On TechRepublic: Why VISTA HATERS will love Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Andy McCue
Posted on ZDNet News: Sep 22, 2004 7:17:00 PM

If serial killer Harold Shipman had served his sentence and been released would you trust him as a doctor to your ailing and aged mother?

A German security company has divided opinion in the IT industry this week by offering Sven Jaschan, who is being charged with the creation of the Sasser virus, a job.

Not surprisingly the antivirus companies immediately jumped into the debate, claiming it would be impossible to trust a computer criminal.

Beyond that initial reaction the story raises wider questions about whether hackers and virus writers can ever be trusted to have changed their ways, so we asked our CIO Jury if rehabilitated or reformed computer criminals could be trusted to work in a corporate IT department.

The question split the jury down the middle with six saying 'yes' and six saying 'no'.

Ted Woodhouse, IT director at Leeds Teaching Hospitals NHS Trust, said "definitely not", questioning whether past form would resurface at the first sign of disillusionment with the employer.

"If [serial-killer doctor] Harold Shipman had been younger, served his sentence in full and been released as 'rehabilitated and having served his debt to society,' who would trust him as a doctor to treat their ailing and aged mother? A leopard does not change his spots--Jaschan belongs in jail for international and corporate vandalism (not to say terrorism) on a massive scale."

David McKean, director of IT services at Cable & Wireless, said the presence of a hacker in the IT department would undermine the trust everyone has to have in their co-workers. "With a criminal hacker in the ranks you do not have that trust and the risk to the business is just too large."

Mark Foulsham, head of IT at eSure, raised the issue of the dangerous precedent hiring a hacker would set. "The issue isn't really one of trust, it's the message this approach sends out--successful hacking improves your employment prospects."

Margaret Smith, director of business information systems at Legal & General suggested most firm hire hackers without being aware of it but doubted whether they could be trusted in an IT department.

"The biggest difficulty would be knowing if someone being interviewed is a hacker or not. They obviously have the right mindset in terms of problem solving/problem creating. Their motives for being hackers would need to be evaluated through things such as psychometric tests," she said.

But, equally others would be prepared to give former computer criminals another chance--depending on the circumstances. Phil Pavitt, CIO at NTL, said people should "never be too proud to learn", while David Jemitus, head of IT at the Government Planning Portal, said it is worth the risk if the person has specialist skills that are in demand.

Bill Gibbons, CIO at Abbey, said reformed hackers could be hired as long as the appropriate controls are in place and corporate policy supports it.

"Clearly such individuals can add value given their in-depth technical capabilities but this must be balanced against the significant risks entailed, so each 'opportunity' needs to be assessed on relative merits of employment," he said.

Dr. Stuart Brough, director of IT services at the University of Strathclyde, said being selective and getting the right person can "pay dividends". He said: "In higher education we have used students, during the vacation breaks, very successfully and they may fall into a similar category. Students are excellent hackers and test our security on a daily, if not hourly, basis."

Today's CIO Jury was…

Stuart Aitken, CIO, Medical Research Council
Dr Stuart Brough, director of IT services, University of Strathclyde
Mark Foulsham, head of IT, eSure
Bill Gibbons, CIO Abbey Group
Neil Hammond, IT director, British Sugar
David Jemitus, head of IT, Government Planning Portal
Phil Jones, CTO, easyGroup
David McKean, director of IT services, Cable & Wireless
Rob Neil, head of ICT services, Ashford Borough Council
Margaret Smith, director of business information systems, Legal & General
Phil Pavitt, CIO NTL
Ted Woodhouse, IT director, Leeds Teaching Hospitals NHS Trust

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 31 Talkback(s)
er...
Don't get me wrong, I think it's a fine idea, if he doesn't screw around. I just found your comparison a tad asinine.... (Read the rest)
Posted by: xjunglistx Posted on: 05/03/05 You are currently: a Guest | | Terms of Use
You've already hired hackers  chrislovesdana | 09/22/04
Absolutely not!  d_jedi | 09/22/04
exactly...  Monkey_MCSE | 09/22/04
Should we have used German scientests who built the  Laff | 09/23/04
Completely different scenerio..  d_jedi | 09/23/04
Um the question seemed to me hiring someone who  Laff | 09/24/04
bad idea.  xjunglistx | 05/03/05
er...  xjunglistx | 05/03/05
Gee it would be like using software from a convicted monopolist  Richard Flude | 09/22/04
That's why I don't do business with IBM. (nt)  No_Ax_to_Grind | 09/22/04
Huh?  wresnick | 09/23/04
He said a monopoly,...  No_Ax_to_Grind | 09/23/04
Dumb thing to say but...  AmusedAtItAll | 09/23/04
Rewarding criminal behavior is just stupid!  No_Ax_to_Grind | 09/22/04
Stupid for who?  Roger Ramjet | 09/23/04
Everyone of us trying to make the world a decent , safe place.  No_Ax_to_Grind | 09/23/04
Then please explain....  AmusedAtItAll | 09/23/04
ah your point?  V Sanders | 09/22/04
Would you hire an embezzler as an accountant?  secureplay_z | 09/23/04
Hire an Embezzler?  Jkirk3279 | 09/23/04
Reason number 1 stands out to me.  No_Ax_to_Grind | 09/23/04
New way to establish credentials--create a killer virus  garydodge7 | 09/23/04
As long as he paid the price for his crime I see no reason for not hiring  voska | 09/23/04
The thing is  d_jedi | 09/23/04
Hacking isn't about the tech  voska | 09/23/04
But the thing is..  d_jedi | 09/24/04
What does this have to do with hackers?  wresnick | 09/23/04
Fiddlesticks  voska | 09/23/04
airlines hire OS  V Sanders | 09/23/04
Seem to forget the other half of the equation  AmusedAtItAll | 09/23/04
Not really relevant here  charlieot | 09/27/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here