job

Corporate spying


Bruce Schneier covers corporate spying today - you know, when your employer or your shop uses spying methodology to learn to know you better. I only wish this was new - government trained security specialists have crossed over to private business since the dawn of time.

Since you do not have to work for the government to have a license to kill - it is enough to be a hired gun - and the number of specialists increases, it is only natural that some accepts tempting offers from the corporate world.

What is more - there is nothing strange in a company - big or small; to protect itself. The challenge is to be able to draw the line - where do you stop? Is it OK to have Wall-Mart or HP to install wiretaps on you (or someone else)? If not - when would it be OK? If you think it is just fine, when would it NOT be OK anymore?

We know that most companies today use computers to track everything related to it's production, logistics and sales. Why is it so chocking to read that they are using computers to analyze and track that information too? After all, Business Intelligent and Data warehousing is nothing new under the sky.

From the article:

"If you try to buy more than three cell phones at one time, it will be tracked," he (David Harrison) reportedly told the audience.

The fact that they let you know some of their thresholds may raise a few eyebrows, but again - if you are a smart criminal, you would not use a clean ID to buy your batch of prepaid phones, now would you? Most likely you would use someone else's CC?

When your company is large enough, you start spending money on security. And security in this sense means you put into action counter-measures and information gathering. When your company is larger than some countries, it would be quite expected that you use some of the same measures to protect your assets.

I think it is unavoidable. We keep introducing tools that facilitate the collection, storing and analyzing of data. Obviously some will collect and analyze more data than others. Surely this will continue. And most importantly, most people do not care.


Available for training

I am about to break a principle now. When I first started my blog, I decided I would not use it to promote services and products. I will break that principle today - as I am currently (this autumn) available as trainer/consultant. 

I am a great trainer (certified in JCI), and I get great feedback. Topics are mainly security related, with focus on user awareness and management training. I also do project management and consulting.

This autumn, I will be a guest lecturer at BI - the Norwegian School of management. 

If you know of anyone who might require my services (I will travel), I will be grateful to hear from you or them!

 

Navigation

Recent comments

Recent blog posts


The blogger is Kai Roer, a European Information security professional.

View Kai Roer's profile on LinkedIn

Lijit

Resources

Archive

Explore Security Bloggers Network (a FeedBurner Network)