YOUR BUSINESS AUTHORITY
Springfield, MO
As if businesses don't have enough to deal with already, there are developing issues that could present one of the most dangerous business risks to date. These risks transcend the entire spectrum of a business and include crime, employment, copyright/trademark, productivity, security and public relations. Frankly, these risks are new, developing, extremely dangerous and can happen with the click of a button. They are centered around the newest business tool the computer.
If your business is actively using the computer for e-mail, internal projects, accounting, Internet access or e-business, it is exposed in a way that makes chief executive officers shudder and attorneys salivate.
Where documents, memos (internal and external), trade secrets, accounting records and purchasing/receiving re-cords used to be kept in files, they're now housed in computers.
This makes this information much more vulnerable to theft, misuse, and security breaches.
In addition, unauthorized access to information can lead to lost productivity, public relations problems, and worse, lawsuits.
Let's look at e-mail a great way to communicate if properly used, a keg of dynamite if not managed effectively. In a recent high profile case, Chevron Corp. was ordered to pay female employees $2.2 million to settle a sexual harassment lawsuit stemming from an inappropriate e-mail circulated by male employees. The offender's e-mail messages included, among other things, "25 Reasons Why Beer is Better than Women."
In another case, a company was ordered by a court to turn over all e-mail records so that a wrongful termination suit could be litigated. With no policy in place for purging e-mail, the company faced the prospect of searching more than 20,000 backup tapes containing millions of messages. The estimated cost to do this was more than $20 million.
Using the Internet can be a great way to access information. It also can be a huge waste of productivity. U.S. businesses lost an estimated $500 million in workplace productivity when Congress released the Starr Report and President Clinton's video deposition over the Internet. Some 13.5 million workers slacked off and logged on to see what the president and Monica Lewinsky had been up to.
In another instance, firefighters in Columbus, Ohio, triggered an Internet investigation, media sensation, and public uproar when a routine scan of on-the-job Internet surfing revealed that they were visiting as many as 8,000 pornographic sites a day.
And then there was the FCC employee who inadvertently sent a dirty joke titled "Nuns in Heaven" to 6,000 journalists and government officials on the agency's group e-mail list. This employee's lapse in judgment resulted in negative publicity and national embarrassment for the FCC.
What about computer crime? Accord-ing to the 1999 Computer Security Institute/FBI Computer Crime Security Survey, U.S. businesses lost more than $100 million to computer security breaches in 1999.
Many suspect just a small percentage of crimes were even reported. A financial institution experienced a $1 million loss from theft of proprietary information. A high-tech company suffered a $500,000 loss when its system was penetrated. A manufacturer reported a $1 million loss to financial fraud.
In this survey, 20 percent of respondents reported theft of proprietary information. Sabotage of data or networks was cited by 17 percent of respondents. In many cases, all it took was one click of a mouse.
These are just a few of the risks associated with businesses operating computers. Let's look at a few techniques to re-duce them.
The first line of defense is developing effective e-risk policies and procedures. This starts with a policy that governs what documents can be created and the content that's acceptable in your company. These should be written to address e-mail, Internet, and software usage.
Jokes should be off limits (sorry).
A retention and deletion program should be put in place. There is no good reason to save everything, especially e-mail files. This may actually include forcing employees to empty their mailboxes.
Employees need to know the rules regarding the Internet as well. What type of sites are off limits? What about personal use of the computer at work?
Copyright and trade secrets should be available only to employees that need to access this information.
Employers typically have the right to monitor employee e-mail and Internet usage.
All of these issues need to be in writing, and typically they are placed in the employee handbook.
The second line of defense is establishing security measures for your system.
Install firewalls and secure passwords.
Install encryption coding to safeguard the transmission of electronic data.
Assign your network administrator a security role.
Conduct periodic security audits.
Protect your network from viruses and update the anti-virus program often.
Lastly, in order to protect against these risks, look into cyber insurance coverage.
This coverage can protect you from financial damage caused by viruses; copyright, patent and trademark in-fringement; extortion; unauthorized use/access; employee or third-party sabotage; errors and omissions; and theft of money and data. An employment practices liability policy can protect against risks like sexual harassment and wrongful termination.
As with most risks, it's prudent to proactively identify and implement measures before anything happens. Bus-inesses should consider hiring experts to help them establish guidelines and manage risk.
A good team normally includes an attorney and security and insurance experts. Seek out professionals who have experience and expertise in cyber-exposure.
(Richard Ollis is a commercial in-surance specialist with Ollis and Company Insurors.)
This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.
Longtime employee sues Ozarks Tech, alleges retaliation
Cavender’s opens hat shop in southeast Springfield
Caterpillar to acquire John Fabick Tractor Co.
Eric Schmitt introduces Modern Skies Act
Springfield airport to cut the ribbon on $35M in construction projects
Legacy Bank accused in lawsuit of failing to protect customers in data breach