Customer data security and theft: a Malaysian organization's experience

被引:10
作者
Abidin, Mohd Aizuddin Zainal [1 ]
Nawawi, Anuar [1 ]
Salin, Ahmad Saiful Azlin Puteh [2 ]
机构
[1] Univ Teknol MARA, Fac Accountancy, Shah Alam, Selangor, Malaysia
[2] Univ Teknol MARA, Fac Accountancy, Perak, Malaysia
关键词
Malaysia; Internal control; Customer information; ISLAMIC WORK ETHICS; IDENTITY THEFT; FRAUD; OWNERSHIP; EMPLOYEES; INTERNET; RISK;
D O I
10.1108/ICS-04-2018-0043
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This study aims to identify weaknesses in current internal control systems in protecting customer data and the drivers that motivate employees to steal customer data and the impact of customer data theft on the organization. Design/methodology/approach A case study approach was taken to investigate and analyze internal control system weaknesses. One organization that involved investor and treasury services was selected as a case study in this research. A mixed method of data collection, specifically survey questionnaires and observations, was used. Findings This study revealed that employees are aware of the policy to protect customer data in their organization. Ironically, customer data theft still occurred despite the company having an internal control system. The main concern was the attitude of the employees to adhere to the policies in place, which becomes the major cause of internal control violation. Employees tend to ignore policies and standard operating procedures, providing opportunities for data theft and fraud to occur, although they realize this will result in a severe impact on the reputation of a company. Research limitations/implications - The results provide further confirmation of the fraud triangle theory, i. e. opportunity on the possible causes of the data theft and fraud, supporting prior empirical research and surveys conducted by researchers and global professional firms on fraud. This study, however, was conducted on only one organization with limited participation from employees because of the sensitivity of the nature of the topic. Practical implications - This study provided recommendations that can be a reference for companies and regulatory bodies in preventing customer data theft cases, such as regular training and awareness campaigns to the staff, stringent recruitment policies, close monitoring on the accessibility of customer data and continuous use of advanced technology to prevent a data breach. Originality/value - This study is original, as it focuses on an organization that operates in the financial services industry, which is one of the most attacked sectors for data theft and cybercrime activity globally. Furthermore, this kind of research is rare in fraud literature, particularly in developing markets such as Malaysia. The findings of this study are inferred from the direct observation of the organizational and employee work environments, activities and behaviors, which are private and confidential and difficult to access by researchers for publication in academic journals.
引用
收藏
页码:81 / 100
页数:20
相关论文
共 83 条
  • [1] Ahmad NMNN, 2016, INT J BUS SOC, V17, P347
  • [2] Exploring the crime of identity theft: Prevalence, clearance rates, and victim/offender characteristics
    Allison, SFH
    Schuck, AM
    Lersch, KM
    [J]. JOURNAL OF CRIMINAL JUSTICE, 2005, 33 (01) : 19 - 29
  • [3] Amirudin N R., 2017, Management Accounting Review, V16, P55
  • [4] [Anonymous], COMP CRIM SEC SURV
  • [5] [Anonymous], J ADM SCI
  • [6] [Anonymous], 2018, REP NAT OCC FRAUD AB
  • [7] [Anonymous], 2016, GLOB STAT INF SEC SU
  • [8] [Anonymous], GLOB CRIME
  • [9] [Anonymous], 2011, MANAGEMENT ACCOUNTIN
  • [10] [Anonymous], 2003, FED TRAD COMM ID THE