You gotta assume if someone is an engineer they can do some nasty stuff. The idea is there's professional etiquette and ethics. It's as easy as encrypting some code, downloading it as some image file, and running it through a benign sounding script. Keystroke monitoring is more likely to find you chatting with your SO than a breach.