A security expert has warned firms they need to address a "new generation"
of security weaknesses enabled by peer-to-peer (P2P) networks on the systems of
third-party contractors and business partners.
Former White House security advisor Howard Schmidt, now president of R&H
Security Consulting, issued the warning at a conference of senior IT security
professionals hosted by certification organisation ISC2.
"It's a very important and emerging issue," Schmidt said. "We [talk a lot]
about intrusion detection and antivirus…but one thing we're not paying enough
attention to is P2P file sharing networks and how much data we're really
exposing inadvertently, which we have no control over."
Schmidt said IT managers typically control the use of file sharing networks
within their own networks but contractors or agents working for their
organisation can often keep or access corporate data on their laptops or home
PCs, alongside P2P clients. He added that these users may then look for music or
movie downloads on P2P applications, and inadvertently expose the entire
contents of the hard drive.
"I've seen thousands of documents containing internal administrative
passwords which are now being shared throughout the world," Schmidt warned. "
The risk is that [criminals] are now searching for corporate information – P2P
search strings [we've identified] show they're actively seeking these documents.
"
Schmidt said security chiefs should closely monitor P2P networks at a
granular level to see if corporate is exposed, and should look out for potential
leaks across the whole supply chain, not just within the corporate perimeter. "
That's the information you need so you can protect against [this threat]," he
said.
London, Haringey, United Kingdom | Haringey Council
PMO Support Officer - Haringey, London - £32,289 - £37,542 pa Experienced project support officer required by the internal IT services organisation of a London borough council to work within its Programme Management Office ... more >
EDS are currently looking to recruit an experienced Core Infrastructure Project Manager to join our Project Management Defence team in one of the following locations: Reading or Bracknell (Berkshire) or Camberley (Surrey). Summary: Within DII ... more >
Programme Managers - Project Managers -Project Support Staff - Competitive Salary + Excellent Benefits - London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use ... more >
Leek Wootton, United Kingdom | Warwickshire Police
IT Business Analyst - Leek Wootton, Warwickshire - £29,112 - £31,491 PA - 37 hrs per week Everyone who works for Warwickshire Police helps to protect our communities from harm. Work with us and ... more >More job opportunities