Slashdot Mirror


Before You Fire the Company Geek

An anonymous reader writes "A new 'insider threat' survey by the US Secret Service and Carnegie Mellon University finds that 82 percent of people who hack their company 'exhibited unusual behavior in the workplace prior to carrying out their activities.' A somewhat amusing writeup at washingtonpost.com points to a bunch of more interesting gems hidden deep in the study, including: 'Almost all - 96 pecent - of the insiders were men, and 30 percent of them had previously been arrested, including arrests for violent offenses (18 percent), alcohol or drug-related offenses (11 percent), and non-financial-fraud related theft offenses (11 percent).' The blog post also notes that 86 percent held technical positions at the companies: '...if you're going to fire someone (particularly company geeks who have the motive, means and access to inflict pain on your computer systems) make double sure you cut off their e-mail and network access at the same time you hand them their walking papers.'

45 of 624 comments (clear)

  1. Further down in the report... by It+doesn't+come+easy · · Score: 5, Funny

    The survey went on to say that the remaining 18 percent of people 'exhibited unusual behavior in the workplace while carrying out their normal daily activities.'

    Don't cha know...

    --
    The NSA: The only part of the US government that actually listens.
    1. Re:Further down in the report... by Mad+Man · · Score: 5, Insightful

      Further down in the report... (Score:5, Funny)
      by It doesn't come easy (695416) * on Tuesday May 17, @01:15PM (#12557076)

      The survey went on to say that the remaining 18 percent of people 'exhibited unusual behavior in the workplace while carrying out their normal daily activities.'


      The original article states
      "that 82 percent of people who hack their company 'exhibited unusual behavior in the workplace prior to carrying out their activities.'"

      This does not mean that 82 percent of the people who exhibit unusual behavior are going to hack their company.

      That's like some racist bastard saying that because 50% of all homicides in the United States are committed by African-Americans (which is true), 50% of African-Americans are murderers (which is not true).

      Or some leftist bigot claiming that becuase 65% of all homicides in the United States are committed by someone with a firearm (which is true), that 65% of gun owners are murderers (which is not true).

      I'm sure there's a name for this common type of logical fallacy, but I don't have time to look it up.
    2. Re:Further down in the report... by Fruit · · Score: 5, Funny

      I believe this particular fallacy is usually referred to as "statistics".

    3. Re:Further down in the report... by NoTheory · · Score: 4, Interesting

      Well... just look at Bayes Rule:

      P(A|B) = P(B|A) * P(A) / P(B)

      The fallacy at hand assumes instead that:

      P(A|B) =/= P(B|A)

      The probability of observing unusual behavior in individuals who commit retalitatory hacking is .82 (so, P(A|B) = .82). The probability of observing retaliatory hacking in individuals who commit unusual behavior is not .82 ( P(B|A) =/= .82 ). It's .82 * the probability of retaliatory hacks generally / the probability of unusual behavior generally.

      --
      There are lives at stake here!
    4. Re:Further down in the report... by SatanicPuppy · · Score: 4, Informative

      It's the "Fallacy of Affirming the Consequent"

      Basically, it's whenever you have a one way relation (A->B) and you turn it around to say (B->A), implying that A and B are logically equivalent when it isn't the case.

      Good argument, btw.

      --
      ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
  2. Apologies to Tyler Durden... by TripMaster+Monkey · · Score: 5, Insightful




    "Look...the people you are looking for are the people you depend on. We fix your computers, we update your websites, we route your packets, we patch your servers, we guard your data while you sleep. Do not fuck with us."



    Seriously, though, sabotaging your former or current network is just a plain dumb idea, especially if it is/was your job to keep this sort of thing from happening. In the final analysis, the only real thing an I.T. professional possesses is their reputation. Trash that, and you'll find it difficult to secure further employment.

    --
    ____

    ~ |rip/\/\aster /\/\onkey

    1. Re:Apologies to Tyler Durden... by TripMaster+Monkey · · Score: 4, Insightful


      But if their system goes down 6 months later, there is no link to you.


