Case No 2401691/2017Venue ManchesterHearing 27 to 29 November 2017
Between
Mr MD AlstonClaimantNCC Services LtdRespondent
Before
Employment Judge HughesIn person for claimantMr J Boyd (instructed by Counsel) for respondentDate 29 November 2017
JUDGMENT
[1]The claimant was fairly dismissed. His unfair dismissal complaint is hereby dismissed.[2]The claimant’s claim to have been wrongfully dismissed in breach of contract is not well founded and is hereby dismissed. Signed by _______________________ on 29 November 2017 Employment Judge Hughes Judgment sent to Parties on 1 December 2017 Note: Reasons for the judgment having been given orally at the hearing, written reasons will not be provided unless a request was made by either party at the hearing or a written request is presented by either party within 14 days of the sending of this written record of the decision. Case No. 2401691/2017 1 EMPLOYMENT TRIBUNALS Claimant: Mr M D Alston Respondent: NCC Services Ltd HELD AT: Manchester ON: 27-29 November 2017 BEFORE:
REASONS
[1]This is a claim for unfair dismissal and wrongful dismissal. There is an agreed List of Issues which, in additional to liability issues on unfair dismissal and wrongful dismissal, raise a Polkey issue and the issue of contribution which are usually dealt with at the liability stage.[2]There was a bundle, of documents - R1 (any page references in these reasons are to pages in the bundle). There was also a bundle of witness statements. The claimant had produced a witness statement in support of his case and the respondent called four witnesses:(1) Mr Chris Middleton, IT Security Operations Officer responsible for digital security of the NCC Group’s IT system;(2) Mrs Gayle Durham, Verification Delivery Manager and was the claimant's manager at the time of the events in question; Case No. 2401691/2017 2(3) Mr Jonathan Mills, head of UK Sales and who was the decision maker at the disciplinary hearing at which the claimant was dismissed; and(4) Mrs Margot Haywood, Global Sales Director who dealt with the appeal. The respondent’s representative produced written submissions - R2.[3]The case was heard over three days. The evidence was completed by lunchtime on the third day. I then heard oral submissions and handed down judgment and reasons in the afternoon. The respondent then requested written reasons notwithstanding being the winning party and Counsel being present when the reasons were given. This is not a helpful use of scarce judicial resource. Primary Findings of Fact[4]From the evidence I saw and heard I made the following primary findings of fact relevant to the issues that I had to determine:4.1 The claimant commenced employment with the respondent on 14 April 2004 as a Verification Consultant. It is common ground that he was very good at his job, very experienced and met his targets. He was a long serving employee at the point when he was dismissed.4.2 The nature of the respondent’s business was not in dispute and I shall summarise it by reference to the respondent’s witness statements. Mr Mills gave evidence about sales relating to NCC Group’s Escrow Services which the Verification Consultancy Team is part of. He explained that the respondent provides those services as a risk mitigation plan for any company using software and/or having critical IT assets requiring placement with a third party. He said the solutions devised by the Verification Team (which can be bespoke) “provide peace of mind that material deposited with NCC can be used in the event of supplier failure”. In his witness statement, Mr Middleton explained that NCC sells advice and consultation on cyber security. This means that the respondent’s own digital security is especially important. In her evidence, Mrs Durham explained that any contravention of any digital security policy would potentially have serious impact on the Escrow business, including huge reputational risk and being in breach of contract with customers, because such breaches of security could also damage the customer’s business.4.3 Clearly, given the nature of the respondent’s business, security of client data is paramount. Consequently the importance of employees adhering to the respondent’s digital security policies is particularly important because of the potential consequences of security breaches.4.4 Unsurprisingly, the respondent has a number of policies and procedures that make reference to IT security and security of data. These were summarised in Mrs Durham’s witness statement (paragraph 18 onwards) and the claimant was taken to most of those provisions in cross-examination. He confirmed he was familiar with them. It is therefore unnecessary for me to go through them in detail Case No. 2401691/2017 3 but I shall provide examples. The claimant’s contract of employment [58 onwards] contained a confidentiality clause regarding information. There was a new starter checklist pertaining to the claimant [82] and he signed to confirm he had understood the computer network internet access policy. The Verification Consultant job description [98] made it clear that it was necessary to adhere to security best practice and to safely manage storage of verified source code. The respondent’s disciplinary policy [170] gave some examples of gross misconduct, including: breach of confidentiality; misuse of company property; fundamental breach of trust and confidence; serious breach of the email and internet security policy; introduction of unauthorised third party software into the network; and serious security breaches. The IT and Communications Acceptable Use Policy [175 onwards] made it clear that unless authority was obtained from an Operational Director or Group IT an employee should not use their intranet access to download software or other material, “unless it can be demonstrated it is required for the performance of your duties”. The same document stated that any permanent download of software must be authorised by Group IT. It also stated that the respondent did not allow access to social networking sites from its computers at any time, and had added websites of this type to the list of restricted websites.4.5 Mrs Durham’s evidence was that there was annual security training called Sans Training. The claimant disputed that the training was annual but accepted that he had completed a digital Sans Training module in September 2016 [353]. During the disciplinary process (at the appeal stage) Mrs Haywood obtained information from HR that this included a video called “Data Security 2015” which stated “never store or share sensitive information on public internet or cloud services such as Dropbox… unless you have prior authorisation from management”. The same video said “never install or use unlicensed or unauthorised software”.4.6 The evidence from Mrs Durham, which did not appear to be disputed by the claimant, was that when she joined the Verification Team in 2010 it appeared that the previous manager had not managed in a structured way and consequently she made it a priority to manage the team and