https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Analytics


Disgruntled Employees and Data: a Bad Combination

  • Written by WeathersfieldTM
  • May 31, 2017
Confucius once said, “When anger rises, think of the consequences."

Brought to you by Data Center Knowledge

The impact of disgruntled individuals is as old as the history of humans. Confucius once said, “When anger rises, think of the consequences.” Although he never saw or imagined a data center, his wisdom should be carefully considered by managers of data centers.

“Data leakage by disgruntled employees is a very real problem,” says Brian Cleary, vice president at Waltham, Mass.-based Aveksa. “Organizations are struggling with the number of them who try to take confidential and highly valuable data for malicious intent or financial gain.”
 
Consider the following statistics from a survey of IT professionals by Ipswitch, a Lexington, Mass.-based global provider of secure file transfer solutions:

  • Forty percent of employees admit to using personal email to go behind the backs of their employers and send sensitive information without being seen.
  • More than 25 percent admitted to sending proprietary files to their personal email accounts, with the intent of using that information at their next place of employment.
  • Nearly 50 percent of employees send classified information via standard email weekly, thereby putting payroll info, social security numbers, and financial data at risk due to lack of security.
  • Forty-one percent of IT executives use personally owned external storage devices to back up work-related files monthly.
  • The issue is made increasingly complicated by orphaned accounts of those who leave companies that remained open and accessible far too long.

“It’s absolutely critical that employees only have access to what they should have access to and nothing more,” says Cleary. The risks of disgruntled employees leaking information increase when employees gain unnecessary access privileges due to promotions or transfers within an organization.

HR Plays a Big Role

Human Resources departments should be the first line of defense for many companies. HR experts are expected to conduct thorough interviews of all candidates, using their experience to make sure that individuals being considered are honest, have impressive resumes, are there for the right reasons, and have both the right skill set and excellent references.

Next, HR should perform background checks that include credit scores and drug tests, depending on a company’s policy. This process can take from three to six weeks but pays significant dividends in identifying potentially problematic individuals.

It’s also important that HR communicates with IT on issues such as when an employee should be terminated—down to the minute—as well as how denial of access will be implemented and determine what other instructions should be followed.

Appropriate policies and procedures should dictate the termination process to protect the organization, while an IT or operations manager needs to enforce the policies for the data center that include access control verification and no physical access without a designated escort.

One HR professional, who asked to remain anonymous, talked about a specific incident.

“Years ago, we had to let a CIO go. A CIO typically has multiple passwords and very easy access to virtually everything. We had to bring in a network specialist to make sure we had taken away his ability to get in. He was disgruntled—and so were we with him—so we suspected he might do something. We found five different ways he could get into the system. So we did an intrusion test to verify that we’d blocked those five entryways, as well as to discover whether he could find another way to get in. All this was done prior to his termination, with people who worked for him. It had to be kept extremely confidential. I don’t even think we told the people why these tests were being conducted. They thought we were just doing an intrusion test for generic security purposes, but we were really protecting ourselves against this person who had great access to everything in our system.”  IT and HR were very involved in coordinating this ‘underground operation.’”

The consequences we fear from unhappy employees or other internal threats can be avoided, but the price for this is vigilance. The problem itself is complex: It’s more than an IT problem or a data center problem; it is an organizational problem, and one best addressed by close coordination across departments such as HR and IT.

Best Practices

Here’s a list of  best practices for mitigating IP theft, IT sabotage and fraud from CERT, home of the well-known CERT Coordination Center. Based at Carnegie Mellon University’s Software Engineering Institute, the center focuses on identifying and addressing existing and potential threats, notifying system administrators and other technical personnel of these threats, and coordinating with vendors and incident response teams to address them.

  • Consider threats from insiders and business partners in enterprise-wide risk assessments.
  • Clearly document and consistently enforce policies and controls.
  • Incorporate insider threat awareness into periodic security training for all employees.
  • Implement strict password and account management policies and practices.
  • Enforce separation of duties and least privilege.
  • Define explicit security agreements for any cloud services, especially access restrictions and monitoring capabilities.
  • Institute stringent access controls and monitoring policies on privileged users.
  • Use a log correlation engine or security information and event management (SIEM) system to log, monitor, and audit employee actions.
  • Monitor and control remote access from all end points, including mobile devices.
  • Develop a comprehensive employee termination procedure.       
  • Implement secure backup and recovery processes.
  • Develop a formalized insider threat program.
  • Establish a baseline of normal network device behavior.
  • Be especially vigilant regarding social media.
  • Anticipate and manage negative issues in the work environment.
Tags: Agents Cloud Service Providers MSPs VARs/SIs Analytics

Most Recent


  • XDR
    Netsurion Rolls Out Enhanced Partner Program for Managed XDR
    Netsurion now offers reseller partnerships.
  • Update
    Lacework Updates Partner Program, Adds New MSP Program
    The program formalizes Lacework's relationships and support for MSPs and MSSPs.
  • Security Patch
    The Gately Report: Live Patching Beneficial Tool for MSSPs, CISA Launches Early Ransomware Notification
    Also, the number of ransomware victims skyrocketed last month compared to January.
  • Cybersecurity Transformer
    Entara Transforms from Traditional MSP to XSP to Better Address Cyber Threats
    XSP is the natural evolution of the technical service industry.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • edge computing
    'Challenging Results' for MSPs in Channel Futures' Exclusive Quarterly Survey
  • Cloud Computing
    'No Drama'? Microsoft Status as SAP-Preferred Cloud Partner Fades
  • Security shield on digital background
    VMware Security Connect Focused on Redefining Security, Increasing Threats
  • Fortune 500 2021 logo
    AT&T, Microsoft, Verizon, More Tech, Telco Companies Make Latest Fortune 500

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Cisco African American Partner Community Eyes Hiring, HBCU Opportunities

March 28, 2023

National Women’s History Month: Channel Women Recall ‘the Best Thing’

March 28, 2023

Industry Perspectives

View all

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

“Every decade a new technology emerges that is truly disruptive.”-- #AI sentiments from @RingCentral @Microsoft… twitter.com/i/web/status/1…

March 29, 2023
ChannelFutures

Check out this edition of Channel Futures TV! Glen Lomond discusses @HitachiVantara's approach to as-a-service of… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

.@Microsoft #layoffs target more workers in Seattle area. dlvr.it/SldRzg https://t.co/DGtDBBU4m0

March 28, 2023
ChannelFutures

[email protected] buys 5 MSPs to expand geographic footprint dlvr.it/SldPyq https://t.co/GnewmOXRch

March 28, 2023
ChannelFutures

.@Lacework announces partner program updates, new #MSP program. #security dlvr.it/SldP9H https://t.co/hUKTOYgoY3

March 28, 2023
ChannelFutures

Learn how MSPs can generate new revenue streams with audiovisual solutions. @shure #ucservices #channelpartners… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

⭐ 2023 #ChannelInfluencer spotlight: @andrewsage from @Cisco! Congratulations on this incredible honor from your pe… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

The latest @ATTPartners awards give a nice glimpse of how M&A is shaping partner hierarchies.… twitter.com/i/web/status/1…

March 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X