      Until they look through their logs...

      --
      ____

      ~ |rip/\/\aster /\/\onkey

    2. Re:Apologies to Tyler Durden... by Sabaki · · Score: 5, Funny

      We had a case of layoff sabotage at a company I worked for once. The best part is how we found out -- he bragged about it during an interview. The other company, being friends of ours, let us know.

      I don't think he got that job, either.

    3. Re:Apologies to Tyler Durden... by Rorschach1 · · Score: 4, Insightful

      And anyone with this attitude really needs to read Heinlein's "The Roads Must Roll". Guess what? Your garbage man can take exactly the same attitude. You're not really as powerful or indispensable as you probably think.

    4. Re:Apologies to Tyler Durden... by netruner · · Score: 4, Insightful

      Given the fast paced, fix-it-now-clean-it-up-later sloppiness that is prevalent in our industry, it's not too much of a reach to put the following into the code:

      #include "MyHomeDirectory/MegaImportantAndNotCMd.h"

      You could also store config files there and flip that archive flag to "off".

      Folks will get a really nasty surprise when your account is deleted, but was it malice, laziness or just someone constantly running "under the gun"?

      --



      DISCLAIMER: This post was not checked for speling and grammar- if you complain- you're a whiner
    5. Re:Apologies to Tyler Durden... by lcsjk · · Score: 4, Funny

      Anybody that stupid does not have to work. He can be declared mentally disabled and get disability checks paid for by all the rest of us.

    6. Re:Apologies to Tyler Durden... by greed · · Score: 5, Interesting
      Folks will get a really nasty surprise when your account is deleted,

      Had a realization about unintentionally creating a situation like that at my previous job.

      All the department's partitions on the AFS and DFS servers were charged to my account--they had no way of assigning space to a group. It was 4:30 PM before a long weekend. Very few people were left in IT.

      I suddenly realized what would happen to all the batch jobs when everything belonging to my account was locked out.

      My manager was able to find someone in IT who could suspend the automatic lockout until they could reassign all the filesystem resources...

  3. Of course... by eyegor · · Score: 5, Funny

    They're assuming we already haven't taken control of everything else... who needs email when you control the elevators and doors... :)

    --

    Don't anthropomorphize computers, they don't like it.
  4. unusual behavior by kob43 · · Score: 4, Funny

    'exhibited unusual behavior in the workplace prior to carrying out their activities.'

    Refering to management?

    --


    Kiss my bass.
  5. 96% were men. 97% of Slashdot readers are men by EnronHaliburton2004 · · Score: 5, Interesting

    - 96 pecent - of the insiders were men
    - The insiders ranged in age from 17 to 60 years (mean age = 32 years)


    OSTG user statistics (Including Slashdot).
    - 97% of OSTG readers are men
    - average age is 29

    Too bad OSTG doesn't have crime statstics for Slashdot readers :)

    I think we should have this for our next poll!

    Worst arrest of your lifetime:

    1. Never. I'm a law abiding citizen.
    2. Never. I run away.
    3. A few misdemenors
    4. Violent offense
    5. Alcohol or drug-related offenses
    6. Non-financial-fraud related theft offenses
    7. I'm writing this from death row.
    8. I stole the money, burned down the office and now live on a beach in Fiji with my red stapler.

    1. Re:96% were men. 97% of Slashdot readers are men by flatface · · Score: 5, Funny

      9. It's copyright infringement, not stealing.

  6. Before You Fire the Company Geek by gowen · · Score: 5, Funny

    .. remember to give him a wedgie, for old times sake.

    --
    Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
  7. Well, duh by Anonymous+Brave+Guy · · Score: 4, Insightful
    The blog post also notes that 86 percent held technical positions at the companies: '...if you're going to fire someone (particularly company geeks who have the motive, means and access to inflict pain on your computer systems) make double sure you cut off their e-mail and network access at the same time you hand them their walking papers.'

    Also, if you're going to fire an accountant, it's a good idea to audit the accounts they dealt with particularly carefully, and if you're going to fire a security guard it's a good idea to collect their pass and master keys as they leave.

