WikiLeaks’ release of secret government communications should serve as a warning to the world’s biggest companies: You’re next.
Computer experts have warned for years about the threat posed by disgruntled insiders and by poorly crafted security policies, which give too much access to confidential data. And there is nothing about WikiLeaks’ release of U.S. diplomatic documents to suggest that the group can’t — or won’t — use the same methods to reveal the secrets of powerful corporations.
And as WikiLeaks claims it has incriminating documents from a major U.S. bank, possibly Bank of America, there’s new urgency to addressing information security inside corporations and a reminder of its limits when confronted with a determined insider.
At risk are companies’ innermost secrets — e-mails, documents, databases and internal Web sites that are thought locked to the outside world. Companies create records of every decision they make, whether it’s rolling out new products, pursuing acquisitions, fighting legislation, foiling rivals or allowing executives to sell stock.
Although it’s easy technologically to limit who in a company sees specific types of information, many companies leave access far too open. And despite the best of intentions, mistakes happen and settings can become inadvertently broad, especially as networks grow more complex with reorganizations and acquisitions.
And even when security technology is doing its job, it’s a poor match if someone with legitimate access decides to go rogue.
With the right access, a cheap thumb drive and a vendetta are the only ingredients an insider needs to obtain and leak secrets. By contrast, outside attackers often have to compromise personal computers at the bottom of the food chain, then use their skills and guile in hopes of working their way up.
Employees go rogue all the time — for ego, to expose hypocrisy, to exact revenge or simply for greed.
A former analyst with mortgage…