Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Filching files from within

By Deborah Radcliff , Network World , 03/01/2004

Revenge is one reason employees misuse and abuse systems, as was the case when Kenneth Patterson, former data communications manager for American Eagle Outfitters, disabled his company's ability to process credit card purchases for the first five days of the holiday shopping season in 2002. But the most common motivator behind the inside job is a sense of entitlement, experts say.

"The threat from inside is not just disgruntled employees wanting to get even," C&W's Neal says. "Businesses have always had what you could call shrinkage. Employees rationalize stealing pencils, paper clips and bottles of Coke. But with digital assets stored in computers, this process becomes more impersonal, repeatable - and scalable. Now you can steal a case of pencils instead of a box of pencils, metaphorically speaking."

So strong is this feeling of entitlement that employee theft of data makes up about 75% of the cases investigated by Anton Litchfield, director of forensics consulting services for NTI, an electronic evidence discovery firm.

For example, last summer a vice president of sales for a stock analysis firm quit to go to a competitor. But before she left, she copied the customer database to take with her.

Suspicions were raised when one of her co-workers told his network manager that he'd seen a Windows dialog box copying large files to a folder on her home computer the week before she left - while nobody was at her desk. She'd accessed her office computer from her home computer using GoToMyPC.

PATTERNS OF BEHAVIOUR
Profile 3:
INTERNAL ATTACK
Create network accounts for themselves and their friends.
Access accounts and applications they wouldn’t normally use for their daily jobs.
E-mail former and prospective employers.
Conduct furtive instant-messaging chats.
Visit Web sites that cater to disgruntled employees, such as f’dcompany.com.
Perform large downloads and file copying.
Access the network during off-hours.
COUNTER MEASURES
Enforce least privilege, only allowing access to the resources employees need to do their job.
Set logs to see what users access and what commands they’re putting in.
Protect those resources that are most important with strong authentication.
If you see someone accessing something they shouldn’t, have that person’s manager discuss it with the employee to deter future bad behavior.
Upon termination, delete all computer and network access.
When employees leave the company, make a mirror image of their hard drive before reissuing it. That evidence might be needed if your company information turns up at a competitor.
Click to see:

That's when the network manager contacted NTI.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.