    Of course, not screwing staff so badly that they are prepared to risk retaliation is also a good move.

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    1. Re:Well, duh by spells · · Score: 4, Insightful

      When the office asshole was fired, they waited for him to go to lunch, revoked all his passwords and user ids, collected his PC, and revoked his access badge.

      Just so that you know, in some large IT companies, you don't have to be the asshole - that is exactly how everybody is treated.

      What I never understood is that they also did this to people when they quit - employee tells his boss he's giving notice and security is called before the employee is allowed to return to his desk. If the employee was going to do something immoral, wouldn't he do it before handing in his resignation?

  8. Don't ya just love statistics by glesga_kiss · · Score: 5, Insightful
    'Almost all - 96 pecent - of the insiders were men, and 30 percent of them had previously been arrested, including arrests for violent offenses (18 percent), alcohol or drug-related offenses (11 percent), and non-financial-fraud related theft offenses (11 percent).'

    Hmm, statistics. I wonder how those numbers compare to people who simply work in IT and don't hack? I'd say 96% being men isn't all that unusual, and I would not be surprised if 11% of the general population has alcohol/drug offences already.

    The problem with stats is that they generally never give you a baseline. Without that they are meaningless.

  9. So in other words... by Heliologue · · Score: 4, Funny

    ...you don't even have to be capable of hacking anymore. Act strangely enough and you can subtlely extort your company for continued employment. What a great idea!

    1. Re:So in other words... by TripMaster+Monkey · · Score: 5, Funny
      Act strangely enough and you can subtlely extort your company for continued employment.

      I've been doing that for years. It's easy. Just get a lot of assorted action figures and display them all around your work area. Then occasionally have disturbing conversations with them...making sure you are overheard.



      "Oh Boba Fett, murder can't always be the answer...what's that, Spawn? But you always agree with Boba Fett!"
      --
      ____

      ~ |rip/\/\aster /\/\onkey

  10. First line of defense by overshoot · · Score: 4, Funny
    Obviously, the most cost-effective strategy is to get rid of any males in IT. 96% means that ditching the guys will get rid of all but 4% of the threats.

    This is, after all, almost an order of magnitude more effective than screening for alcohol, drugs, or felony convictions.

    -+-+-+-+-

    Don't blame me for posting like a PHB. This is how they think, and the fact that it gives them a business excuse to play Charlie with his IT Angels probably won't hurt either.

    --
    Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
  11. Of those they know about... by PornMaster · · Score: 4, Insightful

    Now the good news: almost all of them got caught.

    Well, no... almost all of the ones they know about got caught. How many incidents were simply covered up? How many of the really good ones made it look like a typical software-gone-bad-and-erased-the-data?

    We all know that crime statistics are highly skewed by the reporting process...

  12. you don't even have to be suspicious by yagu · · Score: 5, Informative

    I guess I get it as far as policy goes, but I experienced this a year ago from a large corporation when I got laid off... My manager came to my desk and did the perp walk with me to the office. Told me that in the interest of cutting cough costs the company was willing to offer me a one year severance package and let me go.

    I said, "You're offering me a one year severance package???" He looked confused, but said, "yes".

    I said, "Well then I respectfully decline your offer.... I would like to continue working for this company."

    He said, "It's not optional."

    I said, "Then you're not offering anything to me, you are doing something to me."

    A couple of notes about the treatment therein:

    • By the time I got back to my desk, all access was gone to all systems, man they're fast!
    • The one year package turned out to be 60 days pay (required by the federal WARN law), then one month's pay for every year I'd put in.... with a 10 month maximum. I had 21 years, so I got ten months pay plus the sixty days... I consider that a ten month package.
    • I found it interesting that any others with ten years, eleven years, twelve years, thirteen, fourteen, fifteen, sixteen, seventeen, eighteen, nineteen, and twenty years all also got the same package as mine.... so much for any extra benefits for being a long time and loyal employee.
    • No information as to who else was gone was given, and those who would still talk to me (funny how one laid off somehow develops a quick case of leprosy) had no information internally who was laid off -- they could only tell by seeing around them -- no lists were dispersed.
    • Those who may have had info would not give it (a bit of a pain since I no longer had access to directories, phone numbers, etc.) making the process of setting up contacts for references nigh impossible (turned out, my entire management hierarchy was gone... and I never did find out where they all went).
    • I had a few years left for qualifying for full retirement.

