Angry employees tattling on companies that violate software licenses

News
Feb 17, 20115 mins

Disgruntled IT pros are blowing the whistle on companies with out-of-compliance licenses

Software piracy by IT professionals is rampant, according to a survey of 200 IT professionals on IT Ethics conducted by Network World. While 89% of respondents said it was unethical for an IT employee to make the company fall out of compliance with software license agreements, 70% said they have directly witnessed other IT folks knowingly violating software licenses.

In a tough economy, disgruntled or fired employees are reporting their companies’ questionable software licensing practices and exposing a culture of widespread software piracy.

Rampant software piracy by IT professionals was clear in a survey of 200 IT professionals on IT Ethics conducted by Network World. While 89% of respondents said it was unethical for an IT employee to make the company fall out of compliance with software license agreements, 70% said they have directly witnessed other IT folks knowingly violating software licenses.

One survey respondent told Network World that IT professionals are often ordered to violate software agreements by managers on the business side of the house. Additionally, 69% of respondents said they’ve directly witnessed their IT professional peers looking the other way when employees use the network to illegally install unlicensed software or share DRM-protected files.

The Software and Information Industry Association (SIIA) confirms that its caseload of corporate piracy is on the rise. The SIIA says that frustrated IT professionals are increasingly fingering their employers for failing to buy enough copies of the software used on the job.

The SIIA, which litigates software piracy cases, says the number of reports it received about corporations violating their software licensing agreements increased during the second half of 2010. SIIA is now investigating more than 40 complaints per month, up from 30 a year ago.

Survey results: When IT professionals cheat

SIAA gives out anti-piracy rewards to whistleblowers — $127,000 to 24 sources in 2009 and $57,700 to 16 sources in 2010 — who report incidents of corporate end-user software and content piracy that are later verified.

“The reason people report to us is because they are disgruntled,” says Keith Kupferschmid, senior vice president of intellectual property at SIIA. “They may have been fired. They may have not gotten the bonus or raise that they wanted. They end up getting angry and reporting to us.”

How IT Pros Cheat on Certification Exams

IT professionals “absolutely understand that this is an ethical issue,” Kupferschmid says. “Ninety-five percent of the people who end up reporting noncompliance are from the IT world. They tell us this is immoral, this is unethical. They use terms like that. It’s usually not the IT people who are responsible for the company falling out of compliance. They’re trying to do the right thing, but they are being forced to do the wrong thing.”

IT professionals are “probably more ethical than other employees, at least in the software compliance area,” Kupferschmid says. “The reason is that they work in this area and they respect it. They don’t like it when other people don’t.”

The number of reports received by SIIA declined during the 2008 recession because IT professionals were thankful that they had jobs and less likely to betray their employers. At its peak, SIIA was investigating 70 complaints per month. The number of actionable complaints is rising again because employees are starting to feel more secure in their jobs, and they’re more comfortable becoming whistleblowers, SIIA said.

“We get hundreds of reports a month, but of those reports we’ll act on 40-plus cases,” Kupferschmid said, adding that tips come to SIAA via phone, e-mail or its Web site. “One or two of those cases a month are intentional non-compliance. Those are the biggest cases we see….The intentional cases are small in number but fairly constant.”

Most cases involve companies that do not have software compliance programs in place, Kupferschmid says. “There are two types of unintentional cases. There are companies trying to be compliant and despite their best effort and compliance programs, things slip through the cracks. The other type involves rogue employees.”

Background on Microsoft Software Licenses 

According to SIIA, the typical software licensing offender is not a mom-and-pop shop, but rather a mid-sized firm with more than 500 employees and sales topping $400 million. Ironically, the most common industry – representing 12% of all software piracy cases – is the IT industry, followed by healthcare and education that each represent 10% of cases.

Among the companies caught out of compliance with their software licensing in 2010 were National Customer Engineering, a data center services firm operating in the United States and the United Kingdom, and Whitehead, Inc., a Rockford, Ill., commercial real estate firm. NCE paid a $130,000 fine – three times the value of their unlicensed software – while Whitehead paid a $103,000 fine for regularly buying one copy of software to share among multiple employees.

U.S. companies are actually much better at software licensing compliance than firms in other parts of the world, says Stephen Northcutt, president of The SANS Technology Institute and author of the book “IT Ethics Handbook: Right and Wrong for IT Professionals.”

“U.S. companies pretty much buy their software, although there are exceptions,” Northcutt says. “The rest of the world is behind.”

Related news: Why Computer Science Students Cheat

As more companies adopt cloud computing, the number of corporate end-user software piracy cases may start falling again. That’s because it will be easier for software vendors to track licensing compliance because they will provide password-protected access to applications.

Cloud computing “is going to be extremely significant. A lot of the issues we have today may very well disappear,” Kupferschmid says. “Software companies will be able to identify compliance issues on their own a lot easier. Now we need a source, a whistleblower, a disgruntled employee to tell us that so-and-so is not in compliance. In a cloud environment, it will be harder to be out of compliance. You will not need a disgruntled employee.”