How much do your senior IT personnel know about your organisation? Most senior IT professionals are not only intimately familiar with your entire network, security protocols and IT infrastructure, but they know each staff member’s personal passwords as well and have multiple different ways to access your system.
On the one hand, this is entirely necessary. In digitally transformed work environments, everything we do is in some way supported by technology. Remote workforces that require access to in-house data, platforms and systems has made the role of IT even more critical than before. Your IT team is at the centre of your business.
But what happens when someone leaves on bad terms?
The ugly side of a bad employee breakup
One of our clients, a large organisation in the financial services sector, exited a key senior IT employee without realising that they were dealing with a highly disgruntled employee.
Six months later, a logic bomb that had been patiently sitting in the system waiting to be executed as a scheduled task went off, throwing the business into a crisis situation – and the business’s leadership team did not immediately realise that the source of the attack was actually internal, and not an external hacker or malware.
Never underestimate the lengths a disgruntled employee will go through to disrupt or damage the operations of a past employer, and if that employee is a senior IT professional, they have access to your entire business’s infrastructure before they leave.
We have seen malicious code released, servers formatted and even malware deployed to commit fraud. We have also seen myriad different ways that disgruntled employees leverage IT to exact revenge on corporates.
For example, a scheduled task could be triggered when an ex-employee’s name is removed from the payroll, releasing malicious code into the system.
In another instance, an ex-employee who was not an IT professional still had access to the business’s communication platforms, as well as some backdoors into the system. He was instant messaging his ex-colleagues, spreading seeds of discontent wherever he could, and a few months later used his backdoor access to format 400 servers.
Ex-employees who do not have access to an organisation’s IT infrastructure can still do a lot of damage through digital channels as well, including emailing customers from their company email addresses and setting up fake social media profiles to tarnish the brand’s name or target customers.
Unfortunately, digital forensic specialists like Cyanre are often only called in once an incident occurs.
Similarly, IT teams are quick to try and shut down an incident and get the system back up and running to ensure business continuity, but because they are IT experts and not digital forensic experts, they are not able to determine where the breach occurred, and if the criminal behind it still has access to the system.
The results of these targeted attacks can be devastating for a business, but there are ways to prevent them, particularly when ex-employees are involved.
5 ways to protect your organisation from spiteful attacks
- If an incident takes place within a few weeks or months of a disgruntled employee leaving the business, investigate whether it could be linked to them. Simply repairing the system is never advisable if you haven’t established who is responsible for the breach, as they will likely return – particularly if they are harbouring a vendetta against your business.
- Never just do a repair – always investigate a breach. We’ve repeatedly seen IT teams lock down a breach, only for the same individual to have five other accounts that they still have access to. Only a digital forensics team can track these down, as we are exposed to different risks and breaches on a daily basis. It’s a highly specialised area of expertise. Understanding who breached a system, how it was done and how it can be prevented from happening again is essential.
- By its very nature, IT operates on trust. These are the individuals who keep your business running, and they need to have access to the entire system. This makes extensive background checks even more crucial than ever before. It also means that even if an employee leaves on amicable terms, the system should be carefully checked for any scheduled tasks or logic bombs that could have been left behind, and all passwords should be changed across the business, with special care paid to ensuring that all ex-employees are locked out of the system. This requires an entire system-wide audit.
- Screen and train any personal that handle sensitive information. This is so easily overlooked, particularly in the IT environment. If a CEO or financial director requires IT assistance, the next person available is despatched to their machine, instantly granting that individual access to confidential information. Do all IT personal understand what should be kept confidential, or could they inadvertently leak highly sensitive information? Our advice is that top leadership personnel should only be taken care of by senior, dedicated IT professionals who have been heavily vetted.
- Have a strong exit policy in place. At Cyanre, we backup every computer when a person exists the business, inline with our exit policies. In most cases, this is simply to still have access to email accounts, data and client information down the line should we need them, but if a breach occurs, these backups become invaluable tools. At the very least, we would advise exit policies to stipulate that emails are backed up before ex-employees delete anything.
The general rule of thumb is that it’s better to be proactive than reactive. With the right policies and procedures in place, as well as a full IT audit when a senior IT professional leaves your business, you can put the necessary security measures in place.