    In my career at this company I had received the highest award given by the company and was flown to a special ceremony to present my project and receive that award.

    Bottom line here: you don't have to be a criminal, act like a criminal, or even be suspected of being a criminal to be treated like one....

    1. Re:you don't even have to be suspicious by IpSo_ · · Score: 4, Insightful

      How does this classify as being treated like a criminal? I always get a kick out of employees who constantly complain about no loyality left in the work place, and how bad they are always treated.

      Were you in handcuffs and a orange jump suit? Put in to a police car with lights and sirens running? C'mon.

      Put yourself in the companies shoes for once.

      1. Companies are required BY LAW to give severance pay and/or notice when laying off employees. Employees can just up and leave any minute they choose for the most part. Not only that, a lot of employees that at least have the decency to give notice are usually an order of magnitude less productive in those last couple weeks. In the companies eyes it would have been less expensive to just leave and not give any notice.

      2. If a company is getting rid of an employee, don't you think its in their best interest to not take ANY chances? It doesn't matter if you've worked there 50 years or not, they owe it to their customers and other employees to remove your access and get you out of the building ASAP, "just in case". It only takes one bad apple to cause major havoc.

      3. Companies have a lot of people to keep in mind when they do business. Share holders, employees, customers. If a company is experiencing hard financial times, in a lot of cases (not all of course) it makes sense to get rid of the highest paid people. If you've been there for 10 years, not only are you normally get paid more then other people, you also get more time off, and require more severance pay. Since getting rid of one high paid employee can in a lot of cases fund two lower paid ones, it also doesn't look as bad to the public. Also because of the severance pay requirements, sometimes companies have to think years in advance, especially in your case. If you have to pay out 12months worth of wages to get rid of someone, you better make sure you do it at the right time and not wait until its too late.

      Yes, some companies are evil, but put yourself in their shoes sometimes.

      --
      Open Source Time and Attendance, Job Costing a
    2. Re:you don't even have to be suspicious by sploxx · · Score: 4, Insightful

      Yes, some companies are evil, but put yourself in their shoes sometimes.
      That sounds like you want to see a company as a person, what it isn't.

      Although I also personally don't like people who always complain about this and that (which IMHO isn't the case here), I think I can't in any case have sympathy with an entity that is only there to produces things in the most efficient way.

  13. These number mean nothing by Blitzenn · · Score: 5, Insightful

    "30 percent of them had previously been arrested, including arrests for violent offenses (18 percent), alcohol or drug-related offenses (11 percent), and non-financial-fraud related theft offenses (11 percent)."

    These numbers also represent the population of the United states as a whole. Yes 30 percent of the US population has been arrested before. more than 20% have a felony on their record and so on. So to paint these people as anything other than ordinary citizens is silly. They simply represent the whole equally as the whole represents itself. Nothing unusual here.

  14. Bad math? by aralin · · Score: 5, Interesting
    • 49 subjects
    • 84% were acting wierd
    • 85% had documented grievances

    So 41.16 were acting wierd, 41.65 had grievances?

    And 100% researchers show signs of random rounding up or down based on mood even within a single study.

    --
    If programs would be read like poetry, most programmers would be Vogons.
  15. Don't ask, don't tell by overshoot · · Score: 5, Insightful
    In the final analysis, the only real thing an I.T. professional possesses is their reputation. Trash that, and you'll find it difficult to secure further employment.

    Short of a felony conviction, that's hard to do. We're a migratory culture and the fact is that no ex-employer wants to do a competitor a favor by giving them information about a candidate -- especially when any negative comments could result in a lawsuit.

