September 21, 2009

Stupid user tricks 4: IT horror never ends

Nine more real-world disasters courtesy of your network's weakest link

Nothing can screw up a well-managed network faster than the people for whom you built it. Whether it's user error, optimistic expectations, or simply that bastard Murphy, IT's job is rarely predictable.

Lucky for you, there are lessons to be learned from others' misfortunes. So rather than wait to make your own forehead-shaped dent in the office wall, familiarize yourself with the screwups detailed below. It will make you that much more prepared to safeguard your IT environment from the ever-evolving boneheaded tendencies of those you serve.

Stupid user trick No. 1: Home is where the malware is
It happens at least once a year, and this year it happened twice, writes one IT admin: "And though we make the point with memos and lectures, there always seems to be someone who gives their work PC to the kids at night."

[ Users are by no means alone when it comes to hard-headedness in the IT world. See "Stupid user tricks 3: IT admin follies" and "True IT confessions" for real-world tales of folks who should know better fouling up. ]

The situation is familiar: To save on expenses, folks buy fewer home PCs, but their kids want to use them more than ever. Enter the corporate laptop into the home Web surfing environment -- a recipe for disaster for IT.

And it's not just kids playing games and doing homework. It's spouses using social networking -- and that uncle nobody talks about surfing porn on your corporate machines.

"Our security tends to be better than the average home box, but that won't protect you forever if you actually run out and look for attack sites," our admin warns. Sooner or later, one of your user's laptops will get compromised, leaving your network exposed to infection the next time he or she logs on at the office.

"We've gotten better at catching these compromised machines early, so instead of it being the big problem it used to be, last year it mainly just confirmed our investment in end-client security," the admin says.

The worst offender? A procurement manager who was found to have a keyboard logger installed on his company-issued laptop. "And this was a guy who spent several $100K a year online for the company," the admin informs us.

Solution: End-point security goes a long way toward preventing infected machines from gaining access to the corporate net, but they'll never be 100 percent effective. Web browsers are the gateway to hell when it comes to attack entry points. Let your users surf helter skelter and your attack potential goes way up. The only preventative measure: a strong fair-use policy and a management staff that'll enforce it.

Moral: Users will continue to break your official-use policy as long as money is tight and they believe the consequences are minor. Include disciplinary action in your policy, and make sure users know you're tracking Web site visits and system access. Otherwise, you are simply setting yourself up for disaster. Another solution: Sponsor employee discounts on netbooks. That way, your users will be less tempted to transform company property into their home PCs.

Close

On Twitter now

Misadventures

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
Non-IT-Type 21-Sep-09 10:37am
1 reply
I think "Stupid User Trick #2" where the users create a really nifty search function using email and Outlook is a brilliant bit of productivity negated by the IT horror of having to buy cheap storage to make up for expensive people time. I can tell you guys never thought up Google. Maybe you should be out in the La Brea Tar Pits inspiring the other dinosaurs.
garyisabusyguy 21-Sep-09 2:25pm
2 replies
I have been in IT for over 20 years and I love running searches against my Outlook inbox, it has saved my butt many times. Recently our company attorney has decided that this leaves our company 'exposed' (not sure about the what or why of it), and convinced upper IT management to flush everything out of inboxes that is over 3 months old. So, what is the remaining solution? Copy everything to a local personal inbox? Extract all emails and store them in SQLServer? Certainly no good solution, and I seriously want to know the 'what' of the exposure and the 'why' of pushing this out into a user community that uses inboxes much like I do.
aemeijers 22-Sep-09 4:34am
Chuckle. In the government world, e-mail is not considered a proper records storage and retrieval system, although prertty much everyone (me included) uses it as such. Your lawyers are worried that in a court case, if they answer a subpeona for records about something, and they miss an old e-mail, it could lead to losing a million-dollar court case.

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Adventures in IT Newsletter

Get a weekly dose of the humorous side of IT.

©1994-2009 Infoworld, Inc.