Lack of equipment interoperability and confusion over who is responsible for security are to blame for the lack of security in voice over IP (VoIP), an issue that IT administrators say is a major concern for them, experts speaking at VON Europe on Wednesday said. The technology and standards that exist to secure VoIP are not the issue, said Tim Jasionowski, senior technologist for voice and rich media technologies at Nokia. The problem is that most enterprises aren’t using many of the technologies.That’s mainly because unless an enterprise uses a single vendor for every piece of equipment in its network, including phones, IP-private branch exchange, firewall and all other components in between, then security technologies such as transport layer security (TLS) and others are unlikely to interoperate across multivendor equipment, he said. Even if an enterprise decided to standardize on a single vendor, it might have additional limits on the products it chooses. That’s because not all major vendors are building support for security standards like TLS into their products, and those that do don’t necessarily support it across their entire product range, said Cullen Jennings, distinguished engineer at Cisco Systems. Once enterprises decide to extend VoIP into mobile devices, they face additional problems, but once again not because the standards and technology don’t exist. Ideally, an enterprise might want to run Wi-Fi Protected Access to secure the Wi-Fi connection on a wireless device, an authentication mechanism for users that may attach to public hot spots, a VPN for accessing the corporate network and possibly other security techniques. “That’s great if you have a nuclear power plant in your pocket attached to your mobile phone,” Jasionowski said. Running all of those security applications requires processing and power, both features in short supply on mobile devices. In addition, the market hasn’t fully worked out who exactly is responsible for security and who is responsible for enforcing that security, said Ari Takanen, chief technology officer for Codenomicon. Currently, layers of security are offered by service providers and equipment makers, and sometimes their efforts overlap. Without the clarity of claimed responsibility, no source is liable for security issues, he said. Enterprises can improve their chances of being able to boost the security on their VoIP networks in a couple of ways, including carefully examining the type of tests that vendors say they run on their products to make sure they work, Takanen said. Organizations like the Protos Project, a collaboration between the Finnish University of Oulu and VTT Electronics, can help buyers test products, he said. In addition, enterprises are responsible for demanding that vendors interoperate, Jasionowski said. In the meantime, product managers are making decisions against interoperability against the advice of their engineering staffs in hopes of securing more business, he said.-Nancy Gohring, IDG News ServiceCheck out our CIO News Alerts and Tech Informer pages for more updated news coverage. Related content brandpost Resilient data backup and recovery is critical to enterprise success As global data volumes rise, business must prioritize their resiliency strategies. By Neal Weinberg Jun 01, 2023 4 mins Security brandpost Democratizing HPC with multicloud to accelerate engineering innovations Cloud for HPC is facilitating broader access to high performance computing and accelerating innovations and opportunities for all types of organizations. By Tanya O'Hara Jun 01, 2023 6 mins Multi Cloud brandpost Survey: Marketers embrace AI at expense of metaverse investments Generative artificial intelligence (GAI) has quickly rocked the world of marketing. Sitecore polled B2B marketers on their perceptions of GAI. Here’s what they said. By Dave O’Flanagan, Sitecore Jun 01, 2023 4 mins Artificial Intelligence news Zendesk to lay off another 8% of its staff, cites macroeconomic issues The new tranche of layoffs comes just six months after the company let go of 300 staffers and hired a new CEO in order to navigate its operations through macroeconomic distress. By Anirban Ghoshal Jun 01, 2023 3 mins CRM Systems IT Jobs Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe