Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • Innovation
    • IT Management

    Research Indicates CEOs, Other Execs Routinely Steal Company IP

    Written by

    Chris Preimesberger
    Published August 3, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security professionals have always contended that the weakest link in any security system isn’t the hardware or software—it’s nearly always a human or humans who interact with it.

      A new study from information security vendor Code42, released July 24, bears witness to this once again, only this time the research reveals a rather disturbing trend: That a majority of CEOs and other business leaders, whose responsibility it is to oversee the protection of their enterprise’s most valuable assets, engage in exactly the type of risky behavior that jeopardizes their businesses’ intellectual property.

      Such are the foibles of humanity–only this particular type of foible can be extraordinarily devastating to a business enterprise if allowed to continue with impunity.

      Knowingly Flouting Data Security Best Practices

      In fact, Code42’s researchers found, a high percentage of executives admit to have knowingly flouted data-security best practices and company policies by doing one or more of the following:

      • taking intellectual property upon leaving their previous employer;
      • keeping a copy of their work on a personal device, outside the relative safety of a company server or in a company cloud;
      • clicking on questionable links, putting their data at risk from malware; and
      • downloading unsanctioned software.

      Some of the conclusions of the study were:

      • Even the strongest data security policies and perimeters are no match for human emotion and behavior.
      • Without visibility to employee endpoints, IT can’t protect valuable company data. Yet, they’re expected to.
      • Despite the expense and effort of setting up security perimeters, CISOs and CEOs are planning for data breaches—stockpiling cryptocurrency and paying the ransom when they happen.
      • While companies know that prevention-only strategies don’t work anymore, most haven’t yet evolved to meet the new challenge.

      IP Theft Widespread?

      What were the most surprising aspects of this survey for Code42, outside of how widespread this IP theft practice is?

      “I don’t think anybody in this industry should be particularly surprised about how widespread IP theft is by departing employees, but it is startling that Code42’s data security research uncovered that so many CEOs would admit to taking information,” Code42 Chief Information Security Officer Jadee Hanson told eWEEK. “I think the reason they walk away with their company’s IP and likely will continue to do so is that people feel entitled to their own work, so they probably don’t consider it stealing.

      “And maybe they don’t even realize they’re stealing it because they aren’t knowledgeable enough about IP policies and regulations. If that’s the case, then I’d consider that to be alarming, too – if anybody, executives need to know the rules backwards and forwards.”

      A couple of other findings in particular struck Hanson as surprising.

      “It’s staggering that so many executives are stockpiling cryptocurrency to pay ransom,” Hanson said. “Our study showed that many executives have already paid a ransom, which is a very dangerous practice. For one thing, it enables and emboldens cybercriminals. From my standpoint, it shows how important it is for organizations to enhance their security plans beyond just prevention. A robust security program needs to include prevention and detection with a large focus on visibility across the environment.”

      Nearly Two-Thirds of Respondents Breached in last 18 Months

      As a CISO, Hanson said he found it startling that 61 percent of the respondents have been breached in the last 18 months.

      “I expected the proportion of impacted companies to be high, but I did not expect that over half of the research respondents would have been impacted in that short timeframe,” Hanson said. “Securing your company’s information is not an easy job; it’s important that focus be applied to not only prevention, but detection and full visibility as well. Being in security means that bad things will happen. When they do, you want to make sure you are positioned with the right visibility and recovery tools and services to bounce back.”

      So what can infosec execs do about this? They are definitely caught in the middle.

      “Infosec execs need to be proactively aware of what’s going on in the industry and within their own organization,” Hanson said. “They need to be serious about educating their employees and turning them into data advocates.”

      Code42’s data security study showed that three-quarters of CISOs believe they can enhance their security strategies by combining prevention and recovery together, so there’s definitely an awareness that strategies need to change. Four best practices that all CISOs should be doing every day, according to Hanson, include:

      • Take a proactive stance on data security beginning as soon as you hire employees by outlining their security responsibilities to your company. If employees are terminated because they didn’t meet their data security responsibilities, create an anonymous case study to use as part of your ongoing employee education training.
      • When an employee has submitted his/her resignation, reply by thanking them for their service, conducting an exit interview where you acknowledge that they’re trusted, remind them about adhering to company policy–and have them sign a document that summarizes IP law and their obligations to safeguard your corporate IP.
      • In terms of technology, have the type of solution in place that gives you visibility to data movement throughout the network in real time by identifying all types of files that are moved from a device, who is moving them, and when and where they’re being moved.
      • Follow up on all alerts in a timely manner. Communicate what you saw with the employee. It really doesn’t matter if it was a non-malicious or an actual malicious act. At that point, you’re just protecting your IP.

      About the Data Exposure Report

      The security, IT and business leader portions of the research for this report were conducted by Sapio Research, an independent research consultancy based in the United Kingdom. The survey was completed, via online response, during February 2018.

      The research surveyed 1,034 security and IT leaders, including CSOs, CTOs, CISOs and CIOs, as well as 600 business leaders, all with budgetary decision-making power. All respondents came from companies with at least 250 employees. A total of 61 percent of the business leaders and 58 percent of the security and IT leader represent companies with more than 1,000 employees.

      To check out the study, go here.

      Chris Preimesberger
      Chris Preimesberger
      https://www.eweek.com/author/cpreimesberger/
      Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.
      Linkedin Twitter

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.