Stopping the Flow
Date: September 01, 2003
It's easier to keep hackers out of corporate computers than to keep data in...
Last October, a Reuters reporter noticed that Swedish software company Intentia used nearly identical URLs, or Web-page addresses, when posting its first- and second-quarter financial results to the Web. Following the pattern, the reporter typed in the likely URL for the third quarter. Lo and behold, the results, which Intentia had not yet officially released, popped up on the screen. Within minutes, Reuters ran a story about the disappointing numbers.
The company promptly filed criminal hacking charges against Reuters. But in the end, it was only Intentia that was punished — censured by the Stockholm Stock Exchange for failing to protect its financial information by posting it to a publicly accessible site.
Internet technologies can be a huge boon when it comes to quickly and widely disclosing information to investors and the public. But as Intentia's faux pas illustrates, these technologies — including the Web, E-mail, and instant messaging — can be as dangerous as they are useful. These days, all sorts of financial information can move casually, and at the speed of light, around an organization. It is just as easy for employees — innocently, accidentally, or maliciously — to send that information outside. In fact, according to responses to the 2003 CSI/FBI Computer Crime and Security Survey, as many security incidents originate from inside the organization as from outside. Theft of proprietary information, which insiders typically know best how to find, costs companies far more than common external security problems such as viruses. While firewalls and other security devices may be able to keep hackers out, companies are increasingly challenged to keep financial information in. "CFOs who don't aggressively protect their companies' information pose a far greater threat to shareholder equity and the health of their companies than anything we saw at Enron, Tyco, or WorldCom," says Thomas J. Parenty, author of Digital Defense: What You Should Know About Protecting Your Company's Assets, released this month by Harvard Business School Press.
^macro[showdigestcomments;^uri;Stopping the Flow]