Home > Midmarket CIO Tips > > Beware of spyware everywhere: The Information Architect
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Beware of spyware everywhere: The Information Architect


Carol Hildebrand, Contributor
05.09.2006
Rating: -2.83- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


MediSync's Help Desk has heard this tale before: A caller outlines how slow his applications are running, how his computer isn't responding, how he's deluged with pop-up ads.

"We know exactly what to do," said Roger Cass, chief technology officer at the Cincinnati-based medical services company. "We take the computer and clean it up, and we're always astounded by how much people can install, even with downloading restrictions in place."

The culprit behind this is spyware, that pernicious class of software that hitches a ride into computers on free downloadable software such as screen savers or music-sharing software. Kazaa has been a common carrier, for instance. Once there, spyware installs itself unbeknownst to the computer user and carries out operations ranging from the annoying -- a constant stream of pop-up ads -- to the criminal, such as tracking and stealing personal information for the purposes of identity theft. And spyware is big business -- as much as $2 billion in 2004, according to security vendor VeriSign Inc.

More on spyware

IT Management Guide: Spyware  

SMB Buying Decisions

While many of the worst excesses are on consumer's computers, the problem is widespread in business as well. In fact, an AOL study in late 2005 showed that more than 80% of PCs contain spyware.

And the small and medium-sized business (SMB) market is particularly vulnerable. According to "Small Business Information Security Readiness," a survey of more than 1,000 small businesses put out by the Small Business Technology Institute in San Jose, Calif., although 70% of those surveyed called information security a priority, more than half had experienced a security incident in the past 12 months.

While that includes threats other than spyware, the latter is a common cause of angst, said Laura DiDio, an analyst at The Yankee Group, a research firm in Boston. "Many think of spyware as being an annoying fact of life, but it can cause performance problems at the very least, and serious security compromises at the worst," she said. "This is more of an issue for the SMB, which has less tolerance for risk and cost than enterprise counterparts."

And spyware is growing beyond nuisance and into threat, said Dave Methvin, chief technology officer at PCPitstop.com, an Internet security Web site. "It used to be that people were mildly sneaky, doing things like fooling somebody into clicking on an ad. But now, there are people who are by any measure involved in criminal activity," he said. "The really bad spyware is intended to steal information off of the computer."

Truly malicious spyware can do things like send information from accounting software like QuickBooks, or track online banking activity. "Once they get things like that, they can drain your accounts and get the money out of the country so there's no way to trace it," Methvin said.

That leaves SMBs vulnerable. Many don't even have spam-filtering software, which is the first line of defense for spyware at corporate sites, Methvin said. He estimated that most spyware at businesses comes in through spam.

"They just don't have the stuff that corporate guys do -- firewalls or things that make email nice and clean," he said. For example, Cass said MediSync doesn't have antispyware software, although he does harangue users frequently about safe computer usage, and he does have built-in guards within Windows that don't allow users to install their own applications. "I'm worried, but it's a playing-the-odds kind of thing," he said. "I have to pick my battles, and we need to spend IT resources on other things."

Methvin said that at an absolute minimum, SMBs should have antispyware software and some soft of email filtering technology that's more than antispamware. Many SMBs will start with individual licenses from companies like McAfee Inc. and Symantec Corp., but that can get pricey fast as the company grows. And enterprise versions of security software are also expensive. "I tend to see SMBs using individual tools," Methvin said.

He added that while there are several very good free products out there, always a help for a cash-strapped SMB, most require a fair amount of in-house expertise. And while Microsoft plans to offer Windows Defender in its next version of Windows, that won't be shipped until early next year. The good news is that companies are finally starting to come out with SMB versions of antispyware. (See SearchSMB.com's "Spyware-fighting offerings aplenty".)

The bottom line, however, is that you have to start with something. "Whether an enterprise or an SMB, you really have to be proactive about your defense," DiDio said, "and there's no lack of tools and utilities out there. The trick is what works for your resources."

Carol Hildebrand is a contributing writer based in Wellesley, Mass.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Risk management for the midmarket
Legal Expert: MDM can advance compliance goals
Database security: Limiting access is key
San Francisco network lockup justifies CIO fears
Security monitoring tools: Better to buy than build?
Risk assessment frameworks easy to employ
Marquette CIO enhances student safety with virtual patrolling
Spyware defense for the midmarket
How to choose a DR service provider
Data destruction made simple and cheap
Spyware menace eludes SMBs

Security tools for the midmarket
Legal Expert: MDM can advance compliance goals
Database security: Limiting access is key
San Francisco network lockup justifies CIO fears
Security monitoring tools: Better to buy than build?
CIO Kathy Lang: Virtual patrolling center enhances campus safety
Marquette CIO enhances student safety with virtual patrolling
Spyware defense for the midmarket
Anti-spam tricks for the midmarket toolbox (expert podcast)
Compliance-burdened CIOs turning to security management tools
Information security requires organized teams

Information security management for the midmarket
San Francisco network lockup justifies CIO fears
A cloud computing takeover? Google thinks so
An IT spring cleaning for CIOs
Single sign-on: Sensible security on scale
Spyware defense for the midmarket
Federal breach notification stuck in Congress
Anti-spam tricks for the midmarket toolbox (expert podcast)
Pre-emptive strategy best approach to breach notification
CIOs under fire and in front of the camera
Compliance-burdened CIOs turning to security management tools

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts