Greg Young

A member of the Gartner Blog Network

Greg Young
Research VP
6 years at Gartner
22 years IT security

Greg Young is a research vice president in Gartner and the lead analyst for network security. Mr. Young has experience in IT security in product companies, and in both the private and public sectors. He spent his military career in technology security… Read Full Bio

Coverage Areas:

The Absence of Enforcement, Accountability and Responsibility

by Greg Young  |  May 19, 2009  |  Comments Off

The Financial Post detailed the $1M fine paid by a Celestica outsourcing strategist for surreptitiously reading employees’ emails, including those of senior management.

The less jaded would say wow – a great fine and a win against doers of tomfoolery with the computers.  But no! The former employee was only fined because he traded on insider information having had access to the company financial results.  Any mention of charges for the illegal access part of it?  Nope.  I am thinking of Al Capone going to jail for tax evasion: at least one regulatory body seems to be doing something, albeit for "downstream" or secondary offences. 

Breach disclosure laws are usually only local, and enforcement of computer crime is spotty and underfunded.  Meanwhile, federal agencies on both side of the US/Canada border jockey for the respective privilege of wearing a big cowboy hat.  In the army they teach that leadership comes with authority, responsibility, and accountability: beware of agencies reaching for the hat getting excited about the first, waving a hand at the second never ever mentioning the third.

Comments Off

Category: Uncategorized     Tags: