Skype Security: Is It Safe for Business?
CSO - According to data released last month from research firm TeleGeography, Skype, the popular software that allows computer users to make calls over the internet, now accounts for 12 percent of all long-distance calls. The company saw its user base grow to more than 500 million accounts in 2009 and is making a run at a new market this year.
So far, the popular VOIP provider has been primarily used in personal, consumer settings. But in 2009, Skype launched Skype for SIP, a service that lets its peer-to-peer VoIP clients interact with existing IP PBXs and is aimed at small businesses looking to get in on the cost-savings of internet telephony. Skype for SIP (also know as Skype for Business) was launched in beta early last year and brought into public beta at the end of 2009.
Also see VoIP Security: The Basics for more about DDoS, eavesdropping and other VoIP threats
While many large businesses have used VOIP services for years, those enterprise-class VOIP systems typically used in corporate environments differ from Skype, according to Michael Gough, an information security specialist and president of the Austin, Texas, chapter of ISSA. Gough, owner of the web site skypetips.com, and author of Skype Me! From Single User to Small Enterprise and Beyond, gave CSO his thoughts on Skype's benefits and challenges in the business environment.
CSO: We know that Skype is making a play for business customers with Skype for SIP. But as it stands now, do you think it is used in many business organizations?
Michael Gough: Predominantly it is still used by individuals, but a lot of small-to-medium-sized businesses utilize Skype to cut costs for things like road warriors. Another common use I've seen in business is in outsourcing off-shore resources like help desk or support scenarios where you have a lot of people outside your state and doing off-hour support. Often Skype is an option for some of these companies.
Are there security concerns with Skype that are unique when compared to other VOIP solutions?
In any corporation, if you are going to install software on end-users computer, you have to do your governance. You have to set the rules that govern what you are going to do or allow with any piece of software. So every enterprise has the challenge of controlling the proliferation of Skype into the environment. If you're a local administrator, and you're going to install the product, now, all of a sudden, you have texting and voice conversations that are potentially encrypted and something that the enterprise or company can't monitor. That is definitely a challenge.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts