Can your company’s offboarding missteps destroy its legal defense for protecting core trade secrets?
In the high-stakes legal clash between Apple and OpenAI, OpenAI is executing a clever defensive strategy: turning Apple’s internal security practices against itself. Court documents reveal that an Apple manager accessed a former engineer’s iCloud account after his departure. OpenAI argues this breach of operational boundaries proves Apple failed to maintain reasonable security measures—thereby undermining its claim that the disputed information legally qualifies as a trade secret.
From an IT governance and cybersecurity standpoint, this case underscores a vital norm: under legal frameworks like the Defend Trade Secrets Act (DTSA), intellectual property status requires “reasonable efforts” to maintain secrecy. When corporate access controls overlap recklessly with personal accounts, or when Zero Trust principles fail during employee offboarding, the enterprise’s legal shield collapses. If an organization cannot enforce strict Identity and Access Management (IAM) boundaries during offboarding, can it truly claim its data was safeguarded? How bulletproof are your organization’s offboarding protocols when scrutinized under a legal microscope?
—
離職流程的一個資安漏洞,竟可能摧毀企業辛苦建立的商業機密法律防線?
在 Apple 與 OpenAI 的商業機密訴訟中,OpenAI 採取了經典且犀利的辯護策略:直接質疑 Apple 的內部資安管理。最新法庭文件指出,一名 Apple 主管在工程師離職後存取了其個人 iCloud 帳戶。OpenAI 據此主張,Apple 在離職流程中的過當行為與管控制度瑕疵,證明其未對相關資訊盡到「合理的保密努力」,導致其商業機密的主張在法律上難以成立。
從 IT 資安治理與法律規範的角度來看,這帶出了一個關鍵原則:依據《保護商業機密法》(DTSA)等規範,機密要受法律保護,前提是企業必須採取「合理保密措施」。當企業的身分與存取管理(IAM)以及離職流程(Offboarding)缺乏嚴格界線、甚至背離零信任(Zero Trust)架構時,法院便可能認定該資訊未獲得適當防護。企業若連公私權限都無法精準劃分,又如何證明自己嚴格守護了核心資產?貴公司的離職資安防線,真的經得起法律與合規的嚴苛審視嗎?
#CyberSecurity #DataPrivacy #TradeSecrets #ITProTutor
Source: TechCrunch