improve the quality of service delivery. The claimant agreed that the previous manager had been much more “hands off” than Mrs Durham who might be described as someone who micromanages.4.7 From 2011 onwards the claimant worked from home or at client sites most of the time. He went in to the office in Manchester once a week for about half a day in order to back work up onto the respondent’s internal systems. The claimant’s evidence was that when he worked from home he would regularly connect to an internal network used by the respondent refereed to as “VPN” to upload or download client reports using his own broadband. The claimant did not have administrator status on the IT systems until 2014 (see below). Case No. 2401691/2017 44.8 One of the issues in this case concerned the use of Dropbox which is a file storage and sharing system based in the cloud. There was an email entitled “source code depositing” which was sent by Mrs Durham to the Verification Consultants in her team and copied to a number of other people [96] which stated that there had been an instance where, on completion of a verification, the owner (i.e. the customer) had provided the verified deposit using a box.com repository such as Dropbox live rather than the standard transfer method which would be using a system operated by the respondent called Escrow Live. She said: “This is not an accepted method of depositing files with us as Dropbox was famously hacked a few months back. If the customer absolutely insists on it then you should notify the Verification Managers and, subject to approval by John Campbell, we may allow it under controlled circumstances”.4.9 There was a conflict of evidence as to whether Mrs Durham ever authorised her team to use Dropbox. In her witness statement (paragraph 38) Mrs Durham stated that at no point had she encouraged the use of Dropbox. There were some messages in the bundle sent by a former member of the Verification Team, Mr Adrian Brooks, to the claimant’s phone, in response to a request by the claimant for evidence which would help him at his disciplinary hearing in 2016 (see below). Mr Brooks had not worked for the respondent since 2013. The message exchange was reproduced in full at pages 184-186 of the bundle and a abridged version of it was in handed in by the claimant at the disciplinary hearing [216 and 217]. The message from the claimant to Mr Brooks said he was “in real trouble at work, would appreciate your help, facing gross misconduct, one of the charges is using Dropbox. Would be really grateful if you could remember advocating it at a team meeting and remembering that Gayle agreeing it would be ok”.4.10 As was pointed out by the respondent’s representative this was a “leading message” because it told Mr Brooks what the claimant would like him to say. Mr Brooks replied saying that Mrs Durham had said to use it and that he had argued against it. Further down the chain of messages, albeit not available at the disciplinary hearing, the claimant replied saying he thought that it was Mr Brooks who was arguing to use it and that Mrs Durham was not familiar with it.4.11 It might fairly be said that the messages did not greatly assist the claimant with what was said about Dropbox at the team meeting in question because Mr Brooks did not accept that he had advocated the use of Dropbox. Mrs Durham said in evidence that she recalled there had been a discussion around Dropbox in a team meeting and that she had said that it would be necessary to check with IT if it was acceptable for it to be used. That was consistent with the email referred to in paragraph 4.84.12 The final point to be made about Dropbox is that it emerged during the disciplinary process that the claimant was the only Verification Case No. 2401691/2017 5 Consultant to use it. Taking the above evidence into account, I concluded that the claimant had not been told it was acceptable to use Dropbox and that any use of it would only be permitted on a one-off basis and subject to authorisation and strict controls as per the email referred to at paragraph 4.8.4.13 The respondent has an antivirus system called Sophos. In 2014 it generated a considerable number of system alerts relating to the claimant's work laptop [page 105].4.14 IT security sent a report to Mrs Durham showing that three Verification Consultants had triggered alters over a three month period [106]. The consultant who had triggered the most alerts was the claimant. He had triggered 216 alerts and they were described as pertaining to “porn”, “torrents” and “Lego”. The other two Verification Consultants had triggered 66 and 39 alerts respectively. To put the 216 alerts into context, Mr Middleton’s evidence was that this was about total of 11% of total security alerts for 2,000 employees over that period. Mr Middleton also explained that a “torrent” can be used to download files which have been shared online and could have copyright implications (e.g. downloading of films).4.15 A decision was taken to deal with the problem informally at that point in time, but not going forward. The email sending the report to Mrs Durham (who was then Miss Preston) stated that none of the malware had infected the machines involved and it been dealt with by the toolset used by the respondent. It also stated that there was a suspicion that employees did not realise that IT was detecting this activity when the laptop was being used away from the corporate network, and: “at this point we would ask you just have an informal word with the individuals… in future the consequences could be more serious”.4.16 Mr Rob Cotton (who I assume to be someone senior in IT security) sent a global email to all employees in the Group on 30 June 2014 saying that “a number of laptops had been reporting malware as well as attempts by websites to infect devices where a laptop has been used away from the corporate website. The websites visited should never have been accessed using a corporate laptop and it has become apparent that users are clearly not exercising any caution or commonsense.” He said that the misuse had included downloading “adult content, gambling, peer to peer file sharing, torrents and Warez”. He said sites such as Warez “are notoriously dangerous and prohibited”. He explained that the misuse exposed the respondent and its infrastructure to unacceptable risk and must stop with immediate effect. He went on to say that staff ignoring the guidance and training that had been given and accessing such sites would in future face disciplinary action. In evidence, the claimant confirmed that he took that email seriously. Case No. 2401691/2017 64.17 Mrs Durham asked the claimant to hand in his work laptop so that IT could investigate, which he duly did. He was provided with a replacement laptop.4.18 Mrs Durham met the claimant to discuss the issue [minutes 109-110]. Mrs Durham told him said it was quite serious and could have impact on customer sites and the respondent’s network. She also clarified that they were discussing, amongst other things, accessing