Cybersecurity breaches involving employees.
Cybersecurity Breaches Involving Employees
A cybersecurity breach involving employees occurs when an employee, intentionally or accidentally, causes, facilitates, or becomes the target of unauthorised access to an organisation’s computer systems, networks, databases, devices, or confidential information. Employee-related breaches may arise from phishing, weak passwords, unauthorised disclosure, insider theft, misuse of access privileges, malware, social engineering, lost devices, or deliberate data exfiltration.
The legal consequences may involve employment law, data-protection law, confidentiality obligations, contractual liability, criminal law, and regulatory penalties. The exact liability depends upon the employee’s conduct, the employer’s security measures, applicable legislation, and the nature of the information compromised.
1. Types of Employee-Related Cybersecurity Breaches
Common examples include:
Phishing attacks: An employee is deceived into revealing credentials or opening malicious content.
Insider misuse: An employee deliberately accesses information without authorisation.
Data theft: An employee copies customer, business, or trade-secret information.
Credential compromise: Employee passwords or authentication credentials are stolen.
Unauthorised disclosure: Confidential information is sent to an unauthorised person.
Lost or stolen devices: Laptops, phones, USB drives, or other devices containing organisational information are compromised.
Improper use of cloud systems: Employees upload confidential material to unauthorised cloud or personal accounts.
Malicious insiders: Employees intentionally damage systems or exfiltrate information before or after leaving employment.
2. Employer's Responsibility
Employers generally have an important responsibility to establish reasonable cybersecurity safeguards. Depending on the applicable law and industry, these may include:
access controls;
password and authentication policies;
encryption;
employee training;
monitoring and logging;
incident-response procedures;
data-classification policies;
restrictions on removable media;
regular security assessments; and
prompt investigation of suspected breaches.
An employer may face legal or regulatory consequences where inadequate security controls contribute to the breach.
3. Employee's Duty of Confidentiality
Employees commonly owe contractual and fiduciary duties concerning confidential information. Employment contracts may contain provisions dealing with:
trade secrets;
customer information;
passwords;
proprietary software;
business strategies;
financial information; and
personal data.
Unauthorised access or disclosure may therefore constitute both misconduct and breach of contract.
4. Employee Negligence
Not every cybersecurity incident is deliberate.
For example, an employee may accidentally:
send a confidential file to the wrong recipient;
disclose credentials to a fraudulent website;
leave a laptop unsecured;
download unsafe software; or
use an unauthorised storage device.
The employer should distinguish between honest mistakes, negligence, serious negligence, and intentional misconduct before imposing disciplinary consequences.
5. Malicious Insider Threats
A malicious insider may exploit legitimate access to steal or destroy information.
Examples include:
downloading customer databases before resignation;
deleting company files;
transferring trade secrets to a competitor;
deliberately disabling security controls; or
using another employee's credentials.
In such circumstances, the employer may consider disciplinary action, termination, civil proceedings, injunctions, damages, and, where applicable, criminal complaints.
6. Cybersecurity Breach During Employment Investigations
When an employee is suspected of causing a breach, the employer should conduct a fair and properly documented investigation.
Relevant evidence may include:
access logs;
email records;
system logs;
device records;
CCTV;
file-transfer records;
authentication records;
company policies; and
witness statements.
Evidence should be preserved carefully because its reliability and authenticity may later be challenged in disciplinary or judicial proceedings.
7. Data Protection and Personal Information
Employee-related cybersecurity incidents can expose personal information belonging to:
customers;
employees;
contractors;
suppliers; and
members of the public.
Depending upon the jurisdiction and applicable legislation, the organisation may have obligations concerning security safeguards, breach notification, investigation, and protection of personal data.
8. Post-Employment Cybersecurity Breaches
Cybersecurity obligations may continue after employment ends, particularly regarding confidential information and trade secrets.
For example, a former employee may retain:
customer databases;
confidential business plans;
source code;
proprietary documents; or
trade-secret information.
