Remember, Remember … Insider Cyber Threats

Its Bonfire Night tonight but no gunpowder here…

However, insider cyber threats can be just as explosive as cyber-attacks coming from the outside, and much harder to detect. Adding remote working to the mix, as so many are doing now, can further increase the risk of attacks.

There are a few different types of insider threats, each with different motivations:

  • The ‘malicious insider’, who causes loss or damage on purpose. They probably started out as a well-intentioned employee, but something changed—they became disgruntled with their employer, or a change in their personal life meant that they needed extra money. Examples include:
    • Selling your intellectual property or other sensitive data for financial gain
    • Sabotaging computer systems or corrupting data because they want revenge for some reason.
  • On the other hand, the ‘pseudo insider’ is someone who becomes an insider in order to cause loss or damage to the company: perhaps a criminal, an activist, or someone motivated by a competitor to gain inside information.
  • The ‘unwilling insider’ threat could be an employee who is coerced into revealing secrets, or causing loss or damage, through blackmail or fear. They cause a problem on purpose, but unwillingly.
  • The ‘accidental insider’ threat is due to someone who causes accidental loss or damage unintentionally, through some genuine mistake/human error.
  • The ‘negligent insider’ is a threat because although they don’t set out to cause a problem (unlike the malicious insider), they are willing to bend the rules a bit and don’t adhere to security policies. They might:
    • Be careless about documents and data storage devices
    • Over-share information in conversation or on social media
    • Believe that the security policies are misguided, or don’t apply to them
    • Or they might find that following the rules is just too slow.
How to reduce the risk of insider cyber threat

All insider cyber threats are hard to detect, no matter what type or motivation, and is primarily a people-related problem rather than a technical one. Here are some suggestions for how to minimise the risk in your organisation:

  1. Consider screening potential employees (including contractors) with security in mind. Not all roles need the same level of screening, so focus on those who would have access to sensitive information.
  1. Establish a good security and company culture to minimise the risk of people becoming a threat (accidentally or on purpose):
  • Establish a set of core security policies and procedures, to set clear expectations
  • Acknowledge the risk of insider cyber threats to your team, and provide regular training for all employees on.
  • Establish a process for reporting concerns—a hotline, or via management reports.
  1. Employee training should include:
    • Security policies and procedures
    • Phishing and social engineering
    • Key indicators that might (but equally might not) reveal a problem with a co-worker, such as:
      • Unusual requests, or interest in an area outside their usual role
      • Extensive use of USB sticks, printers and other ways of transferring data
      • Changes in the way they behave, or their work patterns
  1. Establish security management to identify and manage any employee who might become a threat.
  • Consider adding operational and technical safeguards, such as:
    • Limiting personal device use (so you have more control)
    • Adding physical controls, such as locks, to deter the curious explorer
    • Using data loss prevention tools. These enable you to block and audit the use of USBs and data transfers, block unauthorised cloud storage and detect unusual activity such as large data transfers.
  • Also, consider adding personnel safeguards, such as:
    • Being willing to question changes in behavior or work patterns. These may not mean there is an insider threat problem, though may mean that there are other issues
    • Ensuring that exit procedures are followed, so that people who have left the company no longer have access to your systems.
  1. And bear in mind that remote working increases the risks of employees becoming stressed and disengaged, with lower levels of loyalty and commitment:
  • Staff may be living in shared accommodation with little privacy or ability to safeguard devices
  • They may feel isolated or out of the loop due to lack of communication
  • They may overwork (or underwork) and burn out.

Set up regular catch-up sessions, and if they don’t exist already, set up channels for social chat, so that staff continue to feel part of your organisation.

 

If insider cyber threats is an area of concern for you, have a look at the CPNI website for more information, infographics, videos and other training and awareness material here, and here.
And, of course, if you’d like us to help you put in place any of these risk mitigations, please contact us or call CSP on 0113 5323763.

Leave a Reply

Your email address will not be published. Required fields are marked *