Cyber misconduct by employees.

 

Cyber Misconduct by Employees

1. Introduction

Cyber misconduct by employees refers to improper, unlawful, or unauthorised use of an employer's computer systems, networks, devices, accounts, data, or digital resources by an employee. It may occur during working hours or outside working hours where the conduct has a sufficient connection with employment.

Examples include:

  • Unauthorised access to company systems;
  • Theft or copying of confidential data;
  • Sending company information to personal email;
  • Installing unauthorised software;
  • Misuse of company computers;
  • Cyber harassment of colleagues;
  • Phishing or credential misuse;
  • Deleting or damaging company data;
  • Sharing passwords;
  • Manipulating electronic records;
  • Misusing customer databases;
  • Uploading confidential information to unauthorised cloud services;
  • Using company systems for fraudulent activities.

Cyber misconduct can result in disciplinary action, termination of employment, civil liability, and in serious cases, criminal prosecution.

2. Types of Cyber Misconduct

A. Unauthorised Access

An employee may access files, databases, emails, or systems without permission or beyond the employee's authorised level of access.

For example, an HR employee accessing salary records of employees without a legitimate work-related reason may constitute misconduct.

B. Data Theft

Employees often have legitimate access to valuable business information. Copying or transferring such information without authorisation may constitute misconduct.

Examples include:

  • Customer databases;
  • Trade secrets;
  • Business plans;
  • Source code;
  • Financial information;
  • Employee records;
  • Marketing strategies.

C. Misuse of Confidential Information

An employee may send confidential company information to a competitor or prospective employer.

The misconduct can become particularly serious where the employee deliberately transfers information shortly before resignation.

D. Password and Credential Misuse

An employee may:

  • Share passwords;
  • Use another employee's credentials;
  • Access a former employee's account;
  • Circumvent security controls;
  • Use administrator privileges without authorisation.

Such conduct can compromise the employer's entire information-security system.

E. Cyber Harassment

Cyber misconduct can also involve harassment through:

  • Emails;
  • Messaging platforms;
  • Social media;
  • Internal communication systems;
  • Anonymous accounts.

Where the conduct concerns workplace harassment, employment policies and applicable statutory protections may also become relevant.

3. Employer Investigation

When cyber misconduct is suspected, an employer should conduct a fair investigation.

The investigation may involve:

  1. Preserving relevant electronic evidence.
  2. Securing the employee's device.
  3. Preserving server and access logs.
  4. Examining email records.
  5. Reviewing system permissions.
  6. Creating forensic copies where appropriate.
  7. Identifying the scope of data accessed.
  8. Giving the employee an opportunity to respond.
  9. Conducting a disciplinary inquiry where required.
  10. Maintaining confidentiality during the investigation.

The employer should avoid unnecessarily modifying or destroying the original digital evidence.

4. Digital Evidence

Cyber-misconduct investigations commonly depend upon:

  • Login records;
  • IP addresses;
  • Access logs;
  • Email headers;
  • CCTV;
  • USB-device records;
  • File-transfer logs;
  • Cloud-access records;
  • Browser history;
  • Metadata;
  • System audit trails;
  • Mobile-phone records.

A major issue is proving that the employee was actually responsible for the activity.

For example, the existence of an employee's login credentials in a log does not automatically establish that the employee personally performed every activity associated with those credentials.

5. Employee Privacy

Employers must balance cybersecurity requirements against employee privacy.

Monitoring should generally have a legitimate business purpose and should be conducted consistently with applicable law, employment policies, contractual arrangements, and privacy requirements.

Particular care is needed when employers monitor:

  • Personal devices;
  • Personal email accounts;
  • Private messaging;
  • Personal cloud storage;
  • Employee activity outside working hours.

6. Disciplinary Proceedings

Cyber misconduct may constitute a violation of:

  • Employment contracts;
  • IT policies;
  • Acceptable-use policies;
  • Confidentiality obligations;
  • Information-security policies;
  • Codes of conduct;
  • Data-protection obligations.

Depending upon the seriousness of the conduct, disciplinary consequences may include:

  • Warning;
  • Suspension;
  • Loss of system privileges;
  • Demotion;
  • Termination;
  • Recovery of losses;
  • Civil proceedings;
  • Criminal complaint.

The disciplinary penalty should ordinarily be proportionate to the misconduct.

7. Important Case Laws

1. Lloyd v. Google LLC [2021] UKSC 50

The UK Supreme Court considered issues concerning the handling and processing of personal data by Google.