pornographic material. She said that this was a conversation she did not want to have with the claimant again. The meeting closed with the claimant being told any further instances could lead to formal action.4.19 During the disciplinary process which led to these proceedings, the claimant pointed to an incident involving somebody called James Hone that had occurred in 2014 [103]. Mr Hone had tried to, or had, downloaded torrent software. That matter was dealt with swiftly and informally, but that was entirely consistent, as the claimant fairly accepted when giving evidence, with the fact that the issue involving him had also been dealt with informally in 2014. The main point about the 2014 incident was that the fact that it had been dealt with informally did not mean this would be the case in future as was made clear in the meeting with Mrs Durham and by Mr Cotton’s email referring to future disciplinary action if there were further incidents exposing the respondent to unacceptable risk.4.20 It was the claimant's case that when he was given a replacement laptop in 2014 he was told verbally by IT that the laptop was compatible with Dropbox and that it was acceptable to use it. There was a dispute on this point, with Mr Middleton being very clear that the claimant would not have been told he could use it. I thought Mr Middleton’s evidence was probably correct given the email referred to in paragraph 4.8. It was not in dispute that the claimant was never provided with written authorisation to use Dropbox.4.21 The claimant and the other Verification Consultants were given administration rights to their laptops in July 2014. Mr Middleton’s evidence, which did not appear to be challenged on this point, was that this was very unusual and permitted only if strictly necessary for the performance of a particular job role. He explained that for the vast majority of employees the system was locked down, meaning that users would have no, or very limited, ability to change software and settings without involving Group IT. He explained the reason was that this was one of the measures used to limit the risk of malware infection. Mr Middleton said Group IT would only give administrator status if there was a business case. He explained that for Verification Consultants there was such a business case because they may need to download and install non-standard software essential to perform a particular verification job. He explained that the tools could vary considerably and that Group IT would install basic tools but thereafter it would be for the Verification Consultants to source appropriate software. There were, as he pointed out, caveats to this which were: the software must Case No. 2401691/2017 7 be essential to the project being worked on; and that the software should be downloaded from reputable source, for instance the manufacturer of a particular product, obtaining a license to use it if necessary. Mr Middleton said that downloading from a source that was not reputable could expose the laptop to unnecessary security risks for the respondent and clients because any malware could end up on the respondent’s network. I completely accepted those points. I also accepted that by providing the Verification Consultants with administrator status, the respondent trusted them to use that status responsibly and was not giving blanket approval to download anything from any source.4.22 Mr Middleton emailed Mrs Durham about the administrator status issue on 13 November 2014. He said that he accepted that her team needed local administrator rights to do vital parts of their job, but that they did not need to be logged in as a local administrator just to check email or browse the web. He proposed they would be given an additional account to be used as an administrator when it was necessary. He said “logging in as an administrator would make life easier because you can do anything but unfortunately makes the impact of any malware exposure many times worse”. The email was circulated by Mrs Durham to her team on 14 November 2014.4.23 An incident occurred in 2016. A system used to monitor the respondent’s network traffic known as SOC had been triggered by activity from the claimant's company laptop. The initial report suggested it could be a Trojan malware infection [159]. Mr Middleton responded immediately asking the claimant to disconnect his laptop from the corporate network until it was confirmed that the alert was a “false positive” or the infection had been cleaned up. Having made efforts to contact the claimant, who was at a doctor’s appointment, Mr Middleton arranged to disconnect the laptop from the respondent’s network.4.24 The respondent commissioned a forensic report on the laptop [144 onwards]. The forensic report was produced by Ms Lauren Baxter, who is employed by the respondent but did not know claimant. The report was finalised and released on 29 September 2016. The investigation was asked to focus on the following questions:4.24.1 Was there any bitcoin mining software installed and if so how did it get there?4.24.2 Were there any other unexpected files on the laptop?4.24.3 Was there any evidence of browsing activity which needed further assessment by HR e.g. anything not obviously related to work?4.24.4 Was any software installed that would not be expected on a corporate device? Case No. 2401691/2017 84.25 The key findings [paragraph 1.3.1 at page 148] were that a file with the title FFMPE windows 1 click dot.exe, was found on the laptop and that it was a malicious programme classed as a “bitcoin stealer”. The programme was found using a virus detector referred to as “Virus Total”. In paragraph 2.1.1 there was a further reference to something with a very similar title to the FFMPE windows file but with the suffix “updater 1A exe”. The claimant pointed to this as being an irregularity in the report. Mr Middleton disagreed. He said it was likely that the updated title may have appeared later when the programme was used or that it may have been downloaded as an update. The report also stated that the claimant had saved a number of internal documents and client documents to a Dropbox account. Finally, the report made reference to the claimant’s internet browsing history. I shall deal with the evidence on each in turn.4.26 Firstly, as to the malware, it was clear from the report that the claimant had downloaded video conversion software and the malware was attached to it. The report stated that the programme was submitted to Virus Total to identify the malware type, and that that file had been reported by nine out of 57 antivirus vendors as malicious and by two as a bitcoin stealer. It went on to say that because the malware came from a site called “Sourceforge” it was more likely to be a Trojanised installer. The report said there were no further logs of files associated with that malicious executable, and that further analysis would be needed to understand the full capabilities of the malware.4.27 The claimant’s case was that because the number of antivirus vendors