We asked our readers to share the dirtiest IT secrets they had encountered at work—lies from the gray areas and the dark side of technology that others are completely unaware of. After organizing the submissions, we handed these "secrets" to experts in related fields for analysis. Some received the experts' recognition, but others were not confirmed.

IT professionals often spread gray lies and play dark political games in tech business as if nothing were wrong.
IT professionals often know exactly what lies behind a problem—and sometimes they themselves are the ones who caused the trouble.
We asked our readers to share the dirtiest IT secrets they had encountered at work—lies from the gray areas and the dark side of technology that others are completely unaware of. After organizing the submissions, we handed these "secrets" to experts in related fields for analysis. Some received the experts' recognition, but others were not confirmed.
Is the power held by system administrators enough to become a CIO's worst nightmare? Do IT employees still take company equipment? Can the data we store in the cloud really vanish into thin air? Are tech support service prices unreasonably high?
Through today's article, we will learn the views of both the parties involved and the relevant experts.
IT Dirty Secret #1: System Administrators Have the Company Over a Barrel
The IT weasel has actually become the gatekeeper of the plump chicken—data.
Anyone who has followed Edward Snowden's story will surely understand the damage a system administrator can cause. But even IT professionals themselves may not imagine how astonishing the power and danger of an unconstrained administrator truly are.
"For IT professionals, there is no such thing as a secret," said Pierluigi Stella, CTO of managed security services provider Network Box USA. "I can install detection tools on my own firewall to capture every data packet entering and leaving a specific computer. I can see what people write in messages, which websites they visit, and what they post on Facebook. In fact, morality is the only factor that keeps IT professionals from misusing or abusing this power. IT professionals are essentially a miniature NSA existing right beside us."
This situation is quite common, and most CIOs are already aware of it, noted Tsion Gonen, chief strategy officer at data protection company SafeNet.
"I estimate that more than 90 percent of enterprises face this kind of crisis," he said. "The reliability of enterprise security is closely related to the trustworthiness of IT administrators. It is very difficult to know exactly how many system administrators are abusing their access privileges—but one thing is certain: the number is large enough to make headlines in the newspapers every week. The scariest part is that security risks often come from the very people responsible for assigning access permissions to employees."
David Gibson, vice president of data governance solutions provider Varonis, also agrees that administrators generally do have the ability to access data without anyone being the wiser, but he offers a more specific figure—50%. He adds that this problem is not confined to administrators—most users have the ability to access far more data than their jobs require.
He said the solution to this challenge can be summed up in two parts: using a "least privilege" model to limit employees' access capabilities, and continuously monitoring those who access data.
"Companies need to be able to see which employees accessed what data, who owns the data, and who has already accessed which files," he said. "On that basis, IT departments will be able to engage directly with data owners, thereby striking a balance between reducing access and maintaining an acceptable user experience."
IT Dirty Secret #2: Employees Are Likely Taking the Company Home
Those "retired" IT assets are likely to get a second life in unexpected ways.
Outdated technology equipment is rarely actually thrown into the trash; it often quickly finds a new home—and sometimes that "new home" intersects with IT employees' own homes.
"Employees stealing decommissioned equipment is nothing new," said Kyle Marks, CEO of Retire-IT, a company specializing in fraud and privacy compliance issues related to IT assets. "I have never met an IT professional who has never taken company property for personal use. For most people, taking a little outdated equipment is no big deal. Many people don't regard it as a security threat—once equipment is retired, they treat it as something that can be disposed of at will."
The biggest problem with retrieving equipment from the trash or recycling bin is that it may still contain sensitive data. If that data is exposed, it could cause huge losses to the company, Marks noted. Of course, even if there are no subsequent problems, the act itself still amounts to stealing company property.
"Theft and fraud are very serious situations that could easily trigger a large-scale privacy incident," he added. "If this state of affairs is allowed to continue, unscrupulous IT employees could push an entire enterprise to the brink of collapse. Yet in most cases, the person responsible for ensuring that all assets are properly disposed of—that is, all data is erased—is often a member of the IT department. Companies need to establish a 'reverse procurement' process to ensure that assets leave their jobs in a proper way."
But does every IT employee extend greedy hands toward outdated hardware? A seasoned IT asset disposition practitioner who declined to give his name says the actual situation is far from what Marks inferred.