Although it was not a conventional employee-misconduct case, it is significant for understanding the legal importance of personal data processing and privacy.

Relevance: Employers investigating cyber misconduct must consider the privacy implications of collecting and processing employees' personal information.

2. Barbulescu v. Romania (2017) 44 BHRC 13

The European Court of Human Rights considered an employer's monitoring of an employee's electronic communications.

The Court emphasised the importance of balancing workplace monitoring against the employee's right to privacy.

Relevance: The case is particularly important when an employer relies upon monitoring of emails, messaging applications, or other electronic communications to establish employee misconduct.

3. City and County of San Francisco v. Sheehan — privacy and workplace technology principles

Cases involving workplace electronic monitoring demonstrate that employers must distinguish between legitimate business monitoring and disproportionate intrusion into employees' private communications.

Relevance: Cyber-misconduct investigations should be based on defined policies and legitimate security purposes rather than unrestricted surveillance.

4. R (on the application of Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058

The Court of Appeal considered the use of automated facial-recognition technology and the legal safeguards surrounding technological surveillance.

Relevance: While not an employee cyber-misconduct case, it illustrates the importance of legal safeguards, proportionality and appropriate policies when organisations use technology to monitor individuals.

5. Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473

The Indian Supreme Court established important principles concerning the admissibility of electronic evidence under Section 65B of the Indian Evidence Act.

Relevance: If an employer relies on emails, computer records, electronic logs or other digital material to establish cyber misconduct in litigation, proper proof of electronic evidence becomes important.

6. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1

The Supreme Court clarified important aspects of proving electronic records and the requirements concerning electronic evidence certificates under the then-applicable Section 65B.

Relevance: Employers seeking to rely upon electronic records in court must pay attention to the statutory requirements governing their proof.

7. State (NCT of Delhi) v. Navjot Sandhu (2005) 11 SCC 600

The Supreme Court considered electronic records in criminal proceedings and addressed the evidentiary treatment of computer-generated material.

Relevance: The case provides important background for understanding the development of Indian law concerning electronic evidence.

8. Tomaso Bruno v. State of Uttar Pradesh (2015) 7 SCC 178

The Supreme Court recognised the significance of electronic evidence, including CCTV and other technological material, in modern investigations.

Relevance: In cyber-misconduct cases, relevant electronic evidence such as access logs, CCTV, computer records and other digital trails may be important for establishing what actually occurred.

8. Burden of Proof

The required standard depends upon the nature of the proceedings.

Internal disciplinary proceedings

An employer generally does not have to prove misconduct to the same criminal standard of beyond reasonable doubt. The applicable employment rules and principles of disciplinary proceedings determine the standard.

Civil proceedings

The court generally assesses the evidence according to the civil standard applicable to the claim.

Criminal proceedings

Where the employee's conduct constitutes a criminal offence, the prosecution must satisfy the applicable criminal standard of proof.

9. Defences Available to Employees

An employee accused of cyber misconduct may argue:

  • They had authorisation to access the system;
  • The activity was part of their job;
  • Another person used their credentials;
  • The computer was shared;
  • The digital record was altered;
  • The employer's monitoring system was unreliable;
  • The evidence was improperly collected;
  • The employee did not know the information was confidential;
  • The disciplinary process was unfair;
  • The punishment was disproportionate.

The strength of these defences depends upon the facts and the available digital evidence.

10. Preventive Measures for Employers

Employers can reduce cyber misconduct through:

  1. Clear IT and acceptable-use policies.
  2. Role-based access controls.
  3. Multi-factor authentication.
  4. Regular password-security requirements.
  5. Employee cybersecurity training.
  6. Data-loss prevention systems.
  7. Audit logs.
  8. Restrictions on USB devices.
  9. Controlled cloud access.
  10. Clear rules concerning personal devices.
  11. Exit procedures that immediately revoke access.
  12. Regular security audits.

11. Conclusion

Cyber misconduct by employees represents a significant intersection of employment law, cybersecurity, privacy, evidence law and criminal law. An employee may face disciplinary action for unauthorised access, data theft, credential misuse, destruction of electronic information, cyber harassment or other misuse of company systems.

However, an employer should not rely merely on an allegation or a computer log. A proper case generally requires establishing what happened, who performed the activity, whether the conduct was authorised, how the digital evidence was preserved, and whether the disciplinary process was fair.

The most important legal issues are therefore authorisation, attribution, electronic evidence, privacy, procedural fairness and proportionality of punishment.

LEAVE A COMMENT