out of 57 identifying this file as some sort of malware, and only two as a bitcoin stealer, this could have been a false positive result, or a flaw in the report. There was discussion around the difference between a “bitcoin stealer” and a “bitcoin miner”. The point, though, as was fairly made by the respondent’s representative, was that whether it was a “bitcoin miner” or “bitcoin stealer”, the file was evidently malware of some description and had been downloaded to the claimant's work laptop. It was not in dispute that he obtained video file conversation software from Sourceforge. The malware came with it although the function of the malware was unrelated to the purpose of the software itself.4.28 It was not in dispute that Sourceforge is a free site which anyone can at upload software to and download software from. The software in unlicensed. Mr Middleton said that although the purpose of Sourceforge (sharing software) is benevolent and some of the software may be very useful, the problem is that some of it has malware attached and there is no way of knowing if it does or not.4.29 The other evidence which was material to the question of whether the antivirus data was in some way flawed came from Mr Middleton. He said that it would not be unusual for a piece of malware not to be identified by every antivirus vendor immediately because as new malware develops it needs to be identified by its digital code in order to Case No. 2401691/2017 9 be picked up by an antivirus checker. He said that means that it is not unusual for only a few antivirus vendors to report software as malicious to begin with, and for more to do so over time. I fully accepted that.4.30 The ostensible purpose put forward by the claimant for downloading the video conversion software was in connection with a system called Webex. It was explained to me that Webex contains video recordings of client conversations, which may need to be replayed. His case was that the system used by the respondent to replay Webex recordings does not function well.4.31 Mr Middleton did not accept that. He said that no-one (including the claimant) had complained to IT that system the respondent advocated for the Webex material was problematic. Mr Middleton also pointed to the fact that the report said there were no movie or video files on the claimant’s work laptop. He said he would have expected to see some if the software had been downloaded to convert work-related videos. Another point which he made was that the video conversion software downloaded by the claimant did not state that it was capable of converting Webex recordings. The claimant accepted that point.4.32 Mr Middleton’s evidence was that for those reasons he thought it more likely that the purpose of the downloaded software was to view torrented copyright movies. I thought that was a reasonable conclusion. It was, in my judgement, significant that the software downloaded by the claimant did not claim to be compatible with Webex.4.33 Secondly, the forensic report identified the fact that the claimant had Dropbox installed on his laptop and that a large number of the respondent’s documents were saved into the Dropbox folder which included jobs that had been completed. The claimant agreed those documents would contain customer information but said they would not contain source code. The report said that analysis of the internet history suggested that mk2@bigfoot.com was the email address used to register with Dropbox. The claimant accepted that that was his personal email address but highlighted that there was also an email from Dropbox sent to his work email address.4.34 Mr Middleton gave some evidence around alternative methods of backing up data which would not involve Dropbox. He explained that the reason Dropbox is a security issue is because the respondent no longer controls the information. Mr Middleton explained that if client information is stored on the respondent’s NCC servers, Group IT controls security and there is antivirus protection, but also that there is control over the length of time the file remains on the system. It is usually for no more than seven days. He explained that there is a method of secure file exchange that can be used for backup. He said an external hard drive could also be used for the same purpose and the Verification Consultants all had them. Mr Middleton also explained that quite apart from the security risk because Dropbox is more readily accessible to third parties, there would be a problem if a member of Case No. 2401691/2017 10 staff who was using a personal Dropbox account left, because the respondent would lose control of all the data contained in it.4.35 The claimant said that prior to the respondent storing client information in-house, this was done by a third party provider and he argued that consequently the respondent did not control the information. Mr Middleton accepted that the respondent had previously used a third party provider, but said that there was control of the information because the contract stipulated the way the data was to be managed and that it should removed within seven days unless it was the Christmas period.4.36 I accepted that it was reasonable for the respondent to take the view that its own systems were more secure than Dropbox. I did not think the point relating to the third party provider was a good one, because clearly that provider was bound by the provisions of its contract with the respondent.4.37 Thirdly, the forensic report stated that the claimant’s browsing history contained browsing that did not relate directly to work but that none of it posed a risk to group security apart from the malware referred to above. It referred, amongst other things, to a large number of results for sites such as Facebook, Twitter, Reddit, Amazon and eBay.4.38 In addition to the forensic report, as part of the disciplinary process, the respondent relied on an extract referred to as a “sample” of the claimant’s internet usage/browsing history [154-158]. One of the issues raised by the claimant was that when he was invited to a disciplinary hearing relating to allegations about misuse of his work laptop he was only provided with the sample rather than the full browsing history. I will turn to that in due course.4.39 The claimant was suspended on 30 September 2016 [124]. The letter of suspension said that the purpose was, “to allow further analysis to take place into an allegation of gross misconduct concerning a serious breach in security, serious breach of internet use policy, misuse of company property and a fundamental breakdown in trust and confidence” and added: “To clarify, this is in relation to a malicious programme found on your laptop and also in relation to a number of internal client and internal documents which have been saved on a Dropbox account”. One of the points the claimant made in relation to the letter was that it did not make it clear that as well as the allegations about malware and the use of Dropbox, there was also a concern over his internet browsing