The latest conviction in an insider hacking case serves as a reminder that most organizations are not prepared for the rogue employee. I remember hearing stories of one legendary IT guy that left a ticking time bomb behind that would check the payroll records every week. If his name was not on the list his script would (and did) systematically start erasing records. Dastardly behavior but all too common amongst the StarTrek paraphernalia set.
Kudos to the investigators in the The Council of Community Health Clinics case who tracked down a disgruntled employee who resigned after an unfavorable review. He accessed the organization’s systems, turned off back up procedures, and deleted a lot of records. Even though he had gone to the trouble of rebuilding all of his home machines to cover his tracks they got him based on the identity of a printer on his home network. Good work.
My advice: don’t be afraid to institute checks and balances when it comes to your IT staff. Executives should go ahead and demand admin access rights on critical systems in case the top IT folks have to be locked out. Create off-site back up procedures and make sure you have adult supervision for the IT staff.
——-
Follow Stiennon on Twitter




