Interview: Firms must tackle spyware

Companies must bolster their defences against the growing threat of spyware, argues Richard Stiennon of Webroot Software

Written by David Neal

Richard Stiennon, vice president of threat research at Webroot Software, the firm behind SpySweeper anti-spyware tools, says the amount of snooping software is growing, though many internet users are currently unaware of the danger.

"Like spam threatened the online network and affected email use, so spyware is hampering the browsing experience," says Stiennon. "We are tracking 150 new pieces of spyware every week and that's not counting the 50 to 60 morphed software tools already out there. It seems like all spyware is written just to take advantage of Microsoft weaknesses so we are waiting to see the first kind that exploits the JPEG vulnerabilities."

Stiennon warns that unless firms do more to protect their systems, sensitive information could be intercepted, and companies could also face prosecution for failing to guard data in compliance with various corporate governance laws. "By exploiting most of the Internet Explorer vulnerabilities, spyware can take over web pages and generally re-direct users. In the worst cases it can lead to the taking of personal information, potentially putting firms at risk of breaching compliance with rules such as Safe Harbor [for data exchange with foreign countries], the UK Data Protection Act and Sarbanes-Oxley [a corporate governance law for firms listed in the US]," says Stiennon. "It is just as easy to be infected in this way as it is with a simple re-direct and you would have a real problem claiming that you had done everything you could to comply with best practices if you let something like that happen."

Stiennon argues that there is a requirement for consumer and enterprise versions of anti-spyware tools, because the two groups have different needs. "There are free [anti-spyware] tools available, and in some instances within the enterprise the IT professional will suggest that these are used to clean up isolated incidents, but when someone like the chief executive is involved, and if his machine is compromised, then they will look for a proper [enterprise] solution," he says.

Stiennon says that one difficulty for IT managers is that it is hard to estimate the true extent of the spyware threat, but adds that they cannot afford to be complacent. "There are a lot of enterprise problems but I only have anecdotal evidence of how many," Stiennon adds. "At a recent event I asked the audience how many had suffered with a spyware problem and every hand went up. In a recent survey Webroot found that up to 65 percent of 271 respondents had some kind of [anti-spyware] solution in place, but 98 percent of these admitted it was a free tool [rather than a stronger product designed to guard enterprises]."

Stiennon believes most users are still unaware of the impact spyware can have on systems. "Often you will get someone calling to say that their PC is running slow and they need a new one, when their existing PC just needs cleaning up. You'll find that there will be so many different pieces of [spyware and similar] software on their machine that it just slows down."

Get IT news on the move with our Pocket Edition.

About Richard Stiennon

Richard Stiennon is vice-president of threat research for anti-spyware tools vendor Webroot Software.

Before joining Webroot, he was vice-president of research at analyst company Gartner, where he covered security topics.

Stiennon joined Gartner from PricewaterhouseCooper's Technical Risk Services group.

Tags:

reader comments

related articles

Global spyware plague

Two thirds of all PCs infected with spyware

Epidemic costing millions as malicious software runs riot 01 Dec 2004

 

Spyware-Adware Exterminator Pro

Protect yourself from spyware and worms 11 Oct 2004

Hack attacks and spam set to increase

IDC warns of the growing importance of enforcing security policies 07 Oct 2004

Global firms ignoring web-based threats

Security vendors highlight growing threat of internet-based malware 18 Nov 2008

Infosecurity Europe show to focus on data breaches

Annual trade show will see the launch of the annual Information Security Breaches Survey 17 Apr 2008

Kaminsky delivers DNS dirt

Researcher explains risks behind flaw 07 Aug 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation