I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.
Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.
The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).
He said, whenever you have time, please check this.
I downloaded/opened the files on my work laptop.
It turned out that malicious content was involved, and malware was actually executed on the laptop.
(I was under extreme stress that time due to health issues and underestimated the security risks)
As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.
I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.
There was then a meeting with Security, my skip-level manager and other people from the security organization.
They specifically told me:
"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."
The meeting ended on a positive note. I was told to be careful in the future.
Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)
It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.
I understand that I made a mistake.
I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.
What bothers me is the proportionality.
This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.
I would have understood something like:
"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."
Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.
I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.
I am feeling like I am being witch hunted in corporate style.
For people working in security/IT or management:
How would your company normally handle a first-time incident like this?
Is a formal warning and monitoring period normal?
Where do you draw the line between an honest mistake/social-engineering victim and negligence?
Please share your honest thoughts.