Employers may use contractual confidentiality provisions and applicable intellectual-property or trade-secret remedies to protect such information.
Important Case Laws
1. International Airport Centers, L.L.C. v. Citrin, 440 F.3d 418 (7th Cir. 2006)
An employee deleted data from a company laptop before leaving employment. The court considered the employee's obligations concerning company information and computer use.
Principle: An employee's authority to use company computer systems does not necessarily authorise destructive or improper conduct involving company data.
2. United States v. Nosal, 676 F.3d 854 (9th Cir. 2012)
The case concerned employees and former employees obtaining confidential company information through computer systems.
Principle: Computer-access restrictions and the distinction between authorised and unauthorised access can be legally significant in employee-related cybersecurity cases.
3. United States v. Morris, 928 F.2d 504 (2d Cir. 1991)
Robert Morris was prosecuted following the release of the Morris Internet worm, which caused widespread disruption to computer systems.
Principle: Unauthorised conduct involving computer systems can give rise to criminal liability even where the legal consequences of the conduct extend beyond the immediate user or system.
4. United States v. Van Buren, 593 U.S. 374 (2021)
The U.S. Supreme Court considered the scope of “exceeds authorized access” under the Computer Fraud and Abuse Act in a case involving an authorised computer user.
Principle: Merely using information for an improper purpose is not necessarily the same as accessing information that the user was not authorised to access. The precise scope of authorised access is therefore important.
5. Waymo LLC v. Uber Technologies, Inc., 870 F.3d 1350 (Fed. Cir. 2017)
The dispute involved allegations concerning confidential information and trade secrets allegedly taken by a former employee and subsequently connected to a competing business.
Principle: Confidential technological information obtained through an employee relationship can receive legal protection, and misuse or acquisition of trade secrets can result in substantial civil consequences.
6. PepsiCo, Inc. v. Redmond, 54 F.3d 1262 (7th Cir. 1995)
A former employee moved to a competitor while possessing knowledge of PepsiCo's confidential business strategies.
Principle: Courts may protect confidential business information and, in appropriate circumstances, restrict conduct that threatens the misuse or disclosure of confidential information.
7. EarthCam, Inc. v. OxBlue Corporation, 703 F. App'x 803 (11th Cir. 2017)
The case involved allegations concerning former employees, confidential information, and competitive use of proprietary material.
Principle: Former employees may remain subject to obligations concerning confidential and proprietary information obtained during employment.
8. American Express Travel Related Services Co. v. Rome, 948 F. Supp. 2d 971 (D. Ariz. 2013)
The case involved allegations relating to unauthorised access to confidential information by an employee.
Principle: Unauthorised access and misuse of confidential business information can support legal remedies where the relevant factual and statutory requirements are satisfied.
Indian Legal Context
In India, employee-related cybersecurity incidents may involve the Information Technology Act, 2000, contractual confidentiality obligations, employment/service rules, intellectual-property law, and applicable data-protection requirements.
Sections of the Information Technology Act may become relevant depending upon the conduct, including provisions dealing with unauthorised access, damage to computer resources, disclosure of information, and computer-related offences.
An employer should not automatically assume that every employee cybersecurity incident constitutes criminal misconduct. The organisation should establish:
What happened?
Who had authorised access?
What information was accessed or transferred?
Was the access intentional or accidental?
What company policy or contractual obligation was violated?
What evidence proves the employee's involvement?
What actual harm resulted?
Conclusion
Cybersecurity breaches involving employees represent a combination of technology, employment, confidentiality, data protection, and criminal-law issues. Employers should implement preventive security controls, clearly define employee access rights, train employees, preserve digital evidence, and investigate incidents fairly. Where an employee deliberately accesses, steals, discloses, or destroys protected information, disciplinary action and legal remedies may be available. At the same time, accidental breaches should be assessed proportionately, considering the employee's level of negligence, applicable policies, actual harm, and the organisation's own cybersecurity safeguards.

comments