6 ms·
IT also failed to put enough checks here. The article states that the employee still had a valid company account that he could use to access the repos. The acc
by ksd482 3y ago
IT also failed to put enough checks here. The article states that the employee still had a valid company account that he could use to access the repos.
The access should have been cut off right away.
- next_xibalba 3y agoI believe this line of thought is commonly called “blaming the victim”.
- plasmatix 3y agoI mean, if someone dies in a car crash and they weren’t wearing their seat belt, is it victim blaming to say they should have been?
- pipes 3y agoYeah but if someone purposely drives into that car with the intention of killing the driver, I'd hope they went to prison even if the victim wasn't wearing a seatbelt
- 11101010001100 3y agoIn the US, the person who sold the car will go to jail as an accessory to murder .
- BobaFloutist 3y agoMany such cases. Sad!
- 11101010001100 3y agoYes, theoretically we're all guilty of felony murder.
- foobarbaz333 3y agoThere are compliance regulations that require this btw.
- capableweb 3y agoNo, blaming the victim would have been: > The only reason this happened was because they failed to secure their own systems, it was bound to happen Instead, parent said: > IT also failed to put enough checks here My emphasis on the "also".
- bitwize 3y agoIt's totally legitimate to simultaneously hold that the real perpetrator is, er, the perpetrator, and that the victim could have done more to prevent the incident from happening. Jail the guy, and let his story stand as a warning to implement proper IT and HR practices.
- acdha 3y agoNobody is excusing him but it’s possible for multiple people to make very bad decisions as part of the same problem. In this case, the bank has almost certainly claimed to have security policies in place which would have prevented any of the damages in question. I don’t even work in banking but “how do you deactivate accounts when someone leaves?” is in every single system’s approval process and ongoing audits. Think of it as if he had stolen money from them after being fired: there’s no question that the culpability would be his but also regulators and insurance would descend on the bank’s management asking why they lacked such basic internal controls for such very well-known risks. Most places will remove all forms of access as soon as the decision is made to fire someone because it’s the most likely time to have anything from theft to, in the US, a workplace shooting.
- pierat 3y agoSometimes, the victim is *also* to blame. When shitty policies are part of the root cause, then yes, the victim also shares in creating an environment that allowed easy victimization. You wouldn't secure your laptop in the front seat of a car in NYC or Chicago. Just as you are not to blame with the vandalization and theft of said equipment, you also could have did easy mitigations to hamper it. People who shout "victim blaming" are also refusing to take responsibility for reasonable remediations that would have prevented the bad thing.
- deleted 3y ago[deleted]
- mistrial9 3y agozero-trust works both ways
- sonicanatidae 3y agoThere is a symbiotic relationship between HR and IT. In my orgs, when HR TELLS US, in advance, we nuke the creds while they are discussing the term with HR. If HR doesn't tell us, then we have zero way of knowing to kill their account. When they don't tell us, then termed users continue to have access... again... because we have no way of knowing to term the access.
- Volundr 3y agoDon't underestimate a dumb managers influence on this. Back when I was running an orgs IT we had a similar incident when we fired an employee. HR had given us the heads up when it would happen, and we had someone standing by to kill their credentials (as the meeting started someone would give the final go ahead). Their manager however decided to "get it over with" without telling us, then when said employee asked if they could get some information off their work computer, proceeded to sit with them while they attempted to delete all their work. I was able to recover it from OneDrives second recycle bin so nothing was lost, but I was livid. This employee was literally being fired because they were refusing to train anyone else on their work for "job security purposes", it's not like we didn't have warning this wouldn't be graceful.
- sonicanatidae 3y agoI remove this from HR's and other Department's hands, once IT is made aware. Beforehand, I obviously cannot affect. They tell IT in advance and maintain the schedule and contact us to adjust or DRAMA. Lots and lots of drama. Had I been in that situation, I would taken that garbage to my direct Super, which is usually the CFO. I would explain why this is such a horrific idea. They usually agree. If they don't, then I look for somewhere else to work, since I cannot keep PHI secure, when I cannot control who has what access and when. I'm not going to be held responsible when others callous actions remove all the guardrails. No thanks.
- Volundr 3y agoIn short, the issue is that the manager didn't keep to the schedule. If they had done it at the proper time HR would have been involved and we would have gotten our notification. Instead the damage was done hours before this was scheduled to happen. In terms of higher-ups notification the "oh shit can you recover this" call came from the CEO I don't know what happened to the manager. I can't imagine it ended well for them, pretty much that entire section of the org was on thin ice (acquisition that didn't want to absorb into the company) so I can't imagine it ended well. I know we didn't pursue legal action against the ex-employee, which pissed me off at the time, but I can see the logic in leaving it done and dusted. The only PHI the company held was what HR had on it's the employees, so not at risk here.
- gamblor956 3y agoAt my last job, most of the company was laid off during the early part of the COVID lockdowns. ...Including the IT guy who was responsible for killing everyone's access credentials... All of us that were laid off watched the company-wide zoom where the CEO tried to blame everyone who had been laid off as dead weight. They managed to get the other IT guy to kill our credentials the following week. Then they laid the other IT guy off before anybody had sent in their work laptops or other work equipment because the CEO decided that if the offices were going to be closed indefinitely we didn't need an IT guy. The company had to write off more than $1 million in assets that were never returned, including a number of very expensive, very new RED cameras. A lot of times, IT's "failures" are just the failures of management.
- deleted 3y ago[deleted]