by Michael O. Cooper

Reducing the employee risk

Opinion
Dec 4, 20063 mins

Protecting information is 90 percent about education and user awareness. We have handbooks for policies and such, but we worry about the risks that are created by our employees sending data out of the network. As an HR professional, how do you control the insider risks presented by employees?

Most companies have intellectual property that gives them a business advantage in the marketplace. Employees have access to this information everyday and often share that information with other employees, family members, friends, customers and sometimes, unknowingly, with competitors. Since about 80 percent of threats posed to intellectual property come from inside companies, let’s look at what it takes to educate your staff to protect your intellectual assets.

Very few information leaks are malicious in corporate America. Information is often shared without understanding how it could damage the company’s competitive position. A simple email containing an important or secret document to a client can be intercepted or sent to the wrong address.

Employees often send documents to themselves at a personal email address so they can access them from home. Laptops frequently leave the office containing intellectual property without any intention of the employee sharing the information; however we’ve heard of the millions of names, email address, account numbers, social security numbers, etc. being stolen from laptops.

Here are some simple steps that are valuable tools to use when educating employees about data protection:

Be clear. Simply because a document or process exists inside a company, does not mean that employees know to keep it contained within your organization. This may sound odd, but in this era where information is shared freely over the internet and people’s personal lives and work lives often overlap, it is the responsibility of the organization to clearly delineate what must be kept private. Every document, email, process, form, or piece of information that you consider property of your company should be clearly labeled as such.

Remind employees regularly. Communication about your intellectual property policies should be frequent. One paragraph in an employee handbook that rarely gets referenced is not good enough – less than 10% of employees actually read their handbooks! If your intellectual property is important, communication about its safety should be a top priority.

Invest in technology. Clear policies and communication are important, but are rarely enough to prevent unintentional threats. There solutions today that have the ability to protect data before it becomes a risk by discovering information at-rest, during the transmission of information in-motion, and after by capturing network events related to information at-rest and in-motion to identify previously unknown risks.

Even though your employees usually have the best intentions, they may pose a threat to the security of your intellectual property. Follow the simple steps above to reduce your risk.

Michael O. “Coop” Cooper is a trainer and consultant with Paragon Strategies in San Francisco. His specialty is the underlying motivations and structure of work to increase productivity and efficiency. Insider Threat column archive. Have a question about security issues related to employees? Let us know.