|
Run a tool such as LanGuard to do what is called a vulnerability assesment. LanGuard will provide a free 30-day license, which will allow you to scan your network for weaknesses. In the past it was okay to have secuirty threats inside the network, but not anymore. Your internal systems should be as secure as any Internet device. The LanGuard tool will provide easy to read reports, plus do a whole bunch of things that you are usally changed $10,000 plus by security consutlants.
Also, your colleague is playing with fire and can be terminated if caught.
As for monitoring you can install a simple IDS system such as SNORT (which
is free, but sometimes cumbersome to setup) or invest in any of the IDS
technologies. (Here are some IDS vendors: Symantec, Entersys, Tenable and NFR Security)
|