Why Corporate Security Fails When Insiders Turn Rogue

Why Corporate Security Fails When Insiders Turn Rogue

Corporate security usually focuses on stopping external hackers. But the biggest threat is often sitting right inside the building, holding an administrative badge and a master key to the inventory room.

When a 40-year-old information technology manager at Deloitte Touche Tohmatsu in Hong Kong was recently sentenced to 22 months behind bars, it exposed a glaring vulnerability in how large firms track physical assets. Over a multi-year stretch, Ho Man-kit systematically carted off hundreds of company laptops.

Trust is great. Verification is better. Yet thousands of enterprises treat internal asset management as an afterthought until millions of dollars vanish.

How an IT Manager Stole 423 Laptops in Plain Sight

The numbers are staggering. Ho managed to walk out of the office with 423 company laptops, amassing an estimated value of HK$1.2 million. He did not use sophisticated hacking tools or bypass high-tech digital firewalls. He used cardboard boxes, an elevator, and the sheer audacity of an employee who was supposed to be in charge of the equipment.

Between September 2021 and early 2023, the operation ran with brazen simplicity. Ho would enter storage areas—sometimes even showing up on days he was officially on leave—pack multiple computers into boxes, and hand them directly to an external recycler for quick cash.

The scam only unraveled because a diligent systems engineer ran a routine inventory check on the morning of February 13, 2023. Finding 399 laptops missing triggered an immediate internal review. Security footage quickly exposed the pattern, leading to Ho's confession and surrender just days later.

The Real Driver Behind the Crime

Why risk a stable, high-paying career in IT management for stolen hardware? The court proceedings revealed a depressingly familiar motive: severe financial desperation fueled by high-risk behavior.

Ho funneled the cash from the recycled machines straight into speculative stock trading. Like most compulsive gamblers and desperate traders, he chased losses. Every laptop he sold was a frantic attempt to cover previous financial holes. Predictably, the market wiped him out completely.

When District Court Judge Minnie Wat Lai-man handed down the 22-month prison sentence, she emphasized the profound breach of trust. Ho was the department head. He was the person trusted to protect the assets, which made his abuse of authority an aggravating factor that justified serious prison time. He lost his job, his freedom, and his reputation, leaving him unable to pay back a single cent of the company's losses.

Fixing Corporate Blind Spots

Most organizations suffer from a false sense of security regarding physical hardware. They spend heavily on endpoint protection and cloud security while leaving their stockrooms vulnerable to anyone with a dolly and a compliant recycler.

If you want to prevent this kind of insider theft in your own organization, you have to audit your processes today.

  • Mandate dual-person controls for asset disposal: Never let a single employee control inventory intake, storage access, and asset write-offs.
  • Track serial numbers actively: If your asset management system relies on manual spreadsheets updated once a year, you are flying blind. Automated scanning and regular spot-checks deter theft before it scales.
  • Vary audit schedules: Predictable inventory checks allow bad actors to time their thefts around the calendar. Surprise audits are your best defense.
  • Monitor off-hours access: Modern keycard systems log every single entry. Real-time alerts for access during weekends, holidays, or approved leave periods stop insider crimes early.

Physical security is just as important as cybersecurity. When companies ignore the physical custody chain of their technology assets, they invite disaster.

MJ

Matthew Jones

Matthew Jones is an award-winning writer whose work has appeared in leading publications. Specializes in data-driven journalism and investigative reporting.