All the latest UK technology news, reviews and analysis

Systems still left open to former employees

by Phil Muncaster

15 Jun 2009

Be the first to comment

  • Tweet this

numbers.jpgMany companies fail to protect sensitive data from embittered ex-employees by not properly and quickly terminating all access when someone leaves the company, according to a new study.

A survey by access management firm Courion found that, although the majority of IT managers reckon that terminated employees will not attempt to remotely access data, over half admitted to having no real idea of what access routes remain active after someone leaves the company.

"The fact that 53 per cent of IT managers are largely unaware of employee access rights is of great concern, and has been exacerbated by the high frequency of mergers and acquisitions in the current climate," said Stuart Hodkinson, general manager at Courion.

"The time for over confidence has passed. It is important for IT managers to close these holes by undertaking regular audits, and ensuring that employees have access only to the information they need to do their jobs."

This proliferation of what Hodkinson calls "zombie accounts" is also aided by the fact that 28 per cent of respondents said that their company still provisions accounts manually, making delays and errors in deactivation much more likely.

The survey found that nearly half of businesses take more than a day to inform the IT department of a departing employee, and around a third admit that it takes more than a week to shut off access to systems.

Hodkinson sees this as a worrying window of opportunity for disgruntled employees to attack internal systems, or obtain valuable information that could cost the company a lot of money and tarnish its reputation.

The survey also revealed that nearly one in 10 companies could never be completely certain that terminated employees no longer have access to IT systems.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Developer - Technology driven hedge fund

My client is one of the most successful and highly regarded...

Senior Java Developer - Online Gaming

Java/J2EE, Agile, Scrum, Test driven development, Pair...

C# / ASP.NET Software Developer - Online Gambling

C# / ASP.NET Software Developer - Online Gambling - London...

Java Developer - highly transactional gaming site

Developer, Gaming / Finance, 35-50k My client are...

To send to more than one email address, simply separate each address with a comma.