SailPoint finds almost 50% of workers admitted they would take some form of company property with them when leaving a position, including customer data and electronic files
One of the best headlines I’ve ever seen, at least for a press release, crossed my inbox recently: “SailPoint survey shows employees are more apt to take company data than a stapler.”
Now it might be that staplers have little use in the home these days, or it might be that disgruntled employees are becoming more aware of the value of data. Here’s a look at what the survey revealed.
Data loss a mystery for many businesses
In response to the survey, almost 50% of workers admitted they would take some form of company property with them when leaving a position: 27% would take customer data, including contact information; 23% would take electronic files; 16% would take proprietary product information, including designs and plans; and 16% would take office supplies. Interestingly, employees don’t perceive the recent recession as greatly influencing propensity to steal: 46% of the respondents felt that a coworker’s tendency to steal from an employer has not been influenced by the recession.
The Market Pulse Survey also asked workers what they would do if they were inadvertently granted access to a confidential file (such as one containing salary information, personal data or plans for a pending merger). Almost 40% of respondents said they would look at the file, while another 33% said they would not look but would alert a manager to the mistake. Less than 1% of workers stated that they would attempt to sell confidential data found in improperly secured files, although 6% said they would tell others about the information they saw.
How should we interpret these results? Well, according to Jackie Gilbert, vice president of marketing (and SailPoint co-founder) Jackie Gilbert, “The survey highlights an ongoing challenge that companies face: how to balance business risk with the need to give employees access to sensitive applications and data in order to perform their jobs.”
In other words, better governance rather than thicker firewalls. Employees, partners, vendors and clients with either legitimate or inadvertent access to sensitive, proprietary or privileged data may now form the biggest threat. Jackie did have some suggestions for those who needed help in getting started: “As a starting point, companies need to clearly define policies in this area and educate workers about treatment of confidential data. Step Two is to strictly limit and control what applications and data are accessible and to put automated systems in place to promptly remove access when an employee transfers roles or leaves the company. As a Step Three, companies should conduct quarterly access reviews to ensure that employees truly need the access privileges they have — especially for highly sensitive systems. Companies may also need to monitor the activity of employees who access highly confidential data in order to prevent incidences of fraud or data breaches.” Words of wisdom from an astute lady.




