My advice to them? Don't obsess about it. There are some cases where you should be concerned about the physical
security of your network, but at some point you're either going to have to trust an outside provider or run a cable through a secure area. In the case of this particular client, the risk seemed acceptable.
In the scenario you describe, an outside manhole shouldn't be a great concern. Once the traffic leaves your private network and enters the public Internet (which is of course where it goes once it leaves your building), none of the sensitive data should be sent without using encryption. Proper data encryption mitigates the risk of interception. There's no difference between someone climbing down a manhole and tapping your external connection and an eavesdropping hacker that compromises an intermediate router somewhere on the Internet.
Dig deeper on SSL and TLS VPN Security
Related Q&A from Mike Chapple, Enterprise Compliance
Should companies obtain U.S. security clearance to join the Enhanced Cybersecurity Services program? Mike Chapple offers his perspective.continue reading
Does a Web application security assessment termed 'compliance ready' seem too good to be true? Learn its role in an enterprise compliance program.continue reading
Learn how hiring the right PCI DSS-compliant service providers, especially payment services providers, can reduce your compliance burden.continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.