless printers when assessing network security. The print jobs and...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.