history. I did not agree with that given the reference to “serious breach of internet security use policy” which may be read as including browsing history. However, even if the claimant did not realise his browsing history was of concern when he read the letter, he was well aware of it in advance of the disciplinary hearing because he was notified that there were three specific allegations plus what one might describe as the portmanteau allegation that his actions amounted to a serious breach of trust and confidence. Case No. 2401691/2017 114.40 There was an investigation meeting involving Mrs Durham which took place on 4 October 2016 [125-127]. The claimant disputed the accuracy of the minutes of that meeting but a number of points were not in dispute. These were:4.40.1 The downloaded file which had the malware attached to it was a video converter;4.40.2 The claimant said the purpose of downloading it was to improve formatting of recordings of Webex meetings;4.40.3 The claimant had not checked with IT whether he could download it form Sourceforge;4.40.4 The software had been run on his work laptop after it was downloaded;4.40.5 The claimant had not notified IT of problems with Webex at any point;4.40.6 The claimant understood the implications of the malware infecting the respondent’s network once his laptop had been connected to the network.4.41 In the investigation meeting, the claimant made reference to Mr Brooks having advocated the use of Dropbox. The claimant asked when the respondent had decided that use of Dropbox was not allowed and was told by Mrs Durham that it had never been allowed.4.42 The claimant was then invited to a disciplinary hearing [142] and in that letter of invitation which was sent by Mr Mills who, as I said at the beginning, dealt with the disciplinary hearing, there were four allegations all of which were described as “potential gross misconduct”:4.42.1 The introduction of unauthorised third party software into a work network, specifically movie converting software and Dropbox, which led to a serious breach in security because there was malware in the converting software and was also a breach of the IT and Communications Acceptable Use Policy;4.42.2 A breach of the Customer Data Protection Policy in Company Confidentiality, this being in relation to customers’ documents being saved in Dropbox;4.42.3 A waste of company time and misuse of company property around browsing history; and4.42.4 The trust and confidence allegation which was said to be due to the above.4.43 In advance of the hearing, the claimant was provided with the forensic report, the sample of internet browsing history which I have already Case No. 2401691/2017 12 referred to, and the investigation meeting notes. He was also provided with copies of emails including emails regarding the alerts from the SOC and IT concerning the malicious programme and the email from Mrs Durham warning her team not to use Dropbox [96 & paragraph 4.8 above]. He was also provided with copies of the disciplinary procedure, the IT Accepted Communications and Use Policy and the Customer Data Protection Policy.4.44 The disciplinary hearing was put back because the claimant said he was not given enough notice of it.4.45 Mr Mills’ evidence, which I accepted, was that he did a lot of preparation for the disciplinary hearing, because of the amount of documentation involved and the technical nature of some of the allegations. The notes were at pages 271-289 and there was another set of notes which was taken by the claimant's companion at pages 290-299 which did not appear to differ materially. In some instances one set contained a fuller account than the other. It was clear from both sets of notes Mr Mills asked some very detailed questions, He started with the Dropbox allegation and then asked about the video conversion software/malware allegations.4.46 Finally, he asked about the claimant’s internet browsing history. The claimant said his browsing history all related to breaks from work. Mr Mills told me that he did not accept that because it was inconsistent with the evidence which showed numerous such breaks at times when it would be usual to be working. Whilst he accepted that the claimant did not necessarily work normal hours because he was not based in the office, Mr Mills said the times spent browsing were too frequent and cumulatively lengthy to all be during breaks. Both the claimant and his companion raised the fact that a full browsing history had not been provided to them. The claimant suggested that Mr Mills had before him a much longer document which was later provided to the claimant for the purposes of the appeal [318 onwards]. Mr Mills said in evidence that he thought he was working from the sample document [154 onwards]. The claimant’s case was that this could not be right because the sample did not contain records showing he had visited Amazon and eBay. Mr Mills said that those sites were referred to in the forensic report. He explained he had asked general questions around this allegation because he wanted to understand when browsing had occurred and why.4.47 The claimant handed in copies of some of the messages between him and Mr Brooks during the disciplinary hearing. I have already covered that issue in my findings above. The short point is that the messages from Mr Brooks did not support the proposition that he had advocated the use of Dropbox.4.48 The other piece of evidence which the claimant put forward was an email from the author of the video conversion software that had been obtained from Sourceforge [214]. It stated: “Hello Mark, Please Case No. 2401691/2017 13 uninstall the programme and make sure the registry entry is cleaned or clean it yourself. There was a bug in the programme. Consider waiting for new version I’m working on. My apologies on the bug.”4.49 The claimant’s case was that this demonstrated that there was no malware, simply a bug in the video conversion software. There were clearly some difficulties with that proposition. Firstly, as Mr Middleton pointed out, the author of a programme with malware attached would be very unlikely to admit that. Secondly, the forensic report said otherwise.4.50 The claimant’s case was that because a decision was made by Mr Mills on the day (which he was not expecting) Mr Mills must have already made his mind up in advance. Mr Mills’ evidence was that if there had been any points that he thought merited further investigation, he would have adjourned the disciplinary hearing for that to happen. He said that nothing that was said during the course of the hearing caused him to think that further investigation was necessary and consequently he reached a decision that day.4.51 Mr Mills provided a very detailed rationale about the questions he asked and his conclusions in about the allegations in his witness statement. The unauthorised software/malware allegation was dealt with in paragraphs 20-35; the Dropbox allegation was dealt with in paragraphs 36 to 50; and the browsing history allegation was paragraphs 51-64. I