    --
    Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
    1. Re:Don't ask, don't tell by DaveHowe · · Score: 5, Interesting
      Personally, I wonder how many of the "he must have hacked it when he left" stories are actually the fact that, absent the geek, nobody actually knows what the software does or how to fix it if they mess it up (which was frequent, but they weren't going to report that to their bosses if the geek could fix it for them) - and if the geek was undervalued because his boss thought he did nothing all day, while he was fixing other people's mistakes.

      Not that I have ever been in that position of course :)

      --
      -=DaveHowe=-
    2. Re:Don't ask, don't tell by Cat_Byte · · Score: 4, Funny

      My list on my resume is more along the lines of:
      (Would be) future employer: May we contact your previous employers?
      Me: You can try. They were all .coms and vaporized in the bubble burst. However, one of my old bosses works at Dennys on the night shift now. You might be able to catch him there.

      --
      Two roads diverged in a wood, and I - I took the one the bus load of girls just went down.
    3. Re:Don't ask, don't tell by SacredNaCl · · Score: 4, Funny

      I'm not always the best about documenting what I do, but every job I've ever left where it actually mattered (where I had some responsibility), I've gone above and beyond making sure they were able to do the job without me. I'm sure problems were still blamed on me, but hopefully nobody had the nerve to suggest that I deliberately caused the problems.

      When you fully come to appreciate just how irrational people are when it comes to things that they do not understand fully -- it's quite probable you were being bad mouthed for "f'ing that up" 20 minutes after you left the building.

      I've had users say "You must have done something to it! It worked fine before YOU touched it!" even more amusing on systems that were off site ...because they can't accept that computers are not fully reliable, software has bugs, and that just maybe they did something they weren't supposed to do (though we did try to make that very difficult). As if I ever had the time to come by and work out how to sabotage their word document, or cause their spread sheet to crash and them to have to do it again.

      The same people can grasp that if their car has a defect, the boogie man probably didn't break into it the night before and sabotage their cruise control so it doesn't stay on. You will, however, never convince them the same thing about the beige box next on their desk. Unfortunately, some of these folks end up in management...

      --
      Freedom is merely privilege extended unless enjoyed by one and all.
    4. Re:Don't ask, don't tell by LaCosaNostradamus · · Score: 4, Funny

      What you SHOULD say is:

      "NO! Most of them work at fast food now and would take the job I'm interviewing for with you! For less money, too! Oh god, I'll never tell you who they are!"

      --
      [You have a stable society when some nut guns down a schoolyard and the law doesn't change.]
    5. Re:Don't ask, don't tell by v1 · · Score: 5, Insightful

      Oh it happens. Happened where I used to work - a new member of the staff (placed in a position of authority) found he had created an intensely hostile work environment. (by pissing off everyone in the building) He quit. I pointed out to our manager (more than once) that we needed to change passwords. "Oh, you don't need to worry about that." was the reply.

      One morning two weeks later the supervisor passwords on all our novell servers suddenly stopped working. Cute trick. We had to hack our own servers to get back in, at all eight locations. Fortunately, only the supervisor accounts he knew about had been changed, which made getting passwords reset much easier because we had a few "service" accounts for our paid support people with supervisor privs.

      Only after that did our I.T. manager agree we needed to change supervisor and dial-in passwords. *sigh*

      It doesn't matter who it is that leaves/quits/fired/whatever, if they had access to passwords, those need to get changed, immediately. Just because a person held a position of authority does not mean there is any reason to trust them with company property after they are gone. Looking back on it, I forgive him for doing it, it was our fault and we got what we deserved by treating security so foolishly. The lesson could have been much more painful.

      I'm against the concept of giving someone the boot without warning though. Funny how companies expect a 2 week (or longer) notice when you're going to cut out, but are perfectly ok with taking your badge at the front door when you come in on a Monday morning. Whenever an employer asks me how much notice I'll give them when I'm headed out, I always say "I'd never give you any less notice than I expect to receive from you." They smile, then they frown. They know how the game works.

