Brown Crayon in the Workplace

“Telling my story of what I experienced in the workplace.”

Another HR mistake with my former employer! On Thursday, August 22, 2019, I received an email from the Human Resource Director about the 401k Plan 2018 Summary Annual Report with 3-PDF files. Being a person focused on detail, I first noticed the email sent to over 51 current and past employees. The email is showing each person’s Personal address. The email addresses can be up for negotiation with a 3rd party vendor.

HR is in charge of employees’ most sensitive data and should be Safeguarding personal information by using email encryption to prevent accidental sends. HR needs to be trained well on how to keep themselves protected from damaging the company’s name. A company in the private sector has some legal obligations to its employee’s about privacy rights. I know for a fact that Human Resources send out personal information to others without the employee's permission.

The content and use of email for HR professionals can affect their security. There should be protocols in place in case accidental declassification happens, this way a well-formed response can be carried out that makes the company look better.

Another problem practice in many HR departments is the pervasive use of spreadsheets to hold really sensitive data. An HR person will download lists of employees with all sorts of sensitive data such as salary, date of birth, address, etc., and put it all into a spreadsheet on their computer. Their purpose may be to model salary ranges or increases or to create demographic reports, but the reality is that these spreadsheets are prime targets and high-risk failure points. Much of the most sensitive data HR sends is via email. HR needs to worry a lot about email security, as they are one of the most targeted groups in organizations. Sometimes, your HR department isn’t as secure as you think.

