If security policies aren't able to bend, then they will break.
endif; ?>As someone who works at a security company, I understand the desire to “block everything” or to be overly strict with security policies. But when an IT department becomes too strict with its security, it may have the opposite effect than what was intended.
Employees will find work-arounds so they can get their job done, or worse, they won’t be able to do their job at all. When employees subvert security policies so they can do their job, or even just so they can waste a little time, they are putting the network at risk.
I spoke with a company just this week that was having this exact problem. The company deals with sensitive information so, naturally, its executives are security-minded. After implementing a new security gateway, they locked down the entire network. One of the employees didn’t like having restricted access to websites like Facebook, so she started trying to find ways around it. After several failed attempts, she got in contact with an unidentified, random group on the Internet to try and get around the new security policies. She ended up emailing them from her house, copying a file they provided her with onto a flash drive and then running it on her machine at work. Fortunately, the new gateway product blocked the traffic, BUT the company soon started receiving several thousand intrusion attempts per day from Iran as a result. Remarkably, she wasn’t fired and hopefully learned her lesson.
Now, I’m not going to claim that this employee wasn’t acting inappropriately. Also, she is clearly a case for why organizations need to educate their employees about IT security in addition to deploying security solutions. However, an incident like this makes you wonder if it could have been avoided if the company had simply been more open with their network. I’m all for protecting the network, but organizations should also be smart about it.
Maybe if she had access to some other, safer, more acceptable sites, she wouldn’t have been so bent on getting to Facebook in the first place. If the company is worried about employees wasting time on social networking sites, they could have set up time-based permissions so employees have access during lunch or afterhours.
This time the employee was trying to get around the security policies to go to Facebook, but how many employees are pulling similar stunts just to do their jobs? The Internet has become an essential part of our professional lives, and I know there are some tasks I just can’t complete without access to the Internet. If security is so tight that employees can’t do their jobs, it becomes counterproductive and can push otherwise smart employees to make bad decisions. Security policies are very important but they need to be realistic. Otherwise, you could end up jeopardizing security altogether.