      If someone's got it in mind to sabotage the works before they leave, odds are good that they will smell the pink slip before it's handed out, and have ample opportunity to muck with things.

      --
      I work for the Department of Redundancy Department.
  16. What % was retaliation? by GPLDAN · · Score: 5, Insightful

    Here's what the survey doesn't say. That sometimes employers decide to retaliate against employees who point out problems or cause what management thinks is trouble. These employees often find themselves the targets of investigations.

    All surveys like this do is give ammunition to corporate management to investigate who they want, when they want, expect even less privacy and create conditions of employment so egregrious that the IT worker becomes chattel.

    As it is, there are systems to monitor web surfing, chat conversations, phone conversations, VOIP decoders for phone conversations that aren't analog, cameras, keystroke loggers, mail server agents that look for keywords, policies against the use of encryption, etc etc.

    With blood tests and mandatory screenings for crime history, blood history, pretty soon genetic history of family disease (company insurance is expensive you know they don't need any cancer heads) there will be no part of a worker's life that isn't controlled by the corporation that employs them.

    Surveys like this one cull fear in IT shops, fear of insider attacks, of competitive disadvantage brought about by unscrupulous employees. When, in fact, it's employers for the most part who engage in espionage and frame workers. It's easy and efficient. Want to get rid of that guy nearing his pension? Put some kiddie porn on his hard drive.

    We don't need any more tools to spy. We need some fucking national legislation to curb the uncontrolled police state that exists inside the corporations of the world.

  17. I bet they tried. by astro_ripper · · Score: 4, Funny
    "...if you're going to fire someone (particularly company geeks who have the motive, means and access to inflict pain on your computer systems) make double sure you cut off their e-mail and network access at the same time you hand them their walking papers."

    'Uh, Ted, as our only IT guy, could you go ahead and disable your own e-mail and network access; we're firing you this afternoon.'

  18. How to fire a geek by mnmn · · Score: 4, Insightful

    The steps beyond walking him out should be done by another techie, and not just an MCSE.

    ALL passwords should be obtained before he leaves, and ALL should be changed immediately to randomized strings.

    All user accounts should be audited.. if its not supposed to be there, remove it or change its passwd.

    Audit all incoming ports.

    Force EVERYONE at the company to change their passwords to newer better ones. Any techie at a company remembers many others' passwords, especially if its like their last name etc.

    Take immediate backups of important servers and keep em seperate.

    Or you could simply give him a fat severance package.

    --
    "Give orange me give eat orange me eat orange give me eat orange give me you." -Nim Chimpsky
  19. Re:Logs? What logs? by Hentai · · Score: 4, Funny

    Huh. The trouble with that is, machine-gunning the HR department just kills a bunch of line employees and middle managers - it just makes your downsizing decisions easier. Sabotage actually hurts the bottom line.

    --
    -Hentai [in vita non pacem est]
  20. firing != laying off by CrankyFool · · Score: 5, Insightful

    I think it's really important to differentiate "fire" -- hey, this guy is really bad for us and we need to get rid of him ASAP due to some actionable offense -- and "lay off" -- hey, we have a redundancy, or something.

    When firing geeks (having had to do this once), I think you need to do so with extreme prejudice -- take away access while they're talking to HR, lock down, etc.

    When laying off geeks, I prefer for the rules to be different. The person has done nothing wrong, we don't think they're an active threat and, until about five minutes ago, we trusted this person with our data -- because, presumably, we believed them to be honourable people. They've not stopped being honourable people because we've laid them off, and we shouldn't treat them as such.

    Been laid off twice in my life:

    First time was while I was responsible for a large group of geeks. We merged with another company and on the last day of the merger activities, I had the conversation with HR. New CIO had his own person and figured (accurately) we wouldn't get along. HR wanted to walk me out, I wanted to stay the evening because we were concluding a month of activity connecting the two companies. Ended up going up to the President of the company and saying "hey, I was responsible for this, I want to see this finished." He said "hey, no problem. Nothing personal." I stayed, we finished the connections, and then we went out and got stinking drunk.

