How Secure Is Your Call Center? Endpoint Device Security
The word security covers what seems like a countless number of fronts that can be exploited: network access, the protection of employee phones and mobile devices (especially if you allow BYOD), the physical safety of hardware, and every nook and cranny in between. Inadequate security opens systems up to threats, and threats translate directly into lost profit and lost productivity. I want to focus this entry on one front that gets less respect than it deserves: endpoint device security.
Some administrators subscribe to the mindset that servers and the devices belonging to high-value employees deserve more attention than a typical entry-level desktop. I understand the instinct; there are only so many hours in the day, and the executive laptop feels more important than seat 47 on the call floor. It is a poor practice, and a potentially dangerous one. In a call center environment, the entry-level desktop is often the riskiest machine in the building. Agents who are teleprospecting, verifying contact information, or nurturing leads generate an enormous amount of web activity across sites nobody in IT has ever heard of. High web activity is one of the biggest contributors to virus and malware exposure, so a reasonable argument can be made that those users need more protection than anyone else, not less.
The unglamorous work matters most here. Keeping client software like Adobe Flash and Java current is vital; the majority of the infections I have cleaned up in the last few years came through an outdated browser plugin rather than some exotic exploit. Agents should be running with standard user rights, not local administrator rights, and the machines should be built from a known-good image so that a compromised desktop can be wiped and redeployed in minutes instead of hours. When a machine holds nothing locally and every agent profile lives on the server, reimaging stops being a crisis and becomes routine maintenance.
Appropriate protection for endpoints matters just as much as protecting your production servers and storage, because the two are connected. A single compromised PC can put an IT department into a reactive mess when malware spreads to a critical server, particularly the newer families that mimic legitimate processes such as the certificate validation used by Microsoft Update. An organization has to protect all of its devices with the same seriousness, because they are all links in the same chain, and attackers are happy to start at the weakest one.
The protection options are vast. Most of the well-regarded suites are client/server models where a centrally managed console gives administrators one place to push definitions, view alerts, and quarantine machines. There are also hosted offerings where a vendor manages endpoint security for you. In practice, no single product covers everything, and relying on one vendor or one application has become antiquated. The best practice is a layered approach: a solution at the client, another at the gateway or firewall, and applicable controls in between. Each layer increases the odds of stopping something before it reaches its intended target, and just as importantly, each layer gives you a second set of logs when you are trying to reconstruct what happened.
Endpoint protection goes beyond antivirus, too. Email and spam filtering are better handled at the enterprise level than on the client; a hosted service such as Google Postini, Microsoft Forefront, or Symantec MessageLabs can reject malicious mail before it ever touches your mail server, which means the endpoint never gets a chance to make a bad decision. And beyond the traditional infection paths, administrators need to remember that mobile devices can introduce malware to a PC through USB or Bluetooth. A seemingly harmless smartphone charge at an agent’s desk is a data connection whether the user thinks of it that way or not. Disabling front-of-PC USB ports and Bluetooth adapters through group policy closes that door quietly, and in my experience it generates far fewer complaints than people expect, provided you offer a sanctioned way to charge phones.
Keeping an organization’s endpoints clean is an arduous, constantly evolving task. In the cat and mouse game between malware authors and protection vendors, the bad guys are frequently a step ahead, so staying current on patches and updates is not optional. The floor of a call center will never be as tidy as a server room, but it deserves the same discipline. Treat every desktop like it matters, because to an attacker, every one of them does.