A programmer automated their data-entry job. Now: tell their employer?
qz.com
qz.com
https://news.ycombinator.com/item?id=14656945 (660 points, 506 comments)
At another employer, I worked alongside a customer service rep who automated much of the time consuming work he had to do. He wasn't a programmer by trade, but having a hacker mindset, he learned to do so after tiring of the same old work. Despite the annoyance of the security team and other developers who felt threatened by his work, he was promoted to IT and they locked down the workstations so it wouldn't happen again.
Depending on what he did the security team may have rightfully had issues with the work. I've seen it time and time again. Someone automates something, the tool gets released to users and it's full of SQLi, XSS, and RCE vulnerabilities, sometimes opening up a once protected data-set or systems to company or Internet wide exposure. It's shadow IT/Dev work like this which tends to be responsible for the most security incidents.
Most security incidents? Sounds unsubstantiated.