The increasing insider threat to company security

Jul 19, 2008 09:18 GMT  ·  By

A court of law has found Carolyn M. Gudmundson, a former employee of industry giant Microsoft, guilty of embezzling approximately $1 million. Consequently, she was sentenced to 22 months incarceration time but, after she is done serving her time, she will continue to be closely supervised for a period of three years. Microsoft has been awarded monetary restitution to the amount of $923,000.

"Other employees who have similar opportunities to place their hands in the corporate till need to understand that society takes this sort of crime very seriously," said Judge Ricardo Martinez.

Gudmundson, aged 43, had been a Microsoft employee for a period of about 17 years, between 1987 and 2004. Since 2000, her position in the company was of program manager within the MSN division and, as such, she was responsible with the purchase, registration and renewal of Internet domain names. Microsoft would repay the manager for purchasing of said domain names with her own money, just that Gudmundson was not honest about how much she was spending.

This is how the whole thing went down: whenever an Internet domain had to be acquired, Gudmundson would get out her credit card and purchase it. Then, she took the receipts, modified them so that they would show the domain cost more than she actually spent on it, and filed with Microsoft for reimbursement. Another trick that she would use was to ask Microsoft to pay a third party, which supposedly purchased domains at the request of the company. However, no such purchase was ever made, since Microsoft already owned those domains.

Ricardo Martinez, the judge that presided over the case, said that the punishment, although not fitting the crime, was appropriate because the manager had admitted to doing the crimes she was charged with. The U.S. attorney even dropped a total of 17 charges of mail and e-mail fraud during plea bargain talks.

This is another case that proves insider threat is a serious security issue within a company or an organization. In related news, the administrator for the FiberWAN network of San Francisco who, earlier this week, used his skills to lock everyone else out of the network, has pleaded not guilty to the charges brought against him.