Enterprise IT users fear fallout from Oracle's SAP lawsuit

Software vendors should have exemplary business ethics because they have access to their customers core systems and data. Any suggestion of impropriety can undermine the trust between end users and their suppliers.

Share

Oracle's surprise legal move against its main business applications rival SAP has raised questions again about the likely impact on customers of corporate scandals in the IT world. Whatever the outcome of the case, users are voicing their concerns about software vendors' ethics.

Oracle filed a lawsuit last week against SAP, its SAP America division, its TomorrowNow subsidiary and 50 unnamed individuals Oracle claims were SAP employees.

It could be good for Oracle to say, 'We have no beef with the customer, our beef is with SAP, or it could be perceived as Oracle picking on the customer

David Mitchell, Ovum

The complaint charges that SAP committed "corporate theft on a grand scale", with one or more staff at TomorrowNow allegedly pretending to be Oracle customers and illegally hacking into its secure support website for users of Oracle's PeopleSoft and JD Edwards applications.

SAP then allegedly copied content from the site and used it to offer Oracle customers cut-rate support services in the hopes of eventually migrating them over to SAP's rival applications.

So far, SAP has yet to respond publicly to the accusations and Oracle has not made any additional comment beyond the lawsuit itself.

"If we decide to trust a company, we'd hope it to be justified," said an IT manager at a French company that uses JD Edwards applications and sources its support for that software from TomorrowNow. "When we choose a supplier, we don't necessarily investigate them first," he added. The manager agreed to speak on the condition of anonymity for himself and his company.

While products, services and price are primary factors in procurement decisions, a vendor's business practices are also extremely important, according to John Matelski, chief security officer and deputy chief information officer for the US city of Orlando, and a JD Edwards user.

He is also the former president of the Quest International Users Group, which focuses on the needs of PeopleSoft and JD Edwards applications customers that Oracle acquired through the January 2005 purchase of PeopleSoft.

"As a public sector entity, which is directly accountable to its citizens and constituents, I would be concerned about our relationship with any vendor that is proven to conduct business in an unethical manner," Matelski said.

"Due to the nature of the relationships that we develop, software vendors and consultants would be held to a higher standard, because they would typically have a greater level of access to our systems and data during implementation and support engagements," Matelski wrote.

"The security and privacy of our data is key, and if an organisation is known to have illegally obtained data before, I would need to be much more careful when evaluating whether to establish or continue a relationship with them."

David Mitchell, software practice leader at UK-based analyst Ovum drew a comparison between the potential damage of the lawsuit with fallout of the corporate spy scandal that hit Hewlett-Packard last year. Despite leading to the resignations of several executives including its chairman, HP weathered the storm well and customers stayed loyal to the company.

"With HP, [CEO Mark] Hurd responded positively, he apologised," Mitchell said. "It was about the approach they took when something inappropriate had happened. If HP had not responded so positively I think they would have seen more negative consequences."

Should Oracle's charges against SAP be proven, "they need to embrace it and reassure people how it's come about", he added. If there was some wrongdoing, Mitchell, the former senior director for market development at Oracle UK, believes it will turn out to be the work of one bad apple. "SAP ethically and culturally is a very correct organisation, this isn't rotten DNA," he said. "If this turns out to be true, then it will be an individual, I think, who has acted inappropriately."

As for Oracle, the vendor needs to act to avoid any negative publicity from the suit given that it named many customers whose identities were allegedly purloined by SAP and suggested that SAP customers unknowingly might be using services that contain Oracle's intellectual property.

"It could be good for Oracle to say, 'We have no beef with the customer, our beef is with SAP,'" Mitchell said. "Or it could be perceived as Oracle picking on the customer."

Find your next job with computerworld UK jobs