Threat Intelligence

7/10/2016
10:00 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

8 Ways Ethically Compromised Employees Compromise Security

From audit cheats to bringing data to a new job, unscrupulous employees put organizations at risk.
Previous
1 of 9
Next

Image Source: Adobe Stock

Image Source: Adobe Stock

The prevailing security wisdom to "trust but verify" comes from a deep well of painful experience.

The fact is that there are always a few bad apples in the barrel, and when it comes to employees--whether IT or your typical corporate user--the bad actors can introduce a lot of risk to the organization. But some IT executives may not realize just how many potential bad apples there can be, depending on the circumstances.

Here are a few statistics that show how prevalent shaky ethics really are in the workplace.

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
rstoney
100%
0%
rstoney,
User Rank: Strategist
7/11/2016 | 8:10:04 AM
Code Development and Ethics
So where is the "ethics" line if you develop code, queries or some form of specialized programming?

 

If you wish to say it is completely unethical to take that from one job to another, then you are saying you must in essence forget everything you did on the prior position?

 

Or is it simply enough to re-develop the same code, without copy/paste, in the new position in order to say on th ethical side?

 

Keeping in mind, that a large reason you were hired in the new position, is the new employer hoping you create the same 'magic' you did in the last position.

 

And if your value is the knowledge you develop your measure of value to other companies, with the new model of company /employee loyalty (none either way) - in which an employer can relieve you at whim:  Where is the ethics of simply qualifying for the next job?   If you wish to say ethically you should not take any knowledge with you, then basically, what is your worth to your next employer?

 

Discuss away !
New Mexico Man Sentenced on DDoS, Gun Charges
Dark Reading Staff 5/18/2018
Cracking 2FA: How It's Done and How to Stay Safe
Kelly Sheridan, Staff Editor, Dark Reading,  5/17/2018
What Israel's Elite Defense Force Unit 8200 Can Teach Security about Diversity
Lital Asher-Dotan, Senior Director, Security Research and Content, Cybereason,  5/21/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Shhh!  They're watching... And you have a laptop?  
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10000
PUBLISHED: 2018-05-24
In MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.
CVE-2018-10001
PUBLISHED: 2018-05-24
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can result in Denial of Service, Unauthorized Access, Network Instabil...
CVE-2018-10001
PUBLISHED: 2018-05-24
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed ...
CVE-2018-10003
PUBLISHED: 2018-05-24
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerab...
CVE-2018-10003
PUBLISHED: 2018-05-24
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been...