Security risks of temp workers being ignored

Lock 'em out.

Temporary workers have too much access to computer systems, exposing businesses to potential security risks, says a survey carried out by Websense.

In a survey of more than 100 temporary staff in the UK, the security firm found that 88 percent were able to access documents from the company network drive, 62 percent had used someone else’s login details to access a work computer, 52 percent had used a colleague’s email account, and 81 percent had unlimited access to the Internet from their work PC.

Websense says these findings show that by neglecting to put procedures in place to protect against security breaches by temporary workers, businesses are risking potential large-scale data theft. The fact that 80 percent of temporary staff have the same level of access to company documents as permanent staff, but without the same accountability, is also a serious cause for concern.

The survey also found that staff were not properly briefed, with 97 percent of respondents saying they either did not understand or had never heard of the Computer Misuse Act. Only 21 percent of temporary workers had signed any type of PC or Web use policy.

The survey also touched on the risk presented by Web 2.0 applications. "There is also strong evidence that businesses are failing to manage the use of social networking sites and Web 2.0 technologies, which are a haven for cyber criminals," said Websense.

It said that 67 percent of workers admitted to using social networking sites such as Facebook during working hours, and 81 percent are able to access POP email such as Hotmail.

Among the other findings, 91 percent were able to print any work document they liked, and 37 percent were given access to passwords for company systems like invoicing, procurement, and payroll. Additionally, 42 percent were able to connect a personal device like an iPod, USB stick, or PDA to their work PC.

"Temporary workers are not maliciously trying to steal data," Mark Murtagh, product director at Websense told Techworld. “But organisations should be aware that transient temporary workers, such as data entry and data mining staff, often have access to highly sensitive information and databases.”

Murtagh feels that certain sectors are more at risk than others. "Personally I feel that classic standout industries are more exposed,” said Murtagh. “Certainly the retail sector, as they bring in more staff to deal with the Christmas rush is at risk, as are call centre and financial institutions."

According to Murtagh, Websense is seeing a lot of fraud-based attacks, with hackers using social networking sites such as Facebook and YouTube to attack companies. Last month IDC warned that criminals are taking increasing advantage of “Web 2.0” and social networking to attack companies.

Murtagh advises companies to review the systems that temporary workers use, and especially look at how temporary workers can have the same access rights as permanent staff. "There is a combination of things businesses can do, but it depends on what is agreeable to them considering their structure and costs."


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

formertemp | Published: 19:14 GMT, 28 November 2007

if you want to footprint an institutions core systems, become a temp!

Related Security news

Antivirus programs fail to stop new malware

One in three systems infected.

Adobe sorry for 16-month-old Flash bug

Unpatched vulnerability 'slipped through the cracks'

HTML 5 leaves client storage open to web attacks

Security researcher says web apps could be vulnerable

Rugged Manifesto calls on developers for secure code

Security professionals call for better programming practices



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *