Palo Alto Networks' latest Application Usage and Risk Report has suggested that while social media has become pervasive in organizations worldwide, usage has far outpaced controls. Results in the latest report point to the financial services and healthcare industries as heavy users of social collaboration tools, but very often with no provisioning for associated risks such as non-compliance, data loss and threat propagation.
The semi-annual study is based on assessments of real-world application traffic in hundreds of organizations worldwide.
The report showed that 94 percent of the healthcare and financial services organizations included in the study use an average of 28 social networking applications, including Facebook, Twitter and LinkedIn. Both industries have regulations (such as HIPAA and FINRA) that require organizations to control and monitor information flow across social networking applications in order to protect the confidential data they manage.
However, as IT managers and software engineering professionals will be aware, social networking apps use port 80 or port 443, so all traffic to support these apps will be browser-based traffic. This lack of visibility into social networking traffic could be a violation, or lead to violations, of compliance with industry rules and regulations.
"IT managers cannot simply block Enterprise 2.0 applications since they deliver clear business value. Nor can they simply allow these apps to run amok on their networks. IT needs to safely enable Enterprise 2.0," said Rene Bonvanie, vice president of worldwide marketing at Palo Alto Networks. "By defining and enforcing policies that safely enable these apps, IT can enhance business productivity while mitigating security risks and compliance violations."
Developers, IT architects and project managers of every kind tasked with working in these environments should arguably consider these industries' use of technology such as webmail, which portend a variety of business and security risks, from compliance violations and data leakage to malware propagation -- and this concern may be even more of a challenge for third-party consultants coming in to work with these companies.
Two-thirds of the 750 applications tracked, even client server and peer-to-peer (P2P) applications, can pass as web traffic by hopping ports, using port 80, or hiding within SSL. Palo Alto says that this debunks the myth that ports 80 and 443 are reserved for browser-based traffic only. If P2P file sharing applications look like web traffic, then they are difficult to detect and control. This dramatically increases the risk of inadvertent data leakage.