Procurement Fraud in the IT Sector
TopShelf writes "IT staff usually enjoy unrivaled access to the deepest details of an organization's structure, and all too often, some submit to the urge to use that knowledge for nefarious purposes. Baseline Magazine explores how how Tech Insiders Cheat Their Employers, with examples of executives creating their own vendors to which fat contracts are awarded. Perhaps the most galling case involves a director in the New York City Chief Medical Examiner's office who is accused of scamming FEMA in the wake of the September 11, 2001 terrorist attacks."
For six years I would take a pad of post-it notes from the supply cabinet. After I had enough stock, I opened a wholesale company and sold them all back at a discount rate. Then I did the same with toner cartridges, pens, erasers, etc. Eventually I worked up to filing cabinets.
I'm trying to figure out how to do it with the company cars, but that one's a little tough.
Slashdot Burying Stories About Slashdot Media Owned
As opposed to creating whole outsourcing companies to manage contractors during an outsourcing push. Or an executive personally subcontracting a building project at a bid below the rest of the local builders. Or the usual everyday case of standardizing on vendors that appear heavily in the executive's personal stock portfolio.
[
Right off the top - there are always some people who are going to screw you, no matter how you treat them.
But for most employees, instilling loyalty and pride in the company is the best disincentive to theft. It's also the best way to increase productivity.
How does a company do that? Pay employees what they're worth, don't overwork people, be ethical in your business operations. Basically, it's the golden rule. Treat your employees the way you want them to treat your company. Your employees will take care of the rest, and the money will roll in.
It's too bad that most companies are only in business to line the pockets of the top execs this quarter, and damn the next financial period; we'll figure that out later.
Web 2.0 == Giant Blogspam Circle Jerk
Any employee with purchasing power can defraud the company. The more purchasing authority that person has, the greater the damage he can inflict. The only way to get around this is to make sure you're hiring the type of people who won't do this sort of thing because of a strong sense of ethics. Obviously, this isn't 100% foolproof, but there is always risk in business. The idea is to mitigate that risk as much as possible.
Singling out IT managers as potential sources of fraud is disingenuous. ALL managers have the potential for fraud, because they have the access and the authority to commit the crime.
It sounds like the companies that are being so defrauded must have terrible control measures. For instance, in my company (a logistics/shipping co) we need to have several pieces of documentation before any job is done, or any invoice raised. The measures are stricter when it involves money going out of the company in any way. There are varying levels of control depending on the value concerned.
At least 4 people see a cheque before it is signed and sent out, two signatures are needed on the cheque and one from someone like a manager on the form requesting it. If I want a printer cartridge, I have to fill out a form, get my line manager to authorise it, and then give that to the secetary - who also checks everything, then when she places her order it has to be signed off by her boss. Etc etc.
Control measures are fundamental to reducing exposure to fraud or theft IMHO. Trust me, I'm an accountant.
I would've gotten away with it too if it weren't for those meddling kids!
The only problem is that Data would never do something like sell Dilithium Crystals on ebay2400.com or anything else to profit from having control of the Enterprise. This would be more like the guy from the past who stole a time machine from a scientist from the future and then started making patents on stuff he stole off the Enterprise. Get your analogies striaght. :p
As a rule, I never trust dark brown ketchup.
That reminds me of the recent case where a guy was caught trying to pass a counterfeit billion dollar bill. Most criminals avoid detection by trying to fly under the radar with a scam so low level it is undetected. This guy was caught because the attack was so ridiculously visible - which reminds me I blogged on this and forgot to actually publish the post, must do that.
These frauds are all pretty standard ones that any good auditor should be able to spot. Placing orders with a cutout company is an old ruse. What is suprising is the way that an exec of a public company would put it all on the line for what was actually chickenfeed compared to his salary and $900K stock options. I did that rant on my blog already though
The only part of this that is Internet specific is the attempt to shut down the whistle blowers with court orders in the fourth case. Again it happend in Enrons home base of Texas.
The blogosphere recently uncovered a series of frauds committed by Duke Cunningham and a number of other congressmen. The mainstream media has yet to tell the public anything close to the whole tale which is still being investigated but has already cased the dismissal of Porter-Goss as head of the CIA, the uncovering of a prostitutes and poker game held by lobbyists at the Watergate hotel and a peculiar series of limosine contracts. The bloggers are also currently getting their teeth into what appears to be a bipartisan scam where a legislator buys land up cheap, gets an earmark appropriation passed to build on or close to it that massively increases the value of the land and then sells dear.
In the UK the magazine Private Eye has traditionally been the whistle blower. The US has never had a true equivalent. Private Eye has dramatically reduced the amount of graft in UK public life by bringing to light many schemes that would otherwise have continued for decades.
Perhaps the Internet can be the Private Eye for the US.
Looking for an Information Security student project suggestion?
Try http://dotcrimeManifesto.com/
You have taken nerdiness to such a level, there is no room for mockery.
I applaud you.