Disciplinary consequences of running unauthorized automation scripts on company hardware

I am seeking some legal perspective regarding workplace IT regulations and disciplinary procedures. A junior employee was recently flagged by our systems administrator for downloading and running a script execution tool on a company-issued laptop. The IT team raised severe security concerns, arguing that installing third-party bypass applications violates our internal charter on hardware usage and creates potential network vulnerabilities.

When confronted during an informal discussion, the employee claimed they were merely experimenting during their lunch break and had referenced this page to show that the software was just intended for client-side gaming modifications rather than any malicious internal breach. Regardless of their personal explanation, management is considering this a breach of trust and discussing formal sanctions.

From an employment law perspective, does an employee’s lack of harmful intent mitigate their liability when clearly breaching signed IT security protocols, or does running unauthorized execution utilities typically justify serious disciplinary action or termination?