* Organizations need to get on the ball, survey shows
We have just concluded a major study of messaging archiving practices in North America and will be publishing the results shortly. One of the key themes that came out of the research is that many organizations are at risk because of the way they manage their messaging systems.
Here’s a summary of some of our findings:
* Fifty-four percent of organizations have no policies or systems in place to prevent users from deleting important content from their messaging system, while another 29% have only policies in place to prevent these deletions. Only 17% of organizations surveyed have systems and policies in place. What this means is that only one in six organizations is protected from improper use of e-mail by employees – audits by several messaging security firms indicate that many messaging managers are unaware of the extent to which messaging is misused in their organizations.
* Thirty-eight percent of organizations have been ordered by a court or regulatory body to produce employee e-mail. This means that more than twice as many organizations have been required to provide e-mail to a regulator or court than have systems and policies in place to ensure that all e-mail is available to satisfy these requirements.
* Twenty-four percent of organizations do not have either an e-mail or an instant messaging (IM) retention policy in place. As a means of mitigating the risk associated with improper e-mail use, all organizations should implement such a policy to make sure that employees are aware of how e-mail and IM should and should not be used.
* When asked which was the least risky option for their organization – deleting all e-mail and IM content, keeping all e-mail and IM content, or archiving required content only – 29% of organizations indicated that they are not yet sure. IT organizations should get together with their legal counsel, human resources department and others to determine a consistent policy for the preservation and destruction of e-mail content in order to be compliant with regulatory and litigation requirements.
Misuse of e-mail can put an organization at serious risk. All organizations, regardless of their size, should establish clear and consistent policies about e-mail use.




