By David D. Schein, President & General Counsel, Claremont Management
Group, Inc.
Computer hardware and software are the lifeblood of many
businesses today. Losing some or all of the confidential date on a business’
computers would be a major loss. Much time and money is devoted to virus
detection software, firewalls and other methods to protect computer assets.
Most of this protection is designed to prevent external attacks on the computer
systems. What happens when the threat is from the inside? Employees when they
are fired or leave to join a competitor can cause grievous harm to their
current employer’s computer systems. Often, the systems that are in place to
protect the computer systems are not effective since this threat is from
someone with an authorized ID and password.
One avenue of prevention was the threat of criminal
prosecution under the CFAA (“Computer Fraud and Abuse Act” found at 18 U.S.C. § 1030).
This 1986 law was designed to deter computer hackers. Various cases have been
brought against former employees who deleted valuable files or took such files
with them when they left their prior positions. Presently, there is a split
among the various Federal Circuit Courts of Appeals as to whether criminal
prosecution may be used against these former employees. The cases look at
access, deletion or conversion of such computer files. Access has been a key
issue since in most cases the employees had legitimate access to such files at
least at some point. The Federal courts are also looking at the fact that most
employers have state laws that provide protection for theft or damage to their
property, including computer systems.
Businesses can follow some basic steps in avoiding such
losses from employees:
1. Every
employee should sign a non-disclosure/confidentiality agreement at the time of
employment.
2. Senior
level employees and employees with access to key data should be bound by
appropriate non-compete agreements in compliance with state laws
.
3. Every
business should have a detailed computer and email use policy and employees
should sign a receipt that they have received it.
4. Access
to sensitive data should be restricted to only the employees who need access to
that specific data.
5. Passwords
should be changed regularly and every business should have a protocol of
tracking and canceling passwords of employees immediately at the time they
resign or are terminated.
6. With
regard to Item 4, businesses need to do a better job of tracking external
password access to various sites including Facebook and Linkedin. Businesses
should have a transition procedure for when the employees charged with
communication with such sites leaves.
