When private e-mails get into the wild.
In the beginning, an e-mail was sent from a woman working in a City law firm to one of her male pals.
She also copied it to a number of other people. Like a large proportion of jokes circulating by e-mail, it was crude. Actually, it was funny as well, but mostly it was crude. Indeed, in some cultures and legal systems the activity alluded to is illegal - no, it's not that one.
The woman and her pal had an exchange of e-mails, which set against the original joke were, as a private joke, funny. The sort of thing good friends say to each other in ribaldry.
The trouble is, seemingly, the chap thought it would be funny if he sent the complete exchange to some of his pals - and one of them thought it would be even funnier to release it into the legal community in London. From there, it has spread into banking, newspapers, broadcast media, accounting and consulting firms and, because of the international nature of the work being done by the businesses, and the fact that they have offices and contacts all over the world, it spread very fast.
Within four days, it had spread first to thousands of people and then to as many as ten million, according to some estimates. It took on a life of its own - and, for some reason, thwarted an important convention - that when you are forwarding material, you don't also forward the list of names of people that were on the distribution list when it came to you. Yet, right from the first message, all the names of people that have received the particular chain before you are listed in the body of the mail. And so, in a single e-mail, albeit one of which there are now many derivatives, has caused huge embarrassment to those who have received it.
The law firm where the original recipient works (or, perhaps by now we should say "worked") has taken the question of damage to its reputation so seriously that it has not only issued a press release disclaiming corporate responsibility and saying that it is instituting disciplinary proceedings, but - presumably in an effort to fend of people trying to find the people concerned on its website - has also posted the press release to its website linked from a high profile statement on the front page.
Anderson Consulting, which will change its name to Accenture on 1 January 2001 may be less than pleased that the first time the new name is widely seen in public is with perhaps two dozen of its staff circulating the mail, which by that point was no longer just the jokes and the exchange of correspondence, but a line of people all trying to find out who the woman was in the light of the "revelations" she had made about her "interests." Of course, it is quite possible that, in the nature of ribald humour, the comments, which are somewhat extreme, were exaggerations for effect.
One person forwarded it, seemingly, to his entire address book - including a number of people in employment agencies. It's possible he will soon be in touch with them again because organisations worried about their image are now bound to consider whether they should apply sanctions - and some may consider this to be so damaging to their reputation that they consider dismissal.
Because of the fact that all the names have been left in the mail, those who received it early in its life now have their names on the many different versions flashing around the world. In cultures where the acts described are offensive or illegal, there is a real risk of harm to the organisation. But there is evidence here of other risk - that of how far and how fast information can move around the internet. Leakage of confidential information can snowball and a trickle of e-mails leaving your company can be an avalanche within days or even hours. Confidentiality notices are pointless.
There are those that think that the firms that are taking the forwarding of the e-mail seriously are being a little heavy handed have not considered the consequences of having an ineffective e-mail policy. Ironically, the UK's Data Protection Registrar has said that she considers it to be an abuse of a person's personal privacy for an employer to snoop on an employee's e-mails. But had the firms into which (and out of which) this has passed over the course of a week had been in a position where they effectively monitored e-mails, this would not have happened. What this shows is how insecure e-mail systems are when an employee to ignore policy.
And that's a risk all businesses must address both for reasons of fraud, market abuse and money laundering risk management.




