Wednesday, February 4, 2009

The spy in your cafeteria

Ira Winkler
July 25, 2006 (Computerworld) --

Corporate espionage rarely gets its day in print, so it has been refreshing to see reportage on two major cases recently. The first, involving The Coca-Cola Co. and PepsiCo Inc., received most of the attention. The other, which involved manufacturer Metaldyne Corp., seemed to be a minor footnote, but is exponentially more important.

Despite its regularity, most people still believe that espionage doesn't happen to them or their companies. Corporate espionage is significantly more mundane than people think, and it tends to take on the least technological form possible. Most of these security breaches are not highly targeted espionage campaigns but crimes of opportunity.

Even when you are dealing with Russian intelligence services -- which are probably the most sophisticated in the world with the exception of those of the U.S. -- their most fruitful cases are when an insider walks into their offices looking to sell information. Even if they recruit an insider, they are dependent on the access that the insider generally has and, to some extent, on the insider's ability to understand what information is desired.

While China's intelligence-gathering operations may not be as sophisticated as those of Russia, they're definitely more aggressive and have undertaken a much larger effort. They tend to take advantage of companies trying to break into the Chinese market. U.S. companies are currently frantic to enter that potentially lucrative arena. China knows this and has a process for taking advantage of every opportunity that presents itself.

That process includes efforts to target or coerce Chinese citizens or other people with ties to China who are working in non-Chinese companies. When companies do business in China, they can expect that many of their workers are agents of the Chinese government and that their facilities are bugged. I've had client after client tell me about how their technologies were completely compromised within months of building facilities in China.

Now back to the two cases of espionage. The Coca-Cola case apparently involved an executive administrative assistant in the company's marketing department. One of her associates sent an anonymous letter to Pepsi offering to sell secrets of a soon-to-be-released product. This case involved everything from money hidden in boxes to secret meetings at airports. But it was all much more like something out of Get Smart than James Bond.

In fact, the more you learn about the case, the more you wonder if that's where the would-be perpetrators were getting their "training." The first thing they did was offer the information to Pepsi, which would seem to be an obvious buyer. But PepsiCo is a law-abiding company. A less obvious -- but more likely -- buyer would be a competitor in Europe or Asia. The covert meetings and boxes to exchange large amounts of money were similarly out of some sort of spy novel, not the material of real espionage. The Metaldyne case was much more serious, for a variety of reasons.

Few people outside the automotive industry have heard of Metaldyne, but its technologies, which turn powdered metal into automotive parts, are worth billions of dollars on the world market. The espionage perpetrators were former engineers and executives at Metaldyne. They gave the technologies to Chinese companies and wanted residuals of future profits. Clearly, they took pieces of information over time, and they began to work at acquiring information from other companies.

Both cases involved insiders selling information that they had access to, or to which they were able to position themselves to get access. Any of the acts of espionage in either case could have been performed by anyone else with minimal intelligence. Even the Metaldyne case, which apparently goes so far up the food chain as to include a former vice president of sales, could have been perpetrated by anybody with the access to retrieve documents as requested by the would-be spy agency. For that reason, it is important to understand that it is the little things that matter with regard to preventing espionage -- and security incidents in general.