Context Security

Tag: insider

Layoffs==Data Leakage

by seth on Dec.06, 2008, under Security

Recently read some interesting results of a survey/study carried out by Cyber-Ark… The associated press release can be found here: http://www.cyber-ark.com/news-events/pr_20081201.asp.

Though the headline is _somewhat_ surprising, “…Nervous workers offer to double their hours and reduce their salaries to secure employment”, it is largely innocuous when compared to data that comes to light in the second paragraph.

“When confronted with the prospect of being fired tomorrow ethics go out the door (so to speak), 71% surveyed declared they would definitely take company data with them to their next employer.” (emphasis mine)

Ouch.  71% of seemingly loyal employees would walk away with data, including: “customer and contact databases, with plans and proposals, product information, and access / password codes”

Of course almost every company I have every worked with has had at least some measure of the “that would never happen to me” syndrome.  Some companies would sit back smugly and think that their termination procedures, exit interviews, and general “tight ship” would prevent this potentiality.  Then we read again…

“…more than half have already downloaded competitive corporate data and plan to use the information as a negotiating tool to secure their next post” (emphasis mine)

Rather a scary proposition if you ask me.  We should of course keep in mind that these statistics come from a vendor who has a widget to help with the problem…  Regardless of the numbers, however, in the current economic climate employees have reason to be a bit scared.  When scared, some will have a tendency to act a bit more impetuously than than their reason would otherwise dictate.

I don’t intend for this to be yet another article bemoaning the virtue of DLP solutions.  Honestly, these employees are insiders with access, who are motivated by fear of losing their ability to provide for themselves and/or their families.  I think most of the technical controls attempting to prevent this leakage would be left wanting in the face of a thusly motivated insider.

I honestly think awareness training/reminders are likely the only thing that could be very effective in this situation…  Sadly, the best solution is likely to have a unabashedly solvent company in the first place…

Leave a Comment :, more...

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!