State prosecutors on Sunday indicted Be’er Ya’acov deputy council head Noam Sasson and six other defendants over allegations that he exploited his municipal position to steer public contracts to associates, including a transportation tender from which a company allegedly received more than NIS 20 million.
The indictment charges Sasson with three counts of fraud and breach of trust, aggravated fraud, making a false sworn statement, threats, and witness harassment.
The other defendants include Giora Shabtai, contractor Erez Medina, Oshri Farhan, transportation contractor Eliyahu Dawan, and two companies. They face various charges, including aggravated fraud, offenses involving bribery and mediation, false corporate records, money laundering, and tax offenses.
According to the indictment, Sasson served from June 2019 as a salaried deputy head of the Be’er Ya’acov Local Council, holder of…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
