Keep Proprietary Information in Its Place: Running an "Enterprise" with Control, Insight, and an Eye on Risk Management. A Checklist
Lauren Bielski · ABA banking journal · 2004
When it comes to security, nearly all of us have gotten an education about worms and viruses and need for good network defenses--maybe hard way. Hackers are also less of an unknown. Periodically, sheepish or oddly blank yet hostile stare of one of them will confront us on CNN, Fox, or evening news as we learn about yet another cyber misadventure. We're also more aware of sophisticated blended threat attacks that result from a back door breach of network by a hacker with spy ware which then sits like a live but undetected wire, sniffing around and relaying proprietary information where it shouldn't go. Carlo Schupp, executive vice-president of technology solutions at Ubizen, a managed security firm with U.S. headquarters in Reston, Va., points out that unorganized environments, as we'll explore here, are often prone to these sorts of exposure. What's talked about less, typically, is insider threat. It can come in form of scattered masses, who display passwords on sticky notes or who download unauthorized software that often lashes out to harm networks after fact. Even more avoided in CEO suite is talk about actions of disgruntled employee of urban legend--who, as statistics show--turns out to have real teeth. For instance, 8th Annual CSI/FBI Computer Crime and Security Survey shows that theft of proprietary information continues to cause greatest loss among survey respondents. (A total of $70.2 million was reported in this year's report, with an average reported loss of $2.7 million. About 15% of survey group represented financial services industry.) I've heard people refer to [insider security issues] as crazy aunt or uncle problem, says Doug Camplejohn, vice-president of product and marketing with Vontu, San Francisco. It's something that understood as widespread--everybody has a relative who's a little off--but nobody wants to dwell on because it can seem intractable. Likewise with security, this is especially case with first generation content filtering tools or manual efforts, which can be unsatisfactory or too time consuming, Camplejohn adds. Vontu, he explains, provides a data protection solution that sits on network to monitor e-mail, web, and other traffic to make sure that proprietary information doesn't leave enterprise in a violation of policy. And it's one piece in an increasingly complicated security puzzle. Indeed, we've all heard stories (usually without proper nouns attached) about execs who go to competitor firms and take client lists with them; or those who trade information-perhaps on a marketing strategy-to competitors for private gain. There are others who post proprietary information in public places as payback for perceived bad treatment. Bankers, of course, as Camplejohn indicated, are well aware that spontaneous bad behavior is always a possibility, despite effective hiring practices and solid HR policies. Meanwhile, Justice Department website is loaded with information on pending litigation concerning actions of good employees gone bad. They don't avoid discussing the insider threat because it's esoteric as much as because it's embarrassing and aggravating. Now, recently issued GrammLeach-Bliley-inspired privacy regulation will force banks to address content control more directly than before, notes Brett Schklar, senior director of marketing and product management with Vericept, Englewood, Colo., which provides internet and e-mail content scanning solutions. Deploying scanning and content control solutions may seem like Big Brother, but you need a policy for usage of corporate content in order to meet those regulations. If you, as an individual employee, work on something, work is owned by your company, no matter how personal it feels. Companies need to protect themselves by keeping some sort of track of where that work goes. …