Friday, September 21, 2012

Employees and Computer Hacking


By David D. Schein, President & General Counsel, Claremont Management Group, Inc.
Computer hardware and software are the lifeblood of many businesses today. Losing some or all of the confidential date on a business’ computers would be a major loss. Much time and money is devoted to virus detection software, firewalls and other methods to protect computer assets. Most of this protection is designed to prevent external attacks on the computer systems. What happens when the threat is from the inside? Employees when they are fired or leave to join a competitor can cause grievous harm to their current employer’s computer systems. Often, the systems that are in place to protect the computer systems are not effective since this threat is from someone with an authorized ID and password.

One avenue of prevention was the threat of criminal prosecution under the CFAA (“Computer Fraud and Abuse Act” found at 18 U.S.C. § 1030). This 1986 law was designed to deter computer hackers. Various cases have been brought against former employees who deleted valuable files or took such files with them when they left their prior positions. Presently, there is a split among the various Federal Circuit Courts of Appeals as to whether criminal prosecution may be used against these former employees. The cases look at access, deletion or conversion of such computer files. Access has been a key issue since in most cases the employees had legitimate access to such files at least at some point. The Federal courts are also looking at the fact that most employers have state laws that provide protection for theft or damage to their property, including computer systems.

Businesses can follow some basic steps in avoiding such losses from employees:
1.    Every employee should sign a non-disclosure/confidentiality agreement at the time of employment.

2.    Senior level employees and employees with access to key data should be bound by appropriate non-compete agreements in compliance with state laws
.
3.    Every business should have a detailed computer and email use policy and employees should sign a receipt that they have received it.

4.    Access to sensitive data should be restricted to only the employees who need access to that specific data.

5.    Passwords should be changed regularly and every business should have a protocol of tracking and canceling passwords of employees immediately at the time they resign or are terminated.

6.    With regard to Item 4, businesses need to do a better job of tracking external password access to various sites including Facebook and Linkedin. Businesses should have a transition procedure for when the employees charged with communication with such sites leaves.