5 ms·
In my industry it would be explicitly illegal not to log and monitor all employee emails when they are using a corporate email or a personal email if that perso
by SanchoPanda 7y ago
In my industry it would be explicitly illegal not to log and monitor all employee emails when they are using a corporate email or a personal email if that personal email was used for business purposes. This is by design and not contradicted by any privacy laws.
- d4mi3n 7y agoSecurity guy working in fintech: this is true of many industries that need to adhere to regulation or compliance, including: 1. Finance 2. Medicine 3. Aeronautics There are likely more I'm personally unaware of. In finance, which I'm most familiar with, lenders (sometimes banks, but can be things like credit unions, marketplace lenders, or investors) have a laundry list of regulations they need to meet in order to business in the US. Many of these regulations explicitly require that the lender produce any and all communications between the lender and borrower on-demand--and for good reason. There's a long history of bad actors in finance lying or misrepresenting things in official communications (fraud, embezzlement, money laundering, etc). If you work for any finance company, you had better expect that everything you do on your corp accounts/devices will be logged, audited, and periodically reviewed. That said, the only time I've heard of an employees' email being pulled out of an archive and read were due to concerns around IP theft or questionable behavior between said employee and business clients.
- goatinaboat 7y agoMany of these regulations explicitly require that the lender produce any and all communications between the lender and borrower on-demand--and for good reason. This is why traders WFH during coronavirus lockdowns is so problematic; not only a lack of externally accessible recorded phone lines but the impossibility of policing OOB communications when the local compliance guy can’t physically see you talking on your mobile phone.
- d4mi3n 7y agoThen it should not surprise you to know that phishing attempts have spiked in recent months. The pandemic has sewn much chaos, and bad actors are taking advantage. :( What really concerns me is that these phishing attempts are just the attacks we're observing. Many more will go unnoticed given how ad-hoc current work environments have become with so many organizations going full-time remote overnight without the IT/security systems and processes in place to safely support it.
- goatinaboat 7y agoYeah, entire departments are just setting up their own Zoom, Slack etc with no oversight, it’s crazy. Mostly in a way that anyone can just join too.
- cpitman 7y agoIs that really a limitation of WFH? Even when someone is in the office, if the intent is to bypass monitoring someone can use their phone. I tether my laptop to my phone all the time on client sites (instead of fighting with yet another captive portal).
- jonas21 7y agoThis is why personal phones are generally not allowed on trading floors.
- cpitman 7y agoNo kidding! Ok, that makes more sense then.
- AmericanChopper 7y agoI’ve been privy to how a few of these highly regulated organisations are handling WFH, and the main challenges they seem to face are compute/network capacity on their virtual desktop/VPN/conferencing/instant messaging infrastructure. Which usually tend to be hosted on site. Of course people could bypass the systems completely, by say getting a private slack for their team. But doing so would (usually) be a policy violation, and from a compliance perspective, policy is often a valid control. Not all regulations require technical controls, and if they do, there’s often room to make exceptions to implement alternative controls when circumstances require it.
- goatinaboat 7y agoif the intent is to bypass monitoring someone can use their phone Not if phones are checked in at the security desk when you arrive, there is a phone jammer operating in the building, and compliance staff are patrolling to make sure no one has smuggled a phone in. These measures are normal on most trading floors.
- benhurmarcel 7y agoIn those industries, would you then also get a requirement not to delete emails? If not, those wouldn't appear in those investigations. Because I work in aeronautics, and we've never had such requirement. Unless my company retains all deleted emails without telling us.
- d4mi3n 7y agoThere's typically a retention period. I'm not clear on what that retention period would be for aeronautics, but 3 months to a year isn't unusual in fintech.