Bob Evans

Senior VP, Global CIO


NEWS

Sprint Completes iPCS Acquisition

The $831 million deal will end all pending litigation between the companies and expand Sprint's coverage area and number of subscribers.

More Stories

More >>

 Email  Print  Share

0 Comments

Channel: Global CIO

See all blogs by Bob Evans

From Layoffs To Ripoffs: Wicked New Threats From Ex-Employees

Most companies are "ill-prepared for an onslaught which could prove calamitous" and face "the greatest security threat of our times" from laid-off workers who are "extremely dangerous," say members of a global security-response team. In these dark days, stealing data's old hat; the new threats include tampering with billing systems, changing customer orders, and altering design documents.

For you CIOs out there, are you aware of this? If so, have you taken all necessary precautions? If not, what explanation do you plan to use if you get hit and your CEO calls you in and asks how in the name of heaven this could have happened?

Trying to highlight the enormous risk enterprises are facing as hundreds of thousands of white-collar workers lose their jobs, the Forum of Incident Response and Security Teams (FIRST) has issued a "Scared Straight"-style press release in advance of a global meeting in Japan next month, writes my colleague Tim Wilson at our excellent Dark Reading security site.

What struck me about the tone of the comments from FIRST members and other security experts interviewed by Wilson was the consistency in their levels of concern that most organizations are simply doing nothing to prevent what could be some disastrous disruptions and/or corruptions of their operations. And again, they said next to nothing about the threats from organized-crime rings and other external malicious hackers – instead, the entire focus of this latest round of alarms was the huge swath of office workers who've been laid off or fear they are about to be, and don't want to go quietly into unemployment. Writes Wilson:

"One of the greatest security threats of our times is from insiders, as organizations lay off tens of thousands of workers," said Scott McIntyre, a FIRST steering committee member and representative of the Netherlands-based KPN Computer Emergency Response Team (CERT). "People know the axe is coming, and the longer employers prolong the swing of that axe, the more danger they expose themselves to, either from sabotage or data theft. An employee who thinks he or she is [going to be laid off] can start fouling up systems which are critical to the organization, or decide to take an unauthorized pay-off by stealing a mass of data."

But as bad as data theft can be, it gets worse. This new wave of insider threat is also expected to include code-level attempts to sabotage billing systems, product-design systems, customer-ordering systems, and more. Outlining the concerns of FIRST steering committee chair Derrick Scholl, Wilson offers this:

"Sure, an insider is capable of stealing corporate secrets, or customer lists, or destroying computers, but their potential for harm is far worse," [Scholl] states. "Imagine a software company where an insider has the ability to change code in the product without being detected. What if the insider altered design documents or tampered with customer orders? Or ripped out hard drives and corrupted systems just as a big corporation was about to issue its quarterly bills to hundreds of thousands of customers? It's a totally different order of threat, and it requires a different way of thinking."

Wilson's article offers a range of suggestions of how companies can make plans to mitigate these insider threats, and in spite of the global economic downturn that has gutted IT budgets, CIOs are going to have to find ways to devote the necessary people, dollars, and intensity to be as fully prepared as possible.



This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.


CIO TV

National Semiconductor Company takes the top spot on the InformationWeek 500 list of the nation’s business-technology innovators. ; 2008 InformationWeek 500 winner; collaboration; InformationWeek500 conference; innovation; National Semiconductor; product development; Techweb TV; Ulrich Seif; virtual inventory; Fritz Nelson spoke with Kent Kushar, the CIO of E&J Gallo Winery about what it takes to be the best and what qualities tomorrow's CIO should possess.; CIO's Uncensored; Gallo Winery; Kent Kushar; TechWeb; Tomorrow's CIO; One of the industry's leading CIOs, Ralph Szygenda, talks about what it takes to be a CIO and what tomorrow's CIO will have to do to prepare.; CIOs; General Motors; Informationweek; Ralph Sygenda; TechWeb; Techweb TV; Tomorrow's CIO; Fritz Nelson spoke with Dan Drawbaugh, last year's InformationWeek Chief of the Year, about what qualities tomorrow's CIO should possess. Dan is the CIO of the University of Pittsburgh Medical Center.; CIO's Uncensored; Dan Drawbaugh; Techweb TV; Tomorrow's CIO; CIOs from State of Michigan and National City Corporation Talk About the Innovative Projects their Teams Have Been Executing On, Including Core System Replacement and Business Portals; CIO Innovation; CIO Symposium; CIOs; Informationweek; MIT; TechWeb; Techweb TV; Scott offers his perspective on software innovation, the role of analytics in Disney's business, and more.; analytics; career; CIO; customer relationships; digitization; innovation; software; software as a service; Carter says the notion that innovation is dead is "preposterous!"; access; career; CIO; Connectivity; globalization; offshore outsourcing; software as a service; software innovation; Web 2.0; Redshaw sees a resurgence in software innovation and talks about the benefits of software as a service and SOA at Motorola.; business process management; career; CIO; software as a service; software innovation; Web 2.0; web services; Phillips talks about the benefit of global IT standards, innovation spending, and the future of IT careers.; business process management; career; CIO; global standards; governance; IT education; metrics; scorecards; Bailar discusses the role of IT in business growth, his must-read business book, agile development and he offers up some advice to the software vendor community.; agile development; business books; business performance; business process management; Call Center; CIO; customer relationships; innovation; IT effectiveness; productivity; Project Management; roi; scorecard; time-to-market; The co-authors of "The New Age Of Innovation" talk about their basic concepts of N=1 and R=G. ; CIO; customer intimacy; e-commerce; General Motors; globalization; Ralph Szygenda; re-engineering; GM's tech leader talks about consolidating, re-engineering, upgrading the company's application infrastructure. ; CIO; complexity; General Motors; globalization; integration; legacy systems; privacy; Ralph Szygenda; security; What does it take to be a CIO in the customer-oriented, globalized business environment today? Ask Ralph. ; business; CIO; customer intimacy; General Motors; infrastructure; Ralph Szygenda; supply chain; Learn how GM is building a global IT environment and what it takes to be labeled a dinosaur around his organization.; architecture; business acumen; business process outsourcing; collaboration; complexity; consumer technology; Global IT standards; globalization; IT management; real-time; roi; security; virtualization; Hear Randy's vision for the data center of the future and how he intends to slay the legacy monsters.; applications; business acumen; business processes; business-IT alignment; centralization; CIO career; complexity; data center consolidation; data centers; Data Warehouse; Efficiency; leadership; portfiolio management; reducing risk; roi; scalability; His challenge? Creating open environment for Internet users without compromising information security and privacy.; broadband; business acumen; capacity; CIO; CIO role; content generation; data centers; infrastructure; internet; privacy; security; social networking; video; Web 2.0; She considers business acumen just as important as technical knowledge for a CIO. Here's why.; business acument; Business continuity; career development; disaster recovery; IT recruitment; IT-Business Alignment; roi; security; wireless;