The problem: Internal websites are a great place to park company data, but a special kind of Web gateway called a proxy server can act as a revolving door for sensitive information. Several years ago an Internet prankster used an open proxy to tinker with a wire service story on Yahoo News and to access the New York Times's database of op-ed contributors.
The solution: Configure all Web proxies as one-way doors so that Web requests can pass from your intranet to the Internet, but not vice versa. Use a security scanning program like the open-source Nmap to probe for open ports and unprotected servers.