* IMlogic, Postini separately further the cause of secure messaging
endif; ?>Among the many vendor announcements last week were two that will have important ramifications for the security of messaging.
IMlogic announced Threat Center, which is designed to detect outbreaks of instant messaging (IM) and peer-to-peer viruses, worms and other threats very early. Using a series of honeypots, IMlogic says it will be able to identify these threats before they become widespread and will provide information to customers in real-time with alerts. IMlogic will also be able to issue policy updates for its customers to prevent the spread of these threats. The data provided by IMlogic’s Threat Center will be made available to non-customers, as well.
Postini announced it will offer secure messaging capability in its enterprise-level managed service. The Postini offering will automatically encrypt outgoing e-mail between gateways using the Transport Layer Security (TLS) protocol. Messages received at Postini’s data centers will then be decrypted, scanned for threats as in the current offering, and then re-encrypted for delivery to the recipient. Recipients unable to receive TLS-encrypted messages will receive unencrypted messages as they do now. Future enhancements to the offering in 2005 will include feedback to the sender on recipients that cannot receive encrypted e-mail.
Why are these two announcements important? The IMlogic Threat Center is a response to the rapidly growing threat of malware transmitted through IM. Because employees at about 90% of enterprises currently use some IM, because about 25% of e-mail users in the workplace also use IM, and because most of the IM clients currently used are consumer products that do not natively protect against malware, enterprises are extremely vulnerable to IM software bypassing their current defenses and allowing viruses, worm and other unwanted stuff into their networks.
The Postini announcement is important because it represents the growing need for enterprises to seriously consider deploying secure messaging capability. Most enterprises don’t have a need for desktop-to-desktop encryption because their current defenses are adequate to protect mail inside the firewall. Gateway-to-gateway, policy-based encryption – as in the Postini offering – will suffice for most users because it provides enough security to protect sensitive data while making secure messaging easy to use for individual e-mail users.