accepted that he approached the allegations with an open mind and dealt with them thoroughly. The fact that a decision was made on the day is not unusual in my experience, and it certainly does not follow that the decision maker has already made a decision.4.52 The outcome letter was dated 26 October 2016 [300]. It did not provide a detailed rationale of the reasons why Mr Mills reached the decision he did. It simply reiterated the charges and said that they were found proven and that the claimant was summarily dismissed for gross misconduct.4.53 I thought it likely from the questions asked by Mr Mills during the hearing that the claimant would have had a good idea of what Mr Mills thought required explanation. Nevertheless, the fact is a better rationale should have been provided. I shall return to that in my conclusions, because it was one of the issues raised by the claimant about the fairness of the disciplinary process.4.54 The letter also used the word “we” in connection with the decision making process. When I asked Mr Mills about that he was clear that it was his decision and his alone.4.55 I also asked him about mitigation and sanction given that the claimant was a good worker and had worked for the company for a long time. Mr Mills told me that was something he had carefully considered but that he felt that three very serious allegations had been proven which Case No. 2401691/2017 14 amounted to a very serious breach of trust and confidence. He said that he thought the claimant had been “flippant “in his responses to some of the questions asked during the disciplinary hearing. I asked him to explain what he meant by “flippant”. Mr Mills said, by way of example, that the first explanation the claimant put forward for downloading the video conversion software was that he had administrator status. Mr Mills said that just because the claimant had the ability to do so because of that status, it did not mean he was authorised to do or should have done it. Mr Middleton made similar points in his evidence. He said that he could not accept that the claimant, given his IT background, could have thought his actions were acceptable. He gave the example of using a company car for a ram raid. I thought the point was uncontroversial: the fact that you can do something does not mean you should. That is particularly true when, as in this case, the respondent had trusted the claimant and his colleagues not to abuse their administrator status. I concluded that is was reasonable for Mr Mills to decide that dismissal was the correct sanction given the circumstances.4.56 For the sake of completeness, I should record that Mr Mills’ evidence, which I accepted, was that although he knew of the 2014 incident involving the claimant it played no part in his decision making.4.57 The claimant put in an appeal by email [307]. He provided the grounds on 6 November 2016 [308].4.58 In a letter inviting the claimant to an appeal meeting dated 9 November 2-16 the grounds were summarised by the HR Director who was assisting with the appeal. The claimant did not challenge the summary. Mrs Haywood, who was the decision maker, explained that the appeal focussed on those grounds. We had some discussion about whether the appeal was in the nature of a review or re-hearing. It appeared that the respondent’s policy is that the nature of the appeal hearing depends on the grounds which are put forward, so it could be a rehearing or it could be a review (for example, of the sanction). The grounds were that:4.58.1 There were a number of incorrect and/or unsubstantiated comments about the first two allegations;4.58.2 The claimant had not been provided with all of the evidence about the third allegation (the browsing history/internet usage allegation);4.58.3 The claimant was under the impression that it was not deemed strictly necessary to obtain permission from Group IT prior to downloading the video conversion software;4.58.4 The claimant had downloaded and installed Dropbox to back up work in progress when off site and when the use of VPN did not allow for speedy backups; Case No. 2401691/2017 154.58.5 The claimant had not permanently stored customer or company files in Dropbox;4.58.6 The claimant accepted that he had frequently but briefly logged onto certain social media sites, but wanted to apologise for that and to undertake not to do it again.4.59 Mrs Haywood heard the appeal and the minutes were at pages 337- 346. Prior to the appeal the claimant was provided with a full copy of the internet browsing history. The claimant was accompanied at that meeting by somebody called “Bernie” who made quite a number of points during the course of it including arguing that the internet browsing allegation should not have been included because it was not set out in the suspension letter.4.60 It was clear to me from the minutes that Mrs Haywood asked detailed questions about the allegations and the grounds of appeal.4.61 A number of points that were raised during the appeal were subsequently investigated. This included further investigation with the Group IT department about the speed and availability of the VPN network. A response was received from Mr Matthew Flemming of Group IT stating that of there were approximately 900 users of VPN and that no complaints regarding speed and/or availability had been made. In the hearing before me, the claimant argued that the problem with VPN was about being able to back up using the network and pointed out that Mr Middleton had accepted in his evidence that backing up is not really the purpose of the VPN network. The problem with that argument was that the minutes of the appeal meeting recorded that the claimant raised issues about speed and availability, not speed of backing up. Consequently it was incorrect to say the wrong question was asked.4.62 The appeal outcome letter contained a very detailed rationale from Mrs Haywood as to why she concluded that the appeal should not be upheld by reference to the grounds in paragraph 4.58 above. To briefly summarise, her conclusions on the first two allegations were that it would be impossible for the respondent to keep a complete list of what software could be downloaded and that this was why permanent downloading of software had to be authorised by Group IT. She stated that this was a compliance requirement and also was to protect the security network. She concluded that the claimant had not obtained authorisation to download the video conversion software or Dropbox and therefore his actions were unauthorised and in breach of the respondent’s policies. Mrs Haywood went on to state that having reviewed all of the available information, her conclusion was that Dropbox was not used by the respondent and its use was neither accepted nor recommended. Mrs Haywood also confirmed that enquries with HR showed the claimant had completed on-line Sans training (see above and page 353). Case No. 2401691/2017 164.63 The next point covered related to the VPN not allowing for speedy backups. Mrs Haywood stated there had been