Disabling the Disgruntled

SANTA CLARA, Calif.-Though the risk of data loss due to retaliation from former employees is less worrisome to some CUs than the risk of data accidentally compromised in an e-mail, it's still important for IT managers to protect themselves against data theft after employee lay-offs, several analysts stressed.

Processing Content

"Layoffs have been relatively rare in the credit union industry, but it only takes one rogue employee to expose the CU to lawsuits and losses," said Jeff Rubin, VP-marketing and strategy for Beachhead Solutions. "In tough economic times, there is a lot of pressure to get more done with fewer resources and at less cost. That is exactly the kind of environment where corners may be cut to get the job done, but in a way that exposes information to unacceptable risk."

AFTRA-SAG FCU said CUs can protect themselves from resentful former employees by notifying staff and third parties after an employee is let go, which lessens the risk of social engineering, said Clark Dilley, manager, information systems at the $215-million CU. The employee's user network and e-mail accounts should be immediately deactivated, and administrator-level passwords changed "in the event that the passwords were obtained illicitly," he said.

DLP can help identify and prevent suspicious behavior in cases where an employee is still working at the CU but expects to be let go, said Rubin.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More