1 / 4100%
Intellectual property theft is whereby unscrupulous individuals steal the
intellectual property of another individual or company for financial gain or
malice. Intellectual property is any creative work or innovation with economic
value (UpCounsel, 2020). For example, a song written by an individual is
intellectual property since the music can generate millions of dollars when
recorded into CDs or distributed online. Also, when an individual or company
develops an invention or innovation that performs a particular function, the
technical details of the operation of that invention are intellectual property.
Additionally, trade secrets and customer information that a business employs to
conduct its operations are also intellectual property (UpCounsel, 2020; Cooper,
2017). Companies and individuals store intellectual property in digital devices
such as computers and tablets. Malicious individuals can find vulnerabilities in
these devices and use malware to infiltrate them and steal intellectual property.
Businesses and individuals must ensure the usage of advanced measures to
protect their confidential intellectual property from falling into the wrong hands
to mitigate company image loss, revenue decline, and business failure.
Customary processes and procedures that make it
difficult for employees, managers, and executives to
inadvertently misuse and/or steal the company’s
intellectual property
Classification and Marking
This concept involves locating intellectual property, identifying the type, and
classifying it according to its value. Categorizing intellectual property
according to its value is known as marking (Frank et al., 2019). These markings
protect the trade secrets of companies. Once intellectual property marking is
done, a company can set access control using intervention such as least
privileged to regulate which users can access the intellectual property. Also,
individuals and companies can trademark designs, symbols, and phrases to
prevent use by third parties.
Separation of Duties
This concept states that no user SHOULD have all the privileges to conduct a
critical business function. Separation of duties recommends using different
employees to perform a task to minimize fraud and abuse (Trzeciak, 2010). For
example, modification of systems log should involve atleast two system
administrators to foster oversight into system alteration, thus impeding
potential confidential data leakage.
Least Privilege
It entails system administrators limiting users from accessing specific resources
in a network. It is also referred to as the principle of least privilege (POLP) and
helps control worker access to processes, applications, systems, and devices
(Miller, 2021). By applying least privilege, the system administrator ensures
the safety and confidentiality of intellectual property by giving permission only
to authorized personnel. Hackers require accounts with full administrator
privileges to infiltrate computer networks. However, by employing least
privilege for most users in a network, hackers will have difficulty finding
accounts with full administrator privileges.
Implement strict password and account management protocols
It entails enacting stringent regulations on accounts and password handling
(Trzeciak, 2010). An example is requiring employees to change their passwords
regularly. Also, instructing system administrators to delete all the passwords
and accounts of sacked or employees who have quit prevents ex-employees
from using those credentials remotely to steal company files.
Best practices that companies should implement to
mitigate intellectual property theft
Regular updates and patching - Best practices in impeding intellectual
property theft include ensuring that all software and hardware are up to date
and devoid of vulnerabilities(Cooper, 2017). Patches contain critical fixes that
seal security vulnerabilities that hackers can use to infiltrate computers
networks.
Installing the latest anti-malware software - Having the latest anti-malware
software, such as Malwarebytes, ensures that computers have protection from
exploit kits and other cyber threats (New Jersey Cybersecurity &
Communications Integration Cell, 2015).
Testing and reviewing attack scenarios - System administrators can simulate
attack scenarios and use the information collected to mitigate future
cyberattacks (Cooper, 2017). For example, the administrator can orchestrate a
ransomware attack on one computer and see how the company’s security
measures hold up to the attacks.
Institute periodic security awareness training - Cyber threats are constantly
changing; hence it is critical to ensure that employees know how to protect
themselves by offering regular training (Trzeciak, 2010). Failure to provide
such lessons can lead to the catastrophic leakage of confidential information.
Constantly monitor and respond to suspicious network activity - d System
administrators should always be vigilant of abnormal activity in the network
and act fast to mitigate security breaches (Trzeciak, 2010). Often, hackers lurk
in the network looking for vulnerabilities; hence constant monitoring can
prevent hackers early before initiating an attack.
References
Cooper, C. (2017). Cyberespionage: Your intellectual property under threat.
CSO Online. Retrieved 26 April 2022, from
https://www.csoonline.com/article/3200608/cyberespionage-your-intellectual-
property-under-threat.html.
Frank, D., Harris, H., & Cruz, V. (2019). Intellectual property markings
[Ebook]. https://www.dau.edu/library/defense-atl/DATLFiles/May-
June2019/Harris_Cruz_Frank.pdf.
Miller, M. (2021). What is least privilege & why do you need it?.
Beyondtrust.com. Retrieved 26 April 2022, from
https://www.beyondtrust.com/blog/entry/what-is-least-privilege.
New Jersey Cybersecurity & Communications Integration Cell. (2015). Exploit
Kits: A prevailing vector for malware distribution.
https://www.cyber.nj.gov/threat-analysis-reports/exploit-kits-a-prevailing-
vector-for-malware-distribution.
Trzeciak, R. (2010). Understanding the insider threat: Lessons learned from
actual insider attacks [Ebook]. Cambridge Mellon University - Software
Engineering Institute. Retrieved 26 April 2022, from
https://www.first.org/resources/papers/conference2010/trzeciak-slides.pdf.
UpCounsel. (2020). Intellectual theft: Everything you need to know.
https://www.upcounsel.com/intellectual-theft.
Students also viewed