quick case study for the cybersec folks here. got this real story in my dpo class & wanted ur thoughts.
IT guy at a bank, last day of his notice period. a trainee saw him puttin some CD-ROMs in his bag & told security. they checked him at the exit and found a full export of the bank’s top clients on the discs. guy got fired for gross misconduct & a police complaint was filed.
any red flags or stuff that stands out to u technicaly or otherwise ? i have my own ideas on this cas but curious what u guys think first?
thx 😎


Some operational security questions: What’s this trainee doing? Why was it a trainee noticing things being put in backpacks? Why was the trainee the one notifying security?
Are there protocols in place for media being brought in or out of the facility and its workstations? Why or why not? Was the trainee the only one who reviewed them recently enough to notice a breach and alert?
But most importantly and at any rate you don’t do the grand heist on the last day. Rookie move.
Technically speaking, what kind of logs does burning a CD actually leave on a hardened Win/Linux workstation compared to a USB mount? If the DLP is only looking for ‘Mass Storage Devices’, does the burning process even trigger a file-copy event in the logs?
The process that’s being executed to run the burner would be a clue, based on my experiences (limited) and knowledge (also limited). For windows, if the outright windows burner was used then there’d be system logs for that. If another program were used, well, that begs more IT security questions about permissions.
I have whole months of experience using Linux, so, no idea there.
def a rookie move! ^^ thx for the reply, appreciate it! yeah this case raises so many questions & i’m just guessing here. clearly a ton of security issues.
“Why was it a trainee… notifying security?” totally agree. besides the CDs, my main trigger was the trainee reporting it directly to security, skipping any manager or coworker. why? and why did no one else notice anything? makes me wonder if it’s really a single-man job… accomplices in the team maybe?
“Are there protocols in place…?” i d assume protocols exist but were bypassed. plugging in an external burner would def raise eyebrows or trigger dlp/edr. so i bet the workstations had built-in drives. in my dpo class, everyone just laughed bc it’s “old tech” nobody uses anymore… maybe the cybersec team thought the same? blocked usbs & set protocols for ports but underestimated optical? i have gen z students in my opsec classes who don’t even know what a tower’s cd-player is if i show them a photo. or they know it’s a player but don’t realize it’s a burner too.
what’s ur take?