HR Is Not Protecting Your Private Information
|
That's right, Rockwell, Michael Jackson and the Geico "Money That You Could Be Saving": You do, in fact, always feel like someone is watching you and your private information at work. You're not paranoid. Your fellow employees--to the tune of 35 percent--have admitted to ignoring security policies and looking at your salary information, your medical history and more, with some going so far as to even swipe the CEO's info and lots of sensitive corporate data, according to info from a Cyber-Ark Software survey. From the article:
It's obviously in the best interest of security companies to post articles and reports about how broken internal security is for corporations--helps them sell products, gain credibility and sound like experts (and they may be). But that doesn't necessarily discount the levels to which employees will go to snoop on each other, executives and company secrets. From an employee-to-employee perspective, it's no easy thing to swallow that your colleagues are digging into your personal, confidential information--information protected by law--that has no business being invaded. It speaks to the larger issue of privacy in a technological age that has a tendency to open private information, willingly and unwillingly. As Harvard Business School Professor Rosabeth Moss Kantor blogged recently in her post, Don't Read This, It's Private
But the criminal acts going on in the workplace with your private information are more egregious compared with those affecting those who choose to make themselves and their information easily accessible in the always-connected, socially networked world we and our professional and not-so-professional personas play in online. For private information kept on record at work, companies have some very real self-policing to do. |
For more IT Careers and Workplace News, check out eWeek Careers

Comments (1)
The situation is far worse than the article states. The breaks in security described above are, generally, not malicious. Many of the vendors that supports HR is ill-prepared to manage sensitive data. These are holes that are far more likely to be malicious.
For example: 65,000 records breeched from Aetna's career site powered by a company called Taleo
(article here: http://www.courant.com/business/hc-aetna-website.artmay28,0,7686408.story)
I happened to get this email, which was apparently in response to the first breech from another vendor trying to claim superior security (a far smaller company)
http://hosted.verticalresponse.com/163865/95f4122def/134001403/2d8759f790/
It took me about 15 minutes to expose 4 major security flaws in this company (Cytiva something? I don't know, they have some prominent clients), including SQL injection risks, brute force attack risks, and cross-company exposure. I'm hardly a hacker, if I can find these flaws in a few minutes, it's apparent that an Enemy can run away with our information right through the HR desk.
Posted by Steve O | June 18, 2009 10:52 PM