Earlier quoted context omitted.
devoops
Continuos Disaster
JP Morgan fined by SEC for deleting email records
221–230 of 254 posts
Re: JP Morgan fined by SEC for deleting email records
#222Earlier quoted context omitted.
The SEC is not in the justice business. It is a puppet of the banks themselves. A $4M fine is NOTHING for a company netting $12.62B a QUARTER.
The $4M is a slap on the wrist, but if there's evidence that it was done on purpose, and the deleted data is evidence for a bigger case, they'd be in much bigger trouble still. But, innocent until proven guilty; if there's no indication of any missing evidence, it'll stay at the failure to retain data fine.
Nobody (who isn't a moron) is going to send an email about intentionally doing this, or talk about it with someone who wouldn't also be implicated if discovered. If you saw everything, kept careful notes, and decided to become a whistleblower, your career would be destroyed and your life might even be in danger.
Re: JP Morgan fined by SEC for deleting email records
#223Earlier quoted context omitted.
Who works in the SEC? Former bank/finance employees. Where will these employees go work if they decide to leave the SEC?
What sort of work experience do you think the applicants for the jobs at the SEC ought to have? If you need people people with experience in banking and finance, especially the legal and regulatory/compliance areas, where would you do your recruiting?
Re: JP Morgan fined by SEC for deleting email records
#224Earlier quoted context omitted.
Presumably they would have gone to some low-level tech and told him something to the effect of "We are looking for a new team lead, you might be a good fit. Completely unrelated: how difficult would it be for emails from the last couple years to be 'accidentally' deleted as part of routine operations". I'm not saying that's what happened, I find the sequence of events described by JP Morgan believable. But the same p…
> Presumably they would have gone to some low-level tech and told him something to the effect of "We are looking for a new team lead, you might be a good fit. Not a chance. NOTHING gets done at JPMorgan without a mountain-load of direction and a grip of meetings. This would have had to wipe out both the data and records of that direction. Because the layers of tape are so thick you can't travel floor to floor without…
How did the bureaucracy let this happen if it's as big and bureaucratic as you claim? And there's other examples too.
Re: JP Morgan fined by SEC for deleting email records
#225Earlier quoted context omitted.
> Just require good organization and you’ll get it by diktat? This is what I was responding to. You seemed to be insinuating that I didn't understand that laws or rules are not sufficient deterrents. > nobody was shown to have done anything wrong here beyond the benefit of doubt I'm still confused as to how the SEC was able to fine someone for not committing any wrongdoing, exact definition of the word "crime" which…
Deleting records that are legally required to be retained is not “no wrongdoing”.
Re: JP Morgan fined by SEC for deleting email records
#226Earlier quoted context omitted.
I think corporations of "too big to fail" stature should have different legal protections than what are offered to humans. Innocent until proven guilty is not quite fair to apply to corporations that get bailed out by taxpayers when the policemen are driving bicycles trying to enforce the speed limit on a highway full of McLarens. When a company has positioned itself to be a critical organ of society, it should be re…
The rules of nature do not forgive a well meaning hare that didn't intend to be eaten by a lion. I love this. Consider yourself quoted.
Re: JP Morgan fined by SEC for deleting email records
#227So the story is basically: 1. data that has to be retained for legal reasons can't be deleted by normal deletion processes 2. data that should be deleted didn't delete properly 3. to fix (2) they manually ran delete requests for times up to about the current date (back in 2018), relying on (1) to protect data 4. turns out somebody forgot to configure (1) for emails send to domains belonging to Chase (at that point th…
I’m curious if any IT folks can comment on what they have seen? Do you actually have log records of all messages? Or do you have something like a snapshot of all accounts at a given time?
Re: JP Morgan fined by SEC for deleting email records
#228Earlier quoted context omitted.
What sort of work experience do you think the applicants for the jobs at the SEC ought to have? If you need people people with experience in banking and finance, especially the legal and regulatory/compliance areas, where would you do your recruiting?
Do you think that only experienced murderers should adjudicate murder cases? Should all cops be expected to have extensive criminal experience, and should we expect them to return to crime after they retire from the police?
Re: JP Morgan fined by SEC for deleting email records
#229So the story is basically: 1. data that has to be retained for legal reasons can't be deleted by normal deletion processes 2. data that should be deleted didn't delete properly 3. to fix (2) they manually ran delete requests for times up to about the current date (back in 2018), relying on (1) to protect data 4. turns out somebody forgot to configure (1) for emails send to domains belonging to Chase (at that point th…
I’m not convinced companies actually keep these records so much as they retain access to inbox and outbox data And call that good enough. I think in many environments if you delete an email from your outbox it would become largely irrecoverable. I’m curious if any IT folks can comment on what they have seen? Do you actually have log records of all messages? Or do you have something like a snapshot of all accounts at…
Anyway, all these business rules are (should be) documented in formal policies on data retention, litigation hold, privacy, etc. If a company were going through a working annual audit process for Sox or increasingly even routine annual financial audits (non-sox), policies would be examined for evidence that they are working with spot checks - e.g. auditor selects examples of qualifying events and asks for evidence that the given policy is in fact enabled/enforced technically. This may test retention as well as intention deletion (e.g. we should deliberately have no data beyond five years unless an exceptional circumstance warrants it).
Re: JP Morgan fined by SEC for deleting email records
#230Earlier quoted context omitted.
If an individual does that, they get held in contempt. But with a corporation all they can do is fine, so it just becomes a cost of business :(
Getting held in contempt of court is usually punished with a fine for individuals as well, so how is that different?