Los Angeles Times

Cyber security is part of game in the majors

The Angels and Dodgers are responsibl­e for protecting their data, but MLB is willing to help. ‘I will literally go weeks without writing. Even signatures on contracts are done electronic­ally.’ — Jerry Dipoto, Angels general manager

- By Bill Shaikin

When Jerry Dipoto retired as a player and started his climb up the front-office ladder 15 years ago, the Angels’ general manager discovered that teams would store their most treasured data on handwritte­n index cards. Now? “I will literally go weeks without writing,” Dipoto said Tuesday. “Even signatures on contracts are done electronic­ally.”

In baseball’s informatio­n age, a team is as vulnerable as any other business to hackers breaking into a computer system. The Houston Astros learned that lesson the hard way last year, when Deadspin published leaked documents about trade talks, and Major League Baseball confirmed Tuesday the existence of a “federal investigat­ion into the illegal breach of the Astros’ baseball operations database.”

The league has no evidence that another club has been the victim of a security breach, a high-ranking MLB official told The Times, speaking on condition of anonymity because of the ongoing investigat­ion. The official — speaking generally and not about the Astros case — said each team is responsibl­e for its own cyber security, but MLB employs experts and makes them available to consult with teams.

It is impossible to overstate the role of computer systems in the operation of a team — and not just on the business side, where executives can adjust ticket prices daily based on the latest sales data or modify orders for hot dogs or bobblehead dolls based on updated attendance projection­s.

The Dodgers just added a director of research and developmen­t, and they are hiring a “data scientist” as part of that analytics unit charged with imagining and developing “mathematic­al, statistica­l, and predictive models to support baseball operations.”

Dipoto said every team has a proprietar­y database, developed in-house or custom-designed for the team by a technology company. The Angels’ computers include, among other features, statistica­l analysis, scouting reports, draft valuations, player videos, and what Dipoto said was a personal page for more than 6,000 players, from major and minor leaguers to amateur players in Venezuela and the Dominican Republic and pros in Mexico, Japan, and South Korea.

Minor league managers used to file nightly reports — who’s hot, who’s not, who’s hurt, and so on — and Dipoto said he used to need an hour each morning to listen to all the voice mails.

“Now everything is accessible at the click of a button,” he said.

The New York Times, which first reported the federal probe into the Astros’ data breach Tuesday, said investigat­ors traced the leaks to employees of the St. Louis Cardinals who were “hoping to wreak havoc on the work of Jeff Luhnow,” the former Cardinals executive hired in 2011 as the Astros’ general manager.

The newspaper reported that the Cardinals employees, concerned that Luhnow might have taken proprietar­y informatio­n, gained access to Astros computers based on passwords used in St. Louis by Luhnow and others who followed him to Houston.

In that event, the Astros might have been guilty of failing to take even the most basic of security precaution­s — changing your password every 90 days — said Ken Westin, senior analyst for Tripwire, an Oregon-based company that helps firms detect, prevent and respond to computer security threats. “In their defense, they’re probably not used to being attacked like this,” Westin said.

A baseball team — or any other small business — need not spend more than $20,000 to protect its in- tellectual property from cyber attack, said Mo Rosen, chief operating officer at Xceedium, a Virginiaba­sed company that helps businesses and the government protect data. Rosen said a two-step authentica­tion process — a password, plus a card provided by the Astros, similar to an ATM card — might have been enough to keep the team’s data safe.

“They didn’t even take the most rudimentar­y steps to protect themselves,” Rosen said.

Dipoto said he was not overly concerned by the possibilit­y of a hack into the Angels’ computers, since baseball teams tend to differenti­ate themselves not by the informatio­n they collect but how they apply it. Still, he said, the Angels’ computer security precaution­s ref lect the best practices of corporate America, first launched when the team was owned by the Walt Disney Co.

To access the most confidenti­al baseball operations data, Dipoto said, he needs much more than a password. “It’s like walking into Ft. Knox,” he said.

bill.shaikin@latimes.com

‘I will literally go weeks without writing. Even signatures on contracts are done electronic­ally.’

— Jerry Dipoto,

Angels general manager

Newspapers in English

Newspapers from United States