Listen to this article
Estimated 3 minutes
The audio version of this article is generated by AI-based technology. Mispronunciations can occur. We are working with our partners to continually review and improve the results.
Four former executives of a Waterloo, Ont.-based firearms distribution company face a slew of charges after a complex, multi-year investigation into an alleged scheme that used fabricated invoices and financial records to get tens of millions of dollars in financing.
“It is believed that the fraud proceeds were used for personal gain, including the purchase of luxury items and properties,” said Det. Const. Mike Payne of Waterloo Regional Police Service’s Commercial Fraud unit.
Police allege Trigger Wholesale Inc. defrauded Oakville-based commercial lender Clearflow Commercial Finance of approximately $48 million between 2016 and 2020 through forged documents and…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