    Second time was at a financial services company which was, by far, the most paranoid, employee-hostile company I've ever worked in. Thankfully, the CIO was far more sane. When he was forced to let me go, and I packed my stuff, I offered him the opportunity to look through what I was taking to make sure nothing was inappropriately taken (they didn't watch me pack). he declined, for the "hey, we trusted you until ten minutes ago" reason above.

  21. Their conclusions reek - and will break companies by Ungrounded+Lightning · · Score: 5, Insightful

    They collected the data but then jumped to a very wrong conclusion and issued a prescription that, IMHO, will cause MORE harm to companies than it will prevent.

    The "geek" who has been a major player in running the show will be able to break in and do harm if he wants to. If he's of a criminal or revenge-prone he may already have installed a bunch of stuff - and if he's just doing his job he probably has emergency backdoors and the like in case the normal paths break.

    And while ordinary users may not have this sort of access, many of them WILL have been able to accumulate other users' passwords and the like. They too can get in and do damage.

    IF you motivate them.

    The decision is between giving them notice and an opportunity to gracefully disengage from the company, versus pulling the plug and THEN telling them they're fired. The gentle departure versus the knife in the back.

    As someone who has been in the business for decades, I have been laid off from time to time. The usuall procedure has been to give notice and allow the soon-to-be-ex employee to gracefully shut down or redirect his correspondence, clean out his virtual desk, and take advantage of the company email for the first phase of his job hunt. Doing this creates warm fuzzies all around - the social net is intact, mutual recommendations will be forthcoming at all opportunites, if the company ever had need for me again (eventually it did) I'd hire on with no qualms.

    Exactly ONCE I've had the no-notice shutdown. By a PHB who did it that way "because that's how it's done". (No doubt he'd seen trade journal articles like the one above.)

    I was furious.

    I COULD have done major damage to the company's IT infrastructure - but for my scrupulous honesty in business dealings (even with scumbags).

    As it was, when the PHB in question later did a startup and found himself in need of my talents, I didn't even bother to reply to his offer. How can you trust someone like that? You can imagine how I advised anyone considering hiring him or going to work for him.

    Now imagine doing that to someone who is not just able, but willing, to take revenge for any slight. These people are NOT rare - if you have a hundred employees, chances are you have at LEAST one.

    As a friend who was a union organizer once said to me: "The workers will give you what you ask them for. Ask for quantity and you get quantity. Ask for quality and you get quality. Ask for trouble and you get trouble."

    The surprise plug-pull is asking for trouble.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  22. Not exactly the company "geek", but... by hacker · · Score: 4, Interesting

    My wife works for [insert biggest pharma company in the world here], and has for about 6 years. I used to work for them as well for 5-6 years myself. They were good when I was in, then things got "International", and I resigned quick before the walls started coming down.

    In my wife's department (Cancer Biology), there are people who have been there for literally decades. They're so entrenched, they know every system, process, procedure ever made there. If you want to know an answer to some complicated question, these people will know it... and if they don't, they definately know who WILL know.

    One person in particular had been there for 34 years, 11 months.. and they were going around looking for ways to "cut costs" in her department.

    When you retire at 35-years or more into $PHARMA, you get a nice fat severance. Something like $100k/year for every year there + your stock earnings and benefits cashed out, which amounted to over $1M for this person. That's $100k * 35 + $1M (that's over $4.5M total to retire upon).

    They fired him...

    ...30 days before his 35-year anniversary with the company. He got $60k total as a severance. They didn't want to have to pay out his retirement and severance, so they let him go 4 weeks before he would have earned it. If he had known, he probably could have used up 4 weeks of his vacation to eat up the time instead, but he never saw it coming. Nobody did.

    ... after putting in 35 years with the company .

    This kind of stuff sickens me.

