Court Upholds SCIF's Suspension of Attorney for Repeated Failure of Cybersecurity Tests
Friday, July 31, 2026 | 0
A California appellate court upheld the suspension of a State Compensation Insurance Fund attorney from her position due to her repeated failure of internal cybersecurity tests.
Case: Bedrossian v. California State Personnel Board (State Compensation Insurance Fund), No. B349445, 07/28/2026, unpublished.
Facts: Sylvia Bedrossian worked as a staff attorney for State Compensation Insurance Fund, litigating workers’ compensation cases. Her position required that she work with confidential and sensitive information.
SCIF requires that all employees take cybersecurity awareness and privacy training annually so that they can recognize external threats such as phishing and other social engineering tactics.
Over the course of her employment at SCIF, Bedrossian participated in numerous training sessions on how to identify and handle phishing emails. This training educated employees about red flags that should alert a recipient that an email is potentially dangerous.
In 2018, SCIF’s security department circulated a memorandum to all employees announcing “organization-wide security phishing awareness tests.” These tests involved sending emails to all 4,000 SCIF employees in a randomized fashion that mirrored what a real phishing email might look like.
If an employee clicked on links contained in the emails, replied or opened an attachment, the employee was deemed to have failed the test.
The memorandum informed employees that those who failed would receive counseling and reinforcement training, and repeated violations may result in formal disciplinary action.
In 2019, SCIF began automatically adding an “external sender notification” banner on all emails from outside SCIF, which reminded the recipient in yellow highlighted text that the email was sent from outside the organization and not to click on links or open attachments “unless you recognize the source and know the content is safe.”
Between December 2021 and December 2022, Bedrossian failed three phishing tests. As a result of the first failure, she was required to participate in remedial cybersecurity training sessions.
After Bedrossian failed two more tests, SCIF suspended her for five days.
Procedural history: Bedrossian appealed the suspension to the State Personnel Board.
An administrative law judge issued a proposed decision upholding Bedrossian’s suspension. The ALJ found that SCIF had sufficiently proven multiple “cause[s] for discipline, including the “inexcusable neglect of duty,” “discourteous treatment of the public or other employees,” “willful disobedience” and “other failure of good behavior either during or outside of duty hours which is of such a nature that it causes discredit to the appointing authorities or the person’s employment.”
The board adopted the ALJ’s proposed decision and issued an order upholding the suspension.
Bedrossian then filed a writ petition, which a trial court judge denied.
Analysis: The Court of Appeal for the 2nd District of California said that because Bedrossian didn't cite any proof that the board’s findings were not supported by adequate evidence, she forfeited her arguments.
The court also said Bedrossian’s clicking links in emails containing red flags, “if repeated[,] is likely to result in, ‘[h]arm to the public service’” by compromising data that the fund has a fiduciary obligation to protect.
In addition, because cooperation "among public employees is essential to the smooth functioning of public service,” the board’s finding of Bedrossian’s discourteous behavior toward the security analyst showed harm to the SCIF’s public service efforts as well.
Disposition: Affirmed.
To read the court’s decision, click here.
Comments