
Application of US Intellectual Property Law to Activities Outside the United States
2023/ 8/ 10
How to Find Evidence of Illegal Kickbacks?
2023/ 8/ 14In recent years, there have been a series of reports of information leaks in which corporate technical and business information is illegally taken out, and strengthening information protection has become an issue.One of the main reasons for information leaks is by retired employees.In this article, we will explain the risks caused by information leaks by retired employees and measures to prevent them, and also introduce examples of information leaks that actually occurred and their investigations.

The largest number of cases of information leaks in companies are caused by "mid-career retirees"
According to a report by the Information-Technology Promotion Agency (IPA), an independent administrative agency, that investigated the occurrence of trade secret leaks at domestic companies in 2020, the most common cause of information leaks was "mid-career workers" 36.3%, an increase from 2016% in 28.6.All companies need to think about countermeasures and coping methods in preparation for information leaks by mid-career workers on a daily basis.
Reference: About the Report on the “Fact-Finding Survey on Trade Secret Management in Companies 2020”
https://www.ipa.go.jp/archive/security/reports/2020/ts-kanri.html
Risks posed to companies by information leaks by retired employees
Information leaks by retirees can cause a lot of damage.We will explain specific impacts and risks.
Risk of claims for damages from individuals or other companies
Even if information is leaked by a retired employee, there is a risk that the company that leaked the information may be sued for damages by the individual or company.If a retiree takes out and misuses the personal information of customers or employees, the individual victim may suffer nuisance or damage, and may file a claim for compensation against the company.
If the leaked information is important corporate information of a business partner, depending on the content, it may result in a claim for a large amount of damages.
Risk of loss of competitiveness due to leakage of know-how and trade secrets
The loss would be immeasurable if important trade secrets of the company, not of customers or business partners, were leaked.Leakage of proprietary know-how may lead to a decline in competitiveness.
Risk of slander and reputational damage
Even if there is no financial loss, the damage will still be done.The credibility of the company falls to the ground when the information management ability as a company is questioned.There is also the risk of exposure to slander and reputational damage.
Risk of receiving corrective recommendations/orders or criminal penalties from the government
According to the Personal Information Protection Law, if personal information is leaked, in addition to compensation for damages, the government will receive on-site inspections and corrective recommendations and orders.Violations may result in imprisonment or fines, and businesses that handle personal information must be more careful.
Measures against Information Leakage by Retirees
To avoid the worst-case scenario, countermeasures against information leaks by retired employees should be given top priority. Effective countermeasures include reducing risks by restricting access to and taking out information, using security cameras and records of entry and exit as a deterrent, and raising employee awareness and disseminating information through in-house training and written pledges. is.
Restricting access to and taking out of confidential information
Limiting who has access to sensitive information can reduce the risk of information leakage.It makes it easier to identify the person who took the data out, so it is useful for dealing with information leaks.
Install security cameras and record entry and exit
Even in situations where data cannot be accessed or physically taken out, crimes such as taking pictures of PC screens and important documents are possible.It is also effective to strengthen access restrictions to security areas to keep people away from important information.If security cameras can be installed to monitor the entry and exit status of the office along with IC card information, it will not only help identify the perpetrators in the event of information leakage, but will also act as a deterrent.
Raise awareness through in-house training and non-disclosure agreements
We will define penalties for information leaks in internal regulations and make them widely known through in-house training.It is also effective to exchange confidentiality agreements with all employees.If you leak information, you will be liable for a large amount of damages.In addition, by making known that it will be a blow to the management of the company, it will also encourage other employees to report whistleblowing.
"Forensic investigation" is effective for investigating information leakage by retired employees
If an information leak still occurs, the company should conduct a “forensic investigation”.A forensic investigation is an investigation that collects and analyzes information related to an incident to reveal evidence of fraud.Information leaks are often leaked in the form of data, and in such cases, we search for evidence and history of fraudulent activities from information stored on digital devices.
Forensic investigations should be outsourced to an investigative company rather than conducted in-house.By utilizing the specialized software and AI of research companies, we can conduct surveys efficiently and at a cost suitable for scale.
[Related article] What is a forensic investigation?Commentary on necessary cases, points to note, and examples
Cases of Information Leakage and Forensic Investigations by Retired Employees at Companies
In order to explain what kind of investigations are to be carried out, we will introduce examples of information leaks and forensic investigations that have occurred in actual companies.
[Case handled by FRONTEO] Confidential information taken out by an employee
Two years after former employee A moved to a competitor company, it was discovered that similar products were being manufactured without permission and sold overseas. From the log of the PC used by A, a large amount of data was copied several days before his retirement date.However, the large amount of data made it difficult to conduct an internal investigation, and some courts held the view that ``it is necessary to identify the behavior of the person and the trade secret'' in order to identify the information being taken out.
Therefore, in order to ensure third partyity, we asked FRONTEO, an investigation company, to conduct a forensic investigation.As a result of building a unique database and investigating a large amount of log data on external HDDs and USBs, about 30 records of data were copied to USB memory, and after a few days the external HDD was deleted after unplugging the network cable. In addition, we confirmed the fact that we repeatedly wrote and deleted unrelated program files for about 120 hours.
FRONTEO, which has a proven track record in forensic investigations using AI, for information leakage investigations by retired employees
Since its founding in 2003, FRONTEO has been working to solve the problems of various companies as a pioneer of forensic investigations in Japan.We have an established reputation for our technology and know-how based on outstanding experience.
Utilizing our in-house developed AI engine KIBIT, we have achieved significant labor saving and cost reduction during document review. By combining our experience in dealing with projects and our in-house AI engine, we have achieved high accuracy and efficiency that other companies cannot. is realized.