"I'm not saying theft doesn't exist," he explained. "I'm just saying that I have never encountered a single practitioner who has a fixed pattern of handling outdated hardware."
He also added that most devices disappear mainly due to loss or other hard-to-explain reasons—for example, being shipped to the wrong location.
"This sounds a bit like sweeping denial. In fact, many companies are proud of providing security services in a completely honest and trustworthy manner and adhering to their way of doing things."
IT Dirty Secret #3: Storing Data in the Cloud—More Dangerous Than You Think
If legal provisions get involved, no security mechanism in the world will be able to protect us.
Storing data in the cloud is indeed convenient, but we may well have to pay a high price for that convenience: in a legal dispute as tangled as a ball of thread, our data may vanish.
"Most people don't realize that when their data is stored on someone else's systems in the cloud, living side by side with other companies' data, if the other party encounters legal trouble, our data may also be affected and forced to be exposed," said Mike Balter, president of IT support company CSI Group.
In other words, your cloud data is likely to be dragged into trouble because of investigations targeting others—being unlucky is the only reason. Simply because you share a server with a suspected party, a company can suffer serious losses.
A typical case occurred in January 2012, when U.S. and New Zealand authorities shut down Kim Dotcom's MegaUpload file locker. In addition to a large number of movie files that were indeed suspected of piracy, the authorities also seized data belonging to thousands of law-abiding customers and refused to return it. To this day, those poor ordinary users still cannot be sure whether their data can ever be recovered.
"The risk of data seizure is real," confirmed Jonathan Ezor, director of the Business, Law, and Technology Research Center at Touro Law Center. "If law enforcement or other government officials have any legal basis, they can seize storage devices or systems—in certain special events, obtaining approval may be required—and the data on those systems, whether or not it is under suspicion, may be taken away. In short, when any company's data is stored outside its own control, it will inevitably be exposed to some degree of prying—at the very least, others have access to the same hardware."
To protect yourself from this worst-case scenario, users must know exactly where their data is stored and which legal provisions apply to the situation, said David Campbell, CEO of cloud company JumpCloud.
"Our advice is to find a cloud provider that can provide assurances about the physical location of servers and data, such as Amazon, so that everyone can take a proactive stance in controlling unknown risks," he noted.
Ezor also added that encrypting data can effectively prevent those who obtain it from successfully deciphering its contents. Another good idea: always keep a backup of your data on hand. We really can't be sure when that might become the company's last lifeline.
IT Dirty Secret #4: Employees Tighten Their Belts, but the Boss Writes Empty Checks
The finance people have it the worst.
For almost any mid-sized or large enterprise, the procurement approval process has two ways of being executed, pointed out Mike Meikle, CEO of Hawkthorne Group—a senior management and IT consulting firm. First, there is the official procurement process—extremely time-consuming, requiring us to jump through one approval "ring of fire" after another like cats and dogs in a circus. In addition, there is a special "VIP express diamond channel," of course reserved for only a few "special people."
"C-suite executives all have their own procurement channels," he explained. "Approval processes that would take IT people eight months are often completed by these executives in just a few weeks—and that is a very conservative estimate. I call this the 'VIP express diamond channel.' Among all the government agencies and private enterprises I have dealt with, none has been able to completely escape this secretive procurement avenue that exists in the shadows."
The official process deliberately makes things difficult for employees because companies don't want them spending corporate money, Meikle noted—unless, of course, they can find a way onto that secret channel. He also pointed out that, unfortunately, CIOs often don't qualify to join this VIP club, which means that major technology purchases are often finalized without rigorous cost analysis or examination of IT strategy.
“They'll go out to lunch together, and the vendor whispers sweet nothings in their ear; and before you know it, hundreds of thousands of dollars are generously thrown out for another mobile application management solution—these guys don't even realize the enterprise already has one,” he said indignantly. “Now we have two mobile application management solutions—what do we need that many for, to eat?”
But that's not necessarily the case, an anonymous source from the military and Fortune 100 companies objected. While many companies may indeed have circumvented standard procurement processes, what's often involved is something the IT department urgently needs—the reason being to avoid wasting time on red tape, he said.
