Comment Yes, unfortunately (Score 1) 460
I fear it is a common occurrence. The problem is not so much risk, as the IT professionals are generally safer about where they go on the web. The problem is one of perception, and of policy.
When IT professionals ignore stated policy and do what they like, it tends to do several things. One is resentment, and it helps degenerate the relationships between It and the users, which hurts the company. The second problem is it creates problems amonst policy. If IT doesn't follow policy, then users may feel free to ignore or go around policy as well. In addition it makes policy harder to enforce, when some people get away with ignoring policy while others are punished for the same.
If you have a good security department, they will make sure policy is enforced equally for all users, otherwise your policy is as bad as never haven been written at all.
I am sure I will get slammed by some here for saying it, but it is true. IT needs to foster better relationships with its users. One way to do that is not to ignore policy, and pretend it doesn't apply to you. Your security is at stake here, and the bottom line of the company.