Recently one of our devs was caught running Chrome portable (because he wasn’t given admin access), where he logged in to his personal google account and saved his company credentials, where they were promptly synced to his personal malware-infested home system and ended up in a paid dataset on the darknet. IT Security, InfoSec and Governance policies have to be written with this kind of employee behaviour in mind.
Incidentally him and his team had just complained loudly about MFA being required for our critical apps.
Well, that is bad all over. And also can be seen as an evidence towards “if someone requires access that does not look suspicious, give it to them”: he wasn’t given access, so he went another way and fucked up spectacularly. On the other hand, though:
if it is a company machine, then not having admin access can be expected
I would expect that “do not ever use personal accounts for work and vice versa” does not need reminding, but here we are
yeah, the rules should account for malicious behaviour, intended and not
Most of the damage is done with good intentions.
Recently one of our devs was caught running Chrome portable (because he wasn’t given admin access), where he logged in to his personal google account and saved his company credentials, where they were promptly synced to his personal malware-infested home system and ended up in a paid dataset on the darknet. IT Security, InfoSec and Governance policies have to be written with this kind of employee behaviour in mind.
Incidentally him and his team had just complained loudly about MFA being required for our critical apps.
Well, that is bad all over. And also can be seen as an evidence towards “if someone requires access that does not look suspicious, give it to them”: he wasn’t given access, so he went another way and fucked up spectacularly. On the other hand, though: