Exploring the ethics of network and security monitoring. Delve into the moral complexities of digital surveillance. The increase in working from home and the merging of professional and personal lives has created new methods for monitoring employees, including some that are ethically problematic. Even the strongest opponents of workplace monitoring admit that it must be done with moral standards in mind.
A company’s approach to network and security monitoring shouldn’t replace general compliance or business ethics policies, but it should be its logical extension in the digital realm.
Ethics of Privacy
In the enterprise, unauthorized monitoring can occur through stolen credentials, misconfigured apps, rogue devices, and other hacking incidents, but it can also happen innocently such as an employee connecting their personal laptop to the ethernet network, a marketing department installing a WI-fi-connected TV in a conference room or an industrial pump motor vendor putting its latest product on a 5G cellular network for remote monitoring. Regardless of the cause, these devices are unauthorized and should not be allowed to remain on the network.
Many organizations have begun to adopt the term ethical technology in order to encompass both cybersecurity and monitoring initiatives that are based on company values and principles, rather than specific technologies. These initiatives should not replace general corporate or business ethics policies, but they can help to ensure that technology-based ethical concerns are kept front and center. Companies that take this approach can develop a holistic view of their own ethics programs that can support a strong foundation of trust with employees, partners and other stakeholders. These programs are often housed under a single organizational umbrella or managed separately, depending on the company’s approach.
Ethics of Security
All security systems depend on other systems to work correctly. A missed software update, an unprotected endpoint, a misconfigured monitoring system, or a bad user can render even the best technology useless. It is important that the security measures employed are well thought out and implemented, and that they are continually updated in response to new risks. It is also important that they do not infringe upon employees’ rights and privacy. For example, an attorney may refuse to consent to a firm’s requirement that it read his or her email for legal advice. In that case, the safeguards should not be so intrusive that they jeopardize the lawyer’s ability to represent clients in a professional manner.
While it is possible that some of these issues could be mooted by a contractual agreement between employer and employee, that would not solve the problem of privacy invasion itself. The underlying issue is that, regardless of whether it is morally right or wrong, an employer does not give workers a contractual promise of privacy and can monitor employees’ activity, including reading their e-mails and watching their web browsing. The issue of how far an employer can go in violating a worker’s moral rights to privacy, however, becomes a matter of what purpose the information sought serves and how important that knowledge is. Ideally, a company’s approach to ethical technology should complement and extend its overall approach to corporate and business ethics.
Ethics of Transparency
With a company’s reputation and trust on the line, every aspect of an organization’s technology should be a reflection of its values. This is especially important with disruptive technologies that can have a significant impact on the business. The ethical approach to these technologies is an enterprise-wide undertaking that should be driven by its leaders, embedded in the culture and realized throughout all its business processes.
As more employees work remotely, bringing their professional and personal lives closer together, organizational requirements for managing workers online have ramped up, generating new methods for monitoring and shaping employee behavior. These range from covert keystroke logging, communications monitoring and harnessing device cameras and microphones to nudging employees with automated messages (e.g. “you are going over your sales target,” or “you need to step up your activity”).
These methods can raise privacy and surveillance concerns, while also threatening employees’ rights to freedom and autonomy. The academic literature has already identified ways for organizations to avoid these pitfalls, such as informing employees about the monitoring system and setting fair performance benchmarks. But these efforts are often hampered by an incomplete or low-quality understanding of what these tools and programs can do. This may contribute to the growing backlash against PA tools, such as a recent academic experiment that found they reduced potential employees’ impressions of an employer’s ethics and job acceptance rates, despite justifications for the monitoring (Holt et al, 2017*).
Ethics of Accountability
In the academic and grey literatures, issues of privacy and surveillance are a leading concern. For example, experiments reveal that when employees are informed of PA monitoring, they may perceive it as stressful and detract from job satisfaction. Furthermore, employees may be less willing to trust the company that uses such technology (Holt et al., 2017*). As a result, leaders must consider whether their use of PA is consistent with an organization’s values. If not, it could jeopardize its trust with stakeholders — customers, investors, employees and regulators.
Embedding ethical technology is an important undertaking that can help build trust with all stakeholders.