no complaints by users of VPN about speed or availability. She also pointed out that other methods of back up could have been used, such as the external hard drive.4.64 Finally, as regards internet usage and not having been provided with a full browsing history, Mrs Haywood stated that a sample had been provided and that a full log had been provided for the appeal hearing.4.65 As to the latter point, during cross-examination of the claimant, the respondent’s representative took him to the full log which comprised of about 6,000 entries [318 onwards]. It was established that the timings were in fact one hour later than shown because of British Summertime. Even taking that into account it was quite clear that various entries on various days during what appeared to be work time showed the claimant had visited websites which he accepted were not workrelated. The claimant’s explanation was far from compelling. He said that if he was browsing non work-related websites for half an hour that would class as part of his lunch break; and that if he was doing it for ten minutes it would be in substitution for breaks people would take in the office to have coffee. It was quite clear to me that the respondent had established that the volume and frequency of the breaks, albeit that some of them were short, pointed to at least some of this activity taking place during work time. More to the point though, it was not unreasonable for Mr Mills to reach that conclusion or for Mrs Haywood to uphold it4.66 Mrs Haywood’s evidence was that she could find no reason to overturn any of Mr Mills’ findings, and that she agreed summary dismissal was appropriate due to lack of trust and confidence. She told me she was unaware of the 2014 incident when she made her decision. The Submissions[5]The respondent’s submission contained an accurate summary of the applicable law. Because the claimant had originally argued that he was treated more harshly than Mr Hone, the submissions also covered Hadjioannou v Coral Casinos Ltd [1981] IRLR 352 EAT which provides guidance that arguments on disparity of treatment must be scrutinised with particular care. In light of the claimant’s concession (see paragraph 4.19) it was not necessary for me to consider that argument. The claimant’s case was that his dismissal was unfair predominantly because Mr Mills had a closed mind, but also for the procedural points dealt with in my findings of fact and/or because dismissal was too harsh a sanction.
The Law
[6]The relevant statutory provisions are contained in section 98 of the Employment Rights Act 1996 (“The 1996 Act”): 98 General Case No. 2401691/2017 17(1) In determining for the purposes of this Part whether the dismissal of an employee is fair or unfair, it is for the employer to show – (a) the reason (or, if more than one, the principal reason) for the dismissal, and (b) that it is either for a reason falling within sub-section (2) or some other substantial reason of a kind such as to justify the dismissal of an employee holding the position which the employee held.(2) A reason falls within this subsection if it - ….. (b) relates to the conduct of the employee, …. (4) Where the employer has fulfilled the requirements of subsection (1), the determination of the question whether the dismissal is fair or unfair (having regard to the reason shown by the employer) – (a) depends on whether in the circumstances (including the size and administrative resources of the employer’s undertaking) the employer acted reasonably or unreasonably in treating it as sufficient reason for dismissing the employee, and (b) shall be determined in accordance with equity and the substantial merits of the case.[7]The first stage is for the employer to establish, on the balance of probabilities, a potentially fair reason for dismissal.[8]In a case where conduct is said to be the reason the relevant case law has been well established by cases such as British Home Stores –v- Burchell 1978 IRLR 379, Iceland Frozen Food –v –Jones 1982 IRLR 439, Foley v Post Office and HSBC Bank plc v Madden 2000 IRLR 827, and Sainsbury’s –v- Hitt 2003 IRLR 23. It is for the employer to establish that the decision maker did believe that the misconduct alleged had occurred. The employer must also establish that the alleged misconduct was the reason (or principal reason) for dismissal. If the respondent establishes a potentially fair reason, the tribunal must then consider the question of fairness. There is a neutral burden of proof at this stage. The tribunal must consider whether the decision maker had reasonable grounds in their mind upon which to sustain the belief; and whether, as at the point they formed that belief, as much investigation as was reasonable in all the circumstances had been carried out. The case law also makes it clear that the tribunal should not form its own view as to whether dismissal should have taken place, but should ask whether dismissal was within a band of responses available to an employer acting reasonably. The range of reasonable responses test applies as much to the investigation as it does to the decision to dismiss. Where the reason for dismissal is said to be gross misconduct, the Employment Tribunal must bear in mind that it does not inevitably follow that dismissal as a sanction was within the range of reasonable responses.[9]If an employee’s unfair dismissal complaint is well-founded, the primary remedies for unfair dismissal are an order for reinstatement or re-engagement Case No. 2401691/2017 18 (sections 112 and 113 and ERA). If the employee wishes the Tribunal to make such an order, it is only after deciding not to do so, that the Tribunal shall award compensation in accordance with the principles set out in sections 18 to 26 of the ERA (see section 112 ERA).[10]If an employee is unfairly dismissed under section 98, any compensation may be reduced because of contributory conduct. Section 123(6) of the 1996 Act provides that where the Employment Tribunal finds that the dismissal was to any extent caused or contributed to by the action of the complainant, it shall reduce the amount of the compensatory award by such proportion as it considers just and equitable having regard to that finding. Section 122(2) provides that where the Tribunal considers the conduct of the complainant before the dismissal was such that it would be just and equitable to reduce or further reduce the amount of the basic award to any extent, the Tribunal shall reduce or further reduce that amount accordingly. If the Tribunal considers there was culpable or blameworthy conduct then contribution will be an issue – see Nelson v British Broadcasting Corporation No.2 [1979] IRLR 346 CA.