Not long after he arrived on the Stanford University campus in 2022 as a 17-year-old freshman, Theo Baker received a tip about the school’s president, the neuroscientist Marc Tessier-Lavigne. Baker, the son of two prominent Washington, D.C., journalists, had joined the staff of The Stanford Daily and was looking for a story he could dig into. And here it was: On a website called PubPeer, a forum for discussing scientific papers, critics were claiming that papers coming out of Tessier-Lavigne’s lab contained manipulated and fraudulent data. And that it had been going on for years.
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