  23. I know that situation well by doublem · · Score: 5, Interesting

    At a previous job, I was the only tech staff member who knew how to clear the transaction logs on MS SQL Server. It's not hard to do, but the network admin couldn't even be bothered to do backups more than once or twice a year, which was part of the SQL Transaction log problem.

    When users started getting "transaction log is full" errors and they turned to me to have it fixed.

    Once the error occurred while I was on vacation, and the server remained down for three days and a weekend until I got back. I was accused of hacking the system. I pointed out that I was in the Middle of New Mexico at the time, about a mile underground. Accusations of setting up a logic bomb (Not the phrases they used, but I'll skip the 20 minutes they needed to describe the concept) flew around for a while.

    In the end, the company owner grudgingly admitted that it was probably a maintenance issue, and them reprimanded me for not "trunting the trees" before I left on vacation.

    So for the remainder of my time there I just made sure to do a full backup and shrink the transaction logs every Friday. Automated backups were not an option, as there was never enough drive space for more than one or two backups, so I had to move the old ones to a USB 1.1 drive first.

    And no, system level automation of such rudimentary tasks was not an option. Don't ask. It's a whole other story.

    So I had no reason to hack the system. All I had to do was leave. Of course I documented everything, but I knew no one would bother reading any of it. This is the company that described programmers as "Glorified Typists."

    I made sure to not even visit their web site after I quit.

    I did however have social contact with a few of the non-it staff members. Seems there were a slew of problems with the servers, specifically with a cryptic error about a transaction log that no one in the company could understand.

    In the end they paid a consulting firm to come in and fix the problem, which I'm assuming meant finally automating the backup process and transaction log shrinking.

    --
    "Live Free or Die." Don't like it? Then keep out of the USA
  24. Re:No it doesn't. by Muhammar · · Score: 4, Insightful

    There is a sabotage that actualy works. It is legit, and it also helps your friends:

    1)Go to a better place (in the same city if possible)
    2) Hire away all productive people remaining in your former company.

    There are 2 categories of employees. The sugary HR will eventualy find out that they now have only one.

    --
    I doubt that we will ever figure out - and I suspect that even if we did figure out we couldn't do much about it
  25. Re:Their conclusions reek - and will break compani by Rich0 · · Score: 4, Interesting

    Any IT professional should expect this type of treatment. It is not discourteous, it is professional and appropriate. People who get their feathers ruffled because of this type of thing should check their egos.

    Since when is expecting courtesy having an ego?

    Sure, if somebody threatens a coworker they should be escorted out by armed guards. Everybody expects that, and it is should be done for the safety of everybody else if for no other reason.

    Otherwise, treating employees as if you don't trust them tells them that you don't trust them. It speaks volumes.

    "Professional" does not mean impersonal, or treating employees as if they are nothing more than capital.

    The funny thing is that companies could accomplish most of the security-related goals without destroying the morale of everybody who is left. How about this scenario:

    1. Employee is called to his boss's office.
    2. Boss explains that he has to be let go. Boss has HR present, but HR is presented as being present in case employee has questions, and generally lets the boss (who has a personal relationship) do the talking.
    3. Boss takes employee back to desk for "emotional support" and to help him with anything he needs to carry out. Rest of group gets to say goodbye. It is a sad day, but there is some sense of closure. Everybody gets to say goodbye.
    4. Atmosphere is designed to communicate that employee is not persona-non-grata, and that his coworkers shoud feel free to pass on job openings, and generally feel free to maintain contact. Boss can be a part of this as well.
    5. Employee is walked to the gate, and helped with boxes to the car by boss for emotional support.
    6. Boss tells employee to call him if he needs anything before waving goodbye.

    The employee has been supervised the whole time, and doesn't have an opportunity to cause mischeif. Yet, the entire time he is treated personably, and would be somewhat inclined to accept an offer to rejoin the company.

    Companies often underestimate the impacts that terminations have on the people who remain behind. Seeing their coworkers treated with dignity will go a long way towards discouraging people from jumping off the sinking ship.

    Nobody expects to have free reign inside a company they have just been terminated from. On the other hand, you can at least be nice about it...