SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Project Management

Beware the rogue employee

Beware the rogue employee

By:  David Carey  On: 29 Feb 2008 For: CIO Canada Creator

When reviewing security procedures, factor in the cleverness and sheer determination of employees bent on thwarting the system.

Seems like the world is full of rogues these days. No longer are we surprised when we hear of yet another company employee who has run amok, often under the supposedly not so watchful eye of the IT department.

The latest and most notorious, of course, is Jerome Kerviel, the trader who allegedly racked up $7.1 billion in losses for French bank Societe Generale. Pity the poor SocGen CIO who awoke to this bit of news on the clock-radio. How’s your day going so far?

Whenever there’s a high-profile corporate security breach, it’s a good bet that to one degree or another, IT will carry the can, whether it deserves to or not. The SocGen incident is no exception. In a Financial Times interview, Bank of France governor Christian Noyer pointed to an accumulation of “small mistakes” in internal controls as the probable cause of the financial disaster. “It clearly shows the need to have… even more rigorous controls on the resilience of computer systems to fraudulent penetration,” he said.

If the SocGen incident teaches us anything about the phenomenon of rogue employees, it is that these individuals will go to extraordinary lengths to circumvent security measures. Kerviel is reported to have used various passwords and accounts, breached five levels of controls, and forged documents and emails in order to carry out his unauthorized trades and cover his tracks. That’s dedication!

And that’s something that IT executives should take note of when reviewing security policy – just how foolproof are your safeguards in the face of a cunning employee bent on breeching them, with the aid of colossal nerve, limitless guile and single-minded determination?

Of course there’s only a slim chance you’ll encounter a rogue of this calibre. But preparing for anything less is a calculated risk. And if the calculation doesn’t work out in your favour, your next career move could be flipping burgs at McDonald’s.

And one last thing to keep in mind. The guy who perpetrated the biggest fraud in banking history wasn’t even a techie.


Sign up for our Newsletters
Tags:












Print |  Views: 1004   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




David Carey David Carey is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Controlling 'shadow IT'
Controlling 'shadow IT'Some see it as grassroots deployment of cool technologies; some see it as weeds growing from any crack in the IT plan
Plugging leaks: Teach your employees about security risks
Plugging leaks: Teach your employees about security risksWhat enterprises can learn from casino security. Plus, why employees ignore basic security principles
SocGen's rogue trader highlights IT security holes
SocGen's rogue trader highlights IT security holesAfter a French bank alleged one of its traders made billions in unauthorized transactions, a Canadian CSO advises HR staff and managers to be aware of the limitations of technical controls
ZTE D90: Heavy texting
we have the new zte d90 mobile phone in the office for a test drive, courtesy of telus and zte. i've
blog comments powered by Disqus