- Joined
- Dec 19, 2005
- Messages
- 17,880
“PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc.
Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees.
While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database.
"Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem."“
Source: https://www.theregister.com/securit...dollars-because-nobody-revoked-access/5292763
Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees.
While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database.
"Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem."“
Source: https://www.theregister.com/securit...dollars-because-nobody-revoked-access/5292763