One in four (26%) IT security staff admit to abusing administration privileges to access confidential business information.
This is according to information security specialist Lieberman Software, in its latest password survey of more than 300 IT professionals.
The survey showed a fundamental lack of IT security awareness in enterprises, particularly in the arena of password control and privileged logins. Lieberman Software says IT administrators abusing their privileged login rights to access classified information could pave the way for a further wave of data breaches in 2012.
Around 42% of those surveyed said that, in their organisations, IT staff share passwords or access to systems or applications. In addition, 26% are aware of an IT staff member abusing a privileged login to illicitly access sensitive information.
According to the survey, 48% of respondents work at companies that do not change their privileged passwords within 90 days - a violation of most major regulatory compliance mandates, and one of the major reasons why hackers are still able to compromise the security of large organisations.
Philip Lieberman, Lieberman Software president and CEO, says organisations need to introduce privileged identity management software to add a layer of automated security that dishonest staff cannot bypass.
“Organisations that fail to do this could end up in the same situation as UBS AG, which lost $2.3 billion when rogue trader Kweku Adoboli was allowed unfettered access to their systems, and Soci'et'e G'en'erale, which lost $7 billion when Jerome Kerviel was allowed to run up 'secret trades', which senior management knew nothing about.”
For many organisations, unmanaged privileged account passwords are the backdoors by which hackers find their way into the enterprise's most sensitive data, according to Lieberman. He adds that if almost 50% of all passwords remain unchanged, as this survey discovered, then fundamental and basic IT security practices are being ignored by staff and their senior management.