“Non-technical executives simply don't have the IT knowledge necessary to make major procurement decisions,” he added. “If a senior executive bypasses the procurement review process, insists on signing the purchase order and demanding the vendor ship, then all subsequent technical failures should be attributed to this person through accountability and traceability mechanisms. This is like kryptonite to Superman—their greatest nemesis.”
IT Dirty Secret #5: Standing on the weak side in the balance of customer support
Technicians are just playing with scripts
I'm sure everyone is familiar with this scenario: we communicate over the phone with technical support personnel half a world away, but after just a few words we realize their technical level is poor and they're just reading from a script to the customer. Guess what? That's likely exactly what's happening.
“IT support is a commodity,” said Tim Singleton, president of Strive Technology Consulting, a high-end technical support firm serving small and medium-sized clients. “Most of the tools that can help are free, and computers no longer demand as much technical knowledge from users as they used to. The little girl next door is likely just as capable as a skilled expert at solving your computer problems like an IT company would.”
But some believe this conclusion is too arbitrary. While some simple problems may not demonstrate the necessity of a technical support team, professional advice is still indispensable for complex issues, noted Aramis Alvarez, senior vice president of services and support at Bomgar, an enterprise-level remote IT support solution provider.
“The problem with calling IT support a 'commodity' is that we can't treat all technical problems as the same,” Alvarez said. “Some basic issues can indeed be accurately diagnosed by tech-savvy ordinary users, but more complex situations such as virus infections cannot. The girl next door might indeed have a lot of technical knowledge, but she could end up causing serious damage to the data on the computer.”
Finally, we have to pay a higher price to clean up the mess, added Joe Silverman, CEO of New York Computer Help—a problem that often occurs when companies cut corners technically or when internal IT departments are overburdened.
“In our daily work, we find that many office organizations and functional departments in New York are taking a sloppy attitude toward computer repair work or IT positions—bringing in people from other companies, having family members fill in, or recruiting half-baked friends,” he noted. “Sometimes finance department employees also step in to solve computer problems, but they are often too busy or not experienced enough to fix failed hard drives, motherboards, or power supplies. If the network or server crashes, do you really plan to rely on a finance employee to get the job done, or would you rather trust a senior network engineer with twenty years of experience?”
IT Dirty Secret #6: We know a lot more than you think
Collect data extensively, grasp the full picture
Think you're under intense surveillance by the NSA? Compared to consumer marketing companies and data brokers, the NSA is really just a small player.
The biggest culprit is casinos, said J. T. Mathis, a former casino database manager who wrote and published “Take It All: Through the City of Prosperity” based on his personal experience. “When you walk into a casino, the bet you place is far more than money—you're actually gambling with your personal data.” According to Mathis's estimates, his former employer's marketing database contained approximately 100,000 or more active or inactive gambler names.
“From the moment you step into the casino, every move you make is under tracking,” Mathis pointed out. “If you sit at a slot machine, casino management knows your current location, how many times you've pulled the handle, how many coins you've inserted; they know you like to eat at 4:30 and prefer the lobster platter. They know your favorite cigarette and liquor brands, and whether you watch adult programming in your room. And when you return in the summer, they can immediately discern that the woman with you is not your original wife, so staff can greet her by name 'Cindy' rather than your wife's name 'Barbara'.”
Michael Simon, a former casino executive now at Louisiana State University, confirmed Mathis's account. But he added that the way casinos collect data is not much different from CVS, PetSmart, or Amazon.
“The MBA class I currently teach focuses on database analysis and data mining, and all the companies we've surveyed collect customer information and provide services based on customers' personal habits,” he said. As the author of “My Gaming Life: A Former Casino Executive's Personal Perspective,” Simon added, “This has become a common business practice today, not some secret. For example, I bring my dog to PetSmart for special products and services, and the programs they offer definitely match my personal consumption habits—I'm very satisfied with that. From another perspective, PetSmart is actually providing what I want in a very efficient way, rather than wasting time preparing things I would never accept—such as discounted cat food or tropical fish.”
But only one thing is different: Mathis was laid off by the casino in May 2012, but at the time he still had a copy of the database. And when trying to return the copy to the casino, his luck was rather bad—they refused to answer his calls—so, he decided to use the data he had to talk about gambling matters.
Source: http://developer.51cto.com/art/201311/415064.htm