[11]Finally, if the Employment Tribunal considers the dismissal is unfair, for example because a fair procedure was not followed, the Tribunal should consider the prospect of the claimant being dismissed if a fair procedure had been followed. This can include an assessment as to when dismissal would have occurred or as to the percentage chance that the claimant would have been dismissed - see Polkey v AE Dayton Services Ltd [1987] IRLR 503 HL. In addition, the Tribunal should consider whether the claimant would have left in any event and, if so, under what circumstances. See for example Abbey National v Chaggar [2010] IRLR 47 EWCA & Wardle v Calyon UK [2011] IRLR 545 EWCA. Wrongful dismissal[12]In addition to complaining of unfair dismissal, the claimant complained of wrongful dismissal. A wrongful dismissal complaint is a breach of contract claim, and consequently the legal principles are very different than those which apply to unfair dismissal complaints. For the former, the tribunal’s role is in essence to review the actions of the employer as tested against the range of responses available to an employer acting reasonably. For a wrongful dismissal claim, the question is whether the respondent dismissed the claimant in breach of his contract of employment. In cases where an employee is summarily dismissed for gross misconduct, the employer will not have dismissed in breach of contract if the employee has committed a repudiatory breach of contract which would entitle the employer to treat the contract as at an end, and to regard itself as no longer bound by it. The employer accepts the repudiatory breach by bringing the contract to an end without notice. Therefore the tribunal first has to determine whether there has been a repudiatory breach of contract by the employee. This requires the tribunal to make findings as to the employee’s conduct, and as to whether that conduct amounted to a repudiatory breach of an express or implied contractual term – usually the implied duty of mutual trust and confidence. Therefore, for the wrongful dismissal exercise, the tribunal is required to decide on the balance of probabilities whether the alleged misconduct occurred and, if so, whether it was sufficiently serious to amount to a repudiatory breach. If the tribunal decides that it was, the tribunal must then determine whether the employer accepted that breach by bringing the contract to an end. Case No. 2401691/2017 19
Conclusions
[13]I shall first deal with the reason for dismissal. I was quite satisfied that the respondent had established that the reason in the mind of the decision maker, Mr Mills, was gross misconduct. Mr Mills was quite clear that his view was that each of the first three allegations, whether taken individually or cumulatively, amounted to gross misconduct and that because of the claimant’s position of trust, which he had abused, there was a serious and fundamental breakdown in trust and confidence.[14]I was also quite satisfied that there had been a reasonable investigation, including obtaining a forensic report. The claimant’s criticisms of that report were, in my view, misplaced for the reasons set out in my findings of fact.[15]I did not accept that the failure to refer specifically to the internet browsing allegation in the suspension letter rendered the process unfair, because the claimant was aware of that allegation in advance of the disciplinary hearing. Nor did I accept that using a sample rather than the full log at the disciplinary hearing was unfair or unreasonable. Firstly, the sample and the questions asked about that and the forensic report were more than sufficient to constituent a reasonable process. Secondly, the full log was provided at the appeal stage. Thirdly, the full log did not assist the claimant in any event for the reasons set out in my findings of fact. The latter point is a Polkey point.[16]The key points in relation to the three allegations about misuse of the work laptop were that it was reasonable for Mr Mills to conclude from the evidence before him: that the Verification Consultants had been told not to use Dropbox apart from on a one-off basis if a customer requested it and the use was approved and controlled; that the claimant had downloaded video conversion software from an unsafe site without approval and that malware was attached to it; and that the claimant was browsing social media which was, in any event, contrary to the respondent’s policy and was doing so on such a frequent basis that some of it was within work time.[17]There was also the context which the respondent rightly pointed to, which was that data security is critical to its business because the consequence of breaches of data security could be very serious for the respondent and for its customers.[18]Mr Mills’ evidence on loss of trust and confidence was compelling. He took into account the claimant’s long service and skills but concluded that it was not possible to trust the claimant to behave any differently in the future. I thought that was a reasonable conclusion to reach. The claimant pointed out that it would have been possible for the respondent to lock down his laptop i.e. remove the administrator status. The difficulty with that argument is that it misses the point. As the respondent’s representative rightly pointed out, the Verification Consultants were trusted not to abuse their administrator status, and the claimant had done so. It is no answer to that point to say that by removing the possibility of wrongdoing, trust and confidence will be rebuilt – quite the opposite in fact.[19]I shall now turn to dismissal; as a sanction. For the reasons set out above it certainly cannot be said that summary dismissal was outside the range of reasonable responses, given the claimant’s actions. Case No. 2401691/2017 20[20]I concluded that the fact that the dismissal letter did not spell out why Mr Mills had found the allegations to be proven, this did not of itself render the process unfair, because the reasons would have been clear to the claimant from the evidence used at the disciplinary hearing and the questions asked. For that reason, and the reasons set out in paragraph 15, I did not accept this was a procedurally unfair dismissal. However, and in any event, if it had been necessary for me to consider Polkey, I would have concluded that the outcome would have been no different and the decision making process would have taken no longer.[21]I will deal very briefly with the wrongful dismissal point. The question here was whether, on the balance of probabilities, my conclusion was that the claimant did commit the misconduct alleged. The evidence was compelling in this case – he clearly did. His conduction was such that it went to the heart of the contract and constituted a fundamental and repudiatory breach of contract. The respondent was therefore entitled to dismiss him without notice. If it had been necessary for me to consider contribution, the answer flows from my finding on the wrongful dismissal claim. I would have held that it was 100%. The claimant was a very experienced IT professional; the respondent had very clear policies; the claimant was familiar with them; yet he chose to act irresponsibly thereby creating unacceptable security risks.[22]Fort he above reasons I decided that the unfair and wrongful dismissal complaints were not well-founded and should be dismissed.