Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Inefficient Compliance Activities Costs $$: Survey Says SOX Compliance Costs Were Down In 2006, But They Should Have Been Down More | Main | SEC Approved Multiple Compliance Guidance and Rules Documents For SOX, SMBs and Credit Rating Agencies »

Insider Threat Example: Ex-Coca-Cola Employees Sentenced to Prison For Trying To Sell Trade Secrets To Pepsi

An article broke yesterday that closely mirrors one of the discussion topics within the Human Factors seminar that I teach for the Norwich University MSIA program.

CNN reported that a couple of ex-Coca-Cola employees were sentenced to prison and ordered to pay $40,000 each for "conspiring to steal and sell trade secrets to rival Pepsi."

One will get 8 years in prison and the other will get 5 years.

Another ex-Coca-Cola-worker was also involved and will be charged with wire fraud and unlawfully stealing and selling trade secrets, as were the other two, and sentenced this summer.

Pepsi notified Coca-Cola that the three had offered to sell samples of a new Coke product to Pepsi for $1.5 million.

Discussion of this type of incident is always fascinating. Thoughtful discussion highlights the importance of not only access controls to sensitive information, but also how important practicing ethical behavior, and having a code of ethics, is, and how it complements information security and privacy efforts.

A few things to point out about this:

* These were trusted employees with access to sensitive information (trade secrets) and actual product samples.

* The trade secrets were printed out and hard copies were offered to the primary competitor.

* An actual sample of the new product was offered to the primary competitor.

Here are a couple of scenarios for you to thing about:

* What if you had hired someone for a position...someone who used to be employed at your biggest competitor? What if the person said they still had access to their former employee's computers systems and networks? What if they offered to log in and get access to the competitor's trade secrets, customer database, or other sensitive information? What would you do?

Would you contact the competitor and let them know of that they need to review their procedures for completely removing all access to their networks when their employees leave the company? And that one of their ex-employees still, indeed, had access and was offering to give access to their trade secrets and customer lists?


* What if an employee from your competitor contacted you with a similar offer as in the Coca-Cola case? What if they offered to sell you the brand new plans or recipes for a product that your company has already determined will likely drastically cut into your company's revenues?

Pepsi certainly exemplified doing the right, ethical, thing by working with law enforcement and Coca-Cola to make sure the at-the-time employees of Coca-Cola were brought to justice. But would all companies do that?

This is certainly an important talk to have with your legal counsel and HR head. Not only do you need to know what you would do in these situations, you need to work with the area that is responsible for your company's code of ethics and ensure your information security and privacy policies and practices are hooked into them, and vice-versa.

You don't have a code of ethics? Safeguarding your information depends heavily upon your employees doing the right thing. Your employees to whom you have entrusted your company's trade secrets and customer information. You must tell employees what your expectations are for how they use the access with which they have been entrusted to your information and computer systems.

Ethics, information security and privacy all go hand-in-hand.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/416

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.