Downsizings leave firms vulnerable to digital attacks
Disgruntled castoffs pose security threat
June 25, 2001 12:00 PM ETComputerworld -
During the current wave of corporate layoffs, companies should be extra vigilant about digital sabotage by disgruntled ex-employees, according to security analysts. As employers pare down their payrolls to cut costs, many companies may unwittingly be leaving themselves vulnerable to hostile actions by discharged workers, including theft of confidential company information, illegal use of a company's IT resources and hidden "logic-bombs" that can destroy vital data.
"During times of an economic slowdown, it is common to see an increase in security incidents" caused by frustrated and hostile former employees, said Michael Rasmussen, an analyst at Giga Information Group Inc. in Boston.
That's why it's generally a good idea to thoroughly beef-up existing security processes just before, during and immediately after large-scale layoffs, analysts said.
Common mistakes that contribute to the problem include a failure to disable the passwords and accounts of former employees, a lack of formal rules for the return of company laptops and handhelds and a failure to plug holes that make it possible for an ex-employee to exploit a former colleague's user account to gain illegal access.
Such problems are exacerbated during times of mass layoffs, particularly when IT staffers are given little advance notice and don't have enough time to finish the technical chores necessary to prevent sabotage, said Chris Wysopal, a director at @Stake Inc., a Cambridge, Mass.-based security firm that last week issued an advisory on the subject.
"If you don't have a very good termination policy and good record keeping of all the different access points that people had as employees, you are going to miss something," Wysopal said.
"Unfortunately, though, a lot of the time we hear from companies wanting to tighten their firewalls and intrusion-detection systems only when they are actually laying off people," he added.
| Security at Stake @Stake's guidelines for limiting threats from disgruntled former employees. MAINTAIN a log of all the perimeter connections made by employees. When someone leaves, it becomes easier to identify and close the holes this way. CHECK for and close unofficial accounts that may have been set up by employees. TERMINATE user accounts and disable passwords. WORK together with all relevant departments to ensure smooth implementation of security processes. |
Fenwick & West's policy for securing its networks after an employee leaves depends on the job role and level of access that
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

