« July 2007 | Main | September 2007 »

August 22, 2007

Web 2.0 Harmful to Security

From an intranet perspective you may have thought that Web 2.0 was a fad, or at worst, a distraction. However, today’s Financial Times reports that staff who enter their personal or corporate details on social networking sites such as Facebook and MySpace are providing opportunities for fraud. Individual and department names or phone numbers can be used in phishing or identity theft while the name of a pet, favourite colour or daughter’s birth date might prove useful in hacking passwords.

This raises the need not only for a policy on whether these sites should be available through corporate networks – if you are trying to locate just the right ex-colleague for a job or project then Facebook could provide just the answer – but also guidelines on what information staff should enter into the public domain outside of the office.

What the article does not delve into, though, is why Web 2.0 is any different to the myriad job sites containing corporate details embedded in CV’s. It could be just another case of specialists jumping on the bandwagon that appears to be attracting the most attention. But to err on the side of caution, consider what a hacker armed with personal details might be able to achieve within your organisation.

August 16, 2007

Intranet search still a poor cousin

We started to include intranet search – for people and content – as part of the standard IBF design evaluation in 2006. Now in August 2007, we have seen quite a few different implementations, but with only a few exceptions, intranet search is still very much a poor cousin to the public internet variety. People search, in particular, is fond of declaring ‘no results found’ when a user has made only a simple single-character typing error, leaving them with no choice but to try various permutations until they get lucky. At least with a printed staff directory, frustrated users could thumb through until they found what they needed, but most intranets lack the electronic version of this fallback solution. Quite simply, if you don’t know how to spell the name you are looking for, you’re stuck.

Ironically, one of the solutions we have been persuading intranet managers to take up is almost a century older than intranets themselves. Soundex is a fairly simple set of rules to turn similar-sounding names into a four-letter code. It does have some drawbacks and should not replace a simple text match as the first step in a search, but it is implemented by most scripting languages and is fairly forgiving of spelling and typographical errors.

Content search does a little better in our scoring, but even here we find poor regard for the user experience, with no mention of the original text searched for and scolding messages for choosing search terms that yield too many results. Yet public internet search is very big business indeed, with companies like Google and Microsoft falling over each other to retain or capture market share, respectively. The driving force behind this enthusiasm is advertising. Unfortunately, there are no similar forces at work on intranets. While a few enterprising organizations do actually carry third-party advertising on some pages, the economic model for getting search right is completely different. It is all to do with saving time and frustration within a captive audience. So what is needed is a means of measuring and improving the perceived value of search within an organisation. Knowing how long a user has spent searching and whether they were successful would be a step in the right direction, but there is little evidence that even this basic level of measurement is taking place. Perhaps this is something we should be including in our benchmarks? Let us know what you think.

August 01, 2007

Team blogging - an idea for intranets?

The fact we at IBF are 'team blogging' has in itself raised comment this month, which has prompted an article on the IBF website and blog review.  Let us know what you think... does a changing author of a blog lessen the value of that blog, or does it actually provide a broader viewpoint? 

Maybe, with so many companies considering corporate and CEO blogs for their intranet this is a model they should consider?  A 'leadership team' blog.... less onus on one member of the team to blog every day and a variety of viewpoints for employees to consider?

Toby Ward discussed intranet blogging earlier this year and offer good advice for those considering the idea in his article

It's the last day of July, so I shall be signing off as the IBF blogger for a while.  It's been a new and interesting experience and I'd like to thank everyone who has left comments and enabled discussion and debate.