Bob Evans

Senior VP, Global CIO


 Email  Print  Share

1 Comments

Channel: Global CIO

See all blogs by Bob Evans

The World Bank's Data Breach, And Its Sorry Follow-Up

The World Bank (annual IT budget about $250 million) has been hit by a range of data breaches, at least one of which involved info belonging to staffers. So a corporate guy overseeing IT has sent a flaccid memo to the whole organization. Take a look at the memo and ask yourself if it will make World Bank employees feel better -- or want to quit.

In a way, I feel a bit uncomfortable highlighting the impact of a data breach because in the past few years we've all seen the massive efforts organized crime, savvy individuals, and even ham-handed employees have made in trying to steal information from financial organizations. And when those hacks are successful, Lord knows there is more than enough blame to go around.

But this particular memo from the World Bank big shot, posted on the Web site of the Government Accountability Project, presents a level of detachment and arrogance that deserves to be called out. Look at the following excerpts from Managing Director Juan José Daboub's memo -- based on his message, does anybody out there think that Daboub was one of the World Bank employees whose information was exposed?

"Surveillance has also identified an inadvertent posting of confidential information on an externally accessible server by a Bank Staff member. The information included names and bank accounts for a number of staff members, but no other personal information.... The Credit Union has already taken precautions to monitor unusual activity on all affected accounts. Nonetheless, the WBG will provide affected staff with free credit-monitoring service, identify theft assistance, and other support.... All affected staff will by now have been notified by e-mail."

OK, so let's review: the exposed information includes names and bank-account numbers, but Daboub says that's OK because "no other personal information" was released -- well, heck, if that doesn't make you feel better, what will? Next, Daboub crows a bit in saying that the Credit Union is on the case with a promise to "monitor unusual activity on all affected accounts." Now, call me whiny, but isn't that a fairly common practice that any financial institution, let alone one affiliated with the esteemed World Bank, would have made a standard practice starting about 10 years ago?

And then Daboub, reaching once more into his deep bag of condescending remarks, says, "Nonetheless, the WBG will provide affected staff with free credit-monitoring service, identify theft assistance, and other support." You gotta love the word "Nonetheless" at the beginning of that sentence, where the real point of his message shows through: how much more do you sniveling little whiners expect us to do for you??

Plus, in his preceding sentence, Daboub says the Credit Union is going to "monitor unusual activity on all affected accounts," and that's dandy. But if that's already happening, then why does the World Bank also need to "provide affected staff with free credit-monitoring service?" Could it be that Daboub is showing a lack of confidence in his own internal abilities to protect employees? Nonetheless, indeed.

And then we have his final display of underwhelming support for his employees, wherein he says (and in the internal memo, this sentence is highlighted in boldface type!), "All affected staff will by now have been notified by e-mail." I would think that an organization that exposes its employees' names and bank-account numbers on a public server owes those affected employees a lot more than an e-mail alert. It's a simple matter of demonstrating to your colleagues that you value who they are and what they do, rather than trying to just sweep a piddling distraction under the rug as quickly as possible.

While scrutinizing this memo is a bit like shooting fish in a barrel, the memo's language and the thinking expressed by that language deserves to be shot. World-class CIOs achieve their positions by being accountable, by being responsible, by being high achievers, and by being open, fair, and honest communicators. This memo aims for none of that, and serves as a model for the type of communication business executives should strive to avoid.



This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.


CIO TV

National Semiconductor Company takes the top spot on the InformationWeek 500 list of the nation’s business-technology innovators. ; 2008 InformationWeek 500 winner; collaboration; InformationWeek500 conference; innovation; National Semiconductor; product development; Techweb TV; Ulrich Seif; virtual inventory; Fritz Nelson spoke with Kent Kushar, the CIO of E&J Gallo Winery about what it takes to be the best and what qualities tomorrow's CIO should possess.; CIO's Uncensored; Gallo Winery; Kent Kushar; TechWeb; Tomorrow's CIO; One of the industry's leading CIOs, Ralph Szygenda, talks about what it takes to be a CIO and what tomorrow's CIO will have to do to prepare.; CIOs; General Motors; Informationweek; Ralph Sygenda; TechWeb; Techweb TV; Tomorrow's CIO; Fritz Nelson spoke with Dan Drawbaugh, last year's InformationWeek Chief of the Year, about what qualities tomorrow's CIO should possess. Dan is the CIO of the University of Pittsburgh Medical Center.; CIO's Uncensored; Dan Drawbaugh; Techweb TV; Tomorrow's CIO; CIOs from State of Michigan and National City Corporation Talk About the Innovative Projects their Teams Have Been Executing On, Including Core System Replacement and Business Portals; CIO Innovation; CIO Symposium; CIOs; Informationweek; MIT; TechWeb; Techweb TV; Scott offers his perspective on software innovation, the role of analytics in Disney's business, and more.; analytics; career; CIO; customer relationships; digitization; innovation; software; software as a service; Carter says the notion that innovation is dead is "preposterous!"; access; career; CIO; Connectivity; globalization; offshore outsourcing; software as a service; software innovation; Web 2.0; Redshaw sees a resurgence in software innovation and talks about the benefits of software as a service and SOA at Motorola.; business process management; career; CIO; software as a service; software innovation; Web 2.0; web services; Phillips talks about the benefit of global IT standards, innovation spending, and the future of IT careers.; business process management; career; CIO; global standards; governance; IT education; metrics; scorecards; Bailar discusses the role of IT in business growth, his must-read business book, agile development and he offers up some advice to the software vendor community.; agile development; business books; business performance; business process management; Call Center; CIO; customer relationships; innovation; IT effectiveness; productivity; Project Management; roi; scorecard; time-to-market; The co-authors of "The New Age Of Innovation" talk about their basic concepts of N=1 and R=G. ; CIO; customer intimacy; e-commerce; General Motors; globalization; Ralph Szygenda; re-engineering; GM's tech leader talks about consolidating, re-engineering, upgrading the company's application infrastructure. ; CIO; complexity; General Motors; globalization; integration; legacy systems; privacy; Ralph Szygenda; security; What does it take to be a CIO in the customer-oriented, globalized business environment today? Ask Ralph. ; business; CIO; customer intimacy; General Motors; infrastructure; Ralph Szygenda; supply chain; Learn how GM is building a global IT environment and what it takes to be labeled a dinosaur around his organization.; architecture; business acumen; business process outsourcing; collaboration; complexity; consumer technology; Global IT standards; globalization; IT management; real-time; roi; security; virtualization; Hear Randy's vision for the data center of the future and how he intends to slay the legacy monsters.; applications; business acumen; business processes; business-IT alignment; centralization; CIO career; complexity; data center consolidation; data centers; Data Warehouse; Efficiency; leadership; portfiolio management; reducing risk; roi; scalability; His challenge? Creating open environment for Internet users without compromising information security and privacy.; broadband; business acumen; capacity; CIO; CIO role; content generation; data centers; infrastructure; internet; privacy; security; social networking; video; Web 2.0; She considers business acumen just as important as technical knowledge for a CIO. Here's why.; business acument; Business continuity; career development; disaster recovery; IT recruitment; IT-Business Alignment; roi; security; wireless;