Drip, drip, drip goes the data as leakage threat rises
Threat outpaces danger of disgruntled employees in new IDC poll
Computerworld - Beware: your data may be leaking. According to a recently published IDC security survey, the threat of data seeping out of a company through innocent employee messaging activity is on the rise.
That's the most surprising finding of a study titled "Worldwide Information Protection and Control (IPC) 2007-2011 Forecast and Analysis: Securing the World's New Currency." This inadvertent leakage threat has risen to fourth in importance behind viruses, spyware, and spam, while intentional theft by employees with a criminal or otherwise malicious agenda has actually fallen in rank, and now sits in seventh position.
According to Willy Leichter, Tumbleweed Communication Corp's, director of product marketing, that finding became a key factor when his company designed the software embedded in the Redwood City, CA-based company's new MailGate 3.5 security appliance.
The software's new dashboard-based user interface includes a robust set of options that enable security professionals to create policy management rules that watch for employees inadvertently sending confidential or other key information, such as earnings forecasts, company credit card numbers, or even their own social security or credit card numbers, embedded in outbound e-mail messages. The options also include a more normal set of policy tools designed to fulfill the compliance requirements of HPPA, Sarbanes-Oxley, and other regulatory and corporate policy requirements.
Security or other administrators can specify actions ranging from basic incident reporting to complete message blocking. "They are presented with a wide variety of options in a series of hierarchical checkboxes," says Leichter, "and there is enough variety there to let them set their policies and actions up however they need to." When asked if existing users can migrate current policies to the new software, Leichter said that they could, but if they did that they would not be able to take advantage of important new control opportunities, and the more flexible user interface.
Also included in the MailGate 3.5 software is Tumbleweed's latest multi-layered spam defense technology. New in this mix is an IP reputation filter system to weed out spam from disreputable senders that is based on a data base of 100 million IP addresses, and real-time zombie detection that is designed to block spam at the enterprise gateway. Those technologies teams up with Tumbleweed's Edge Module to do recipient verification, intelligent traffic shaping, and message throttling that is designed to stop directory harvest and denial of service attacks.
"It is time for straight talk," says John Thielens, Tumbeweed's vice president of technology, "it is time for vendors to stop extorting enterprises for technology to protect sensitive data, and our new MailGate software makes us the voice and the technology of reason." He adds that botnets are not going to disappear any time soon, and companies have to take matters into their own hands if they want to drive botnet traffic off their networks.
The new MailGate 3.5 appliance will be available late in July of this year, with prices starting at $5,000. Users of existing MailGate appliances can upgrade their software with the new 3.5 version free of charge.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts