ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    One in three workers would steal data

Unscrupulous IT workers are more likely than ever to steal company data if they thought it would benefit them, an employee survey has revealed.

By Martin James, 24 Nov 2009 at 11:30

data theft

An alarming number of people would consider stealing sensitive data from their employer if it suited their own ends, and the figure is rising, new research has found.

One in three employees canvassed by information security company Cyber-Ark said they had used their employee permissions to access privileged corporate information such as HR records and customer databases without authorisation.

Worryingly from a security point of view, fully three quarters of those questioned in the US and UK claimed they could bypass the controls their companies had put in place to protect such information.

In both cases, the figures represent a rise over last year, despite increased media awareness on the subject after a sharp rise in data breaches.

But perhaps more interestingly than the headline figures was the sharp increase in respondents saying they would consider taking company information with them if they were fired – clearly a result of increased pressure in the job market thanks to the global economic downturn.

Six times as many employees as last year said they would take financial reports or merger and acquisition plans with them and four times as many said they would nab chief executive's passwords and development plans.

One in five companies reported having been victims of insider sabotage, and of those, 36 per cent believed rival firms had benefited.

"This survey shows that while most employees claim that access to privileged accounts is currently monitored and an overwhelming majority support additional monitoring practices, employee snooping on sensitive information continues unabated,” said Cyber-Ark chief executive Udi Mokady, commenting on the survey results.

“Businesses must wake up and realize that trust is not a security policy; they have an organisational responsibility to lock down sensitive data and systems, while monitoring all activity even when legitimate access is granted," he added in a statement.

More than 400 senior IT professionals in the US and UK took part in Cyber-Ark's Trust, Security & Passwords survey, mainly from enterprise class companies.

Read on to find out what to do in case of a data breach.

Email to a friend

Print this page

< Previous   Public Sector : News Next >

2 comments

You need to Login or Register to comment.

To avoid data leakage

As we can see in this case about data theft, one of the most difficult challenges is to protect intellectual property in companies. A company’s expertise and R&D output are at the very heart of its competitive advantage. Nevertheless, the problem is that the company has to share knowledge with his employees as well as with externals. Lock confidential data behind firewall without access for externals doesn’t seems appropriate. Intellectual property must be accessible remotely to enable stakeholders to collaborate and to share documents and information in a comprehensively protected and secured way without any unauthorized access. Printing, saving and forwarding of documents must be prevented, avoiding data theft and leakage it is essential to track the whole document life cycle! Features like “tamper proof audit trails” and “Brainmarks” will show who has stolen certain documents!

By Dynamus on Thursday Nov 26

1 people out of 1 found this comment useful.

Did you find it useful?

Marc Hocking, CTO, Becrypt

The recent stories surrounding data theft reinforce the need for companies to have a sound Information Assurance strategy. This needs to comprise of effective policy which is reinforced by technology. The correct controls need to be in place from the start – trying to put these in place after an employee has been sacked and stolen data is like bolting the barn door after the horse has bolted. Whenever an organisation hires a new employee, there needs to be education about the data policy, and continual reinforcement of this to ensure that employees are updated on any policy changes. Organisations need to make sure that strategies are in place across the entire employee lifecycle, and ensure that these are effectively communicated, so prevent potentially catastrophic data loss.

By Becrypt on Friday Nov 27

0 people out of 0 found this comment useful.

Did you find it useful?

 Sponsored Links

advertisement
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement