Bob Evans

Senior VP, Global CIO


 Email  Print  Share

0 Comments

Channel: Global CIO

See all blogs by Bob Evans

Fearing Layoffs, Most Workers Willing To Steal Data

Most workers frightened by the prospect of layoffs are considering stealing corporate data to use in negotiating for a new job, our excellent sister site Dark Reading reports. They're angry, scared, desperate, and unsophisticated -- but you, the CIO, are cool, calm, and confident because you're prepared for such an onslaught. Right? Well -- you are prepared, aren't you?

The numbers from a range of surveys are scary: 56% of workers in one study are afraid of losing their jobs, and in two other studies 71% of workers said they have either already stolen customer data or are fully prepared to do so, according to "Insiders Pose New Threats In Down Economy," by Dark Reading editor Tim Wilson.

The frightening outlook extends beyond speculation about possible future behavior to hard facts about a surge in unauthorized actions by employees, according to the Dark Reading story:

"...IBM's ISS X-Force research team [reported last week] that it has detected a 30% increase in network and Web-based security events in the past 120 days, with the total number rising from 1.8 billion per day to more than 2.5 billion worldwide. The researchers attribute a significant portion of the uptick to insider activity motivated by economic fear.

"Unlike a 'quick firing,' tens of thousands of employees are readying themselves for the eventuality of losing their jobs -- and no doubt a high percentage of them [will be] 'disgruntled,'" said IBM security expert Gunter Ollmann in a blog earlier this year. "In today's computer-based work environment, with a little planning and forethought, a disgruntled employee can do a lot of damage with little fear of being caught and prosecuted."

If there's any good news in this unprecedented scenario, Wilson wrote, it is the relatively unsophisticated approach being taken by many employees concerned about losing their jobs and willing to steal from their current employers to improve their chances of finding new employment. Kevin Rowney, founder of the data loss prevention (DLP) unit at Symantec, formerly known as Vontu, gave this analysis to Dark Reading:

"Every day we're stopping more and more of these sorts of events -- many more than we saw before the downturn. It's a sad fact that rates of employee fraud rise in a down economy." Most of the economically motivated insider attacks are not particularly sophisticated or even well-thought-out, Rowney says. "In general, these are crimes of passion committed by employees who are angry or scared," he explains.

"These are not people who are sophisticated in IT, developing super-sneaky ways of stealing or sabotaging data without being detected. They're people who are under pressure, or who are mad and seeking vengeance, and they make a large cluster of bad decisions. In most cases, these are fairly obvious activities that can easily be detected if you have the right tools in place."

So we have met the enemy and it is us -- as CIO, are you fully prepared for this unprecedented level of inside attacks? If the CEO comes in and asks for your level of confidence, expressed as a percentage, to stop insider cyberthreats, what number would you offer: 75%? 80%? 90%?

If your answer isn't at least 90%, you need to read this Dark Reading piece immediately and then assign a team to follow some of the steps it outlines. Because here's one more thing the article points out, courtesy of RSA director of product marketing Katie Curtin-Mestre:

"We've seen clients that think they have only one instance of a database, and then through the discovery process, they find that there are 18 unauthorized copies of the data spread around the enterprise. These companies are in no position to leverage policies and controls because they don't know where the data is."



This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.


CIO TV

National Semiconductor Company takes the top spot on the InformationWeek 500 list of the nation’s business-technology innovators. ; 2008 InformationWeek 500 winner; collaboration; InformationWeek500 conference; innovation; National Semiconductor; product development; Techweb TV; Ulrich Seif; virtual inventory; Fritz Nelson spoke with Kent Kushar, the CIO of E&J Gallo Winery about what it takes to be the best and what qualities tomorrow's CIO should possess.; CIO's Uncensored; Gallo Winery; Kent Kushar; TechWeb; Tomorrow's CIO; One of the industry's leading CIOs, Ralph Szygenda, talks about what it takes to be a CIO and what tomorrow's CIO will have to do to prepare.; CIOs; General Motors; Informationweek; Ralph Sygenda; TechWeb; Techweb TV; Tomorrow's CIO; Fritz Nelson spoke with Dan Drawbaugh, last year's InformationWeek Chief of the Year, about what qualities tomorrow's CIO should possess. Dan is the CIO of the University of Pittsburgh Medical Center.; CIO's Uncensored; Dan Drawbaugh; Techweb TV; Tomorrow's CIO; CIOs from State of Michigan and National City Corporation Talk About the Innovative Projects their Teams Have Been Executing On, Including Core System Replacement and Business Portals; CIO Innovation; CIO Symposium; CIOs; Informationweek; MIT; TechWeb; Techweb TV; Scott offers his perspective on software innovation, the role of analytics in Disney's business, and more.; analytics; career; CIO; customer relationships; digitization; innovation; software; software as a service; Carter says the notion that innovation is dead is "preposterous!"; access; career; CIO; Connectivity; globalization; offshore outsourcing; software as a service; software innovation; Web 2.0; Redshaw sees a resurgence in software innovation and talks about the benefits of software as a service and SOA at Motorola.; business process management; career; CIO; software as a service; software innovation; Web 2.0; web services; Phillips talks about the benefit of global IT standards, innovation spending, and the future of IT careers.; business process management; career; CIO; global standards; governance; IT education; metrics; scorecards; Bailar discusses the role of IT in business growth, his must-read business book, agile development and he offers up some advice to the software vendor community.; agile development; business books; business performance; business process management; Call Center; CIO; customer relationships; innovation; IT effectiveness; productivity; Project Management; roi; scorecard; time-to-market; The co-authors of "The New Age Of Innovation" talk about their basic concepts of N=1 and R=G. ; CIO; customer intimacy; e-commerce; General Motors; globalization; Ralph Szygenda; re-engineering; GM's tech leader talks about consolidating, re-engineering, upgrading the company's application infrastructure. ; CIO; complexity; General Motors; globalization; integration; legacy systems; privacy; Ralph Szygenda; security; What does it take to be a CIO in the customer-oriented, globalized business environment today? Ask Ralph. ; business; CIO; customer intimacy; General Motors; infrastructure; Ralph Szygenda; supply chain; Learn how GM is building a global IT environment and what it takes to be labeled a dinosaur around his organization.; architecture; business acumen; business process outsourcing; collaboration; complexity; consumer technology; Global IT standards; globalization; IT management; real-time; roi; security; virtualization; Hear Randy's vision for the data center of the future and how he intends to slay the legacy monsters.; applications; business acumen; business processes; business-IT alignment; centralization; CIO career; complexity; data center consolidation; data centers; Data Warehouse; Efficiency; leadership; portfiolio management; reducing risk; roi; scalability; His challenge? Creating open environment for Internet users without compromising information security and privacy.; broadband; business acumen; capacity; CIO; CIO role; content generation; data centers; infrastructure; internet; privacy; security; social networking; video; Web 2.0; She considers business acumen just as important as technical knowledge for a CIO. Here's why.; business acument; Business continuity; career development; disaster recovery; IT recruitment; IT-Business Alignment; roi; security; wireless;