Rich Meneghello//July 3, 2009//
Where is your company’s sensitive information at this very moment? You may say that it is in the company’s files locked in someone’s office or in a certain directory on the company’s server. I hope you’re right. But according to a recent survey, information you believe is confidential may also be in a number of other places, including your competitors’ offices. A Ponemon Institute report suggests that employers may be losing much more sensitive and confidential information than they imagine.
Some details from the report should give every employer cause for concern, particularly in this time of layoffs and sharply increased staff reductions.
According to the report, 59 percent of those who were terminated or who voluntarily left employment, stole sensitive and confidential company data, including e-mail lists (65 percent), nonfinancial business information (45 percent) and business contact lists (39 percent). The method of capture was reported to be disk or DVD (53 percent), USB memory stick (42 percent), or e-mail (38 percent). Of those who took data, 79 percent said that they were aware that company policies did not permit them to take the data. The most frequent reason for taking the information was 鈥渢o leverage a new job鈥 (67 percent). Also, 69 percent of respondents reported finding a new job, and of those, 67 percent use the information in their new jobs.
One of the most telling statistics 鈥 of those who admitted to taking data, 61 percent of employees reported having an unfavorable view of their previous employer, while 26 percent reported having a favorable view of their previous employer.
The report describes the problem, but what can an employer do? As an initial matter, you should identify for yourself what information is most essential to the way you do business. Or, in other words, 鈥淲hat information would I most not want my competitors to know about?鈥
From a legal perspective there are two essential sources of protection of trade secrets and confidential information: the Uniform Trade Secrets Act and common-law principles of theft and breaches of loyalty. The statute defines a trade secret as information that: 1, derives independent economic value, actual or potential, from not being generally known to, and not being readily ascertainable by proper means by, other persons who can obtain economic value from its disclosure or use, and 2, is the subject of efforts that are reasonable under the circumstances to maintain its secrecy.
Since the law is generally designed to help those who help themselves, what should an employer do to help itself in this area? Here are a number of areas recommended to start from to institute a credible information protection strategy:
鈥 Consider requiring employees to sign confidentiality agreements, non-solicitation agreements, covenants not to compete and assignment-of-invention agreements.
鈥 Implement appropriate security policies that address use of computers, e-mail, voice mail and the Internet 鈥 define physical and electronic access to trade secrets, address telecommuting and employee privacy concerns and identify restrictions on vendors and others to access of confidential information.
鈥 Train company employees in the policy and proper handling of company confidential information, and their security responsibilities.
鈥 Secure the physical environment, which includes steps such as restricting access to servers, routers and other network technology, to those whose job responsibilities require access; keeping an equipment inventory; locking file cabinets and offices that store sensitive information; labeling all documents containing trade secret or confidential information as 鈥淐onfidential鈥; cross shredding all paper documents containing sensitive information; and ensuring that all magnetic media data is erased before discarding.
鈥 Secure the company’s computer systems and network by limiting access to sensitive information to only those who have a need to know or use the information, and keep audit logs of all access requests to critical systems and sensitive information.
鈥 Protect company information upon an employee’s termination by disabling all accounts and access privileges of the terminated employee and changing all access codes and VPN (virtual private network) and dial-in numbers; examine the employee’s computer or laptop to determine if the employee has accessed or copied sensitive information in recent months; conduct an exit interview during which you remind the employee of continuing obligations not to improperly use the company’s confidential information and get the departing employee’s agreement not to do so. Ask the departing employee if he or she has any company confidential information.
These steps won’t guarantee that you will never lose important confidential information to departing employees, but consideration of the problem and implementation of controls will certainly make it much harder for a departing employee to do what so many other departing employees are doing in this struggling economy. Implementing controls will help ensure that your departing employees are the 41 percent of individuals who do not take confidential information with them.
Rich Meneghello, the managing partner of the Portland office of Fisher & Phillips LLP, is dedicated to representing the interests of management. Contact him at 503-205-8044 or [email protected].