BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

You And I: The Not So Obvious Insider Threat

Post by Peter McCalister December 6, 2011

Remember the scene in Jerry Maguire where he has returned to his office to collect his stuff, after learning he has been let go, and he has a bit of a freak-out on the way out the door, grabbing the goldfish and making bold claims about the company he is going to build that will ruin his former employer?

For most of us, that is the perfect visual of a disgruntled former employee and potential insider threat, raising our red flags to immediately take action to remove any and all access privileges that employee had.

annie

But what about the threats which are in much more mundane packaging? The threats posed by you and me – employees that would never dream of deliberately causing harm to our employer, but that pose just as great a risk of an insider threat, albeit accidental. Over privileged and poorly monitored, these employees have the potential to cause as much damage as the obviously disgruntled.

While the percent of breaches that happen by accident is substantially less than the percent of intentional insider threats, according to the 2011 Verizon Data Breach Report, it is important not to overlook this possibility and to ensure that the right privilege identity management policies are in place. A simple misdirected email, such as the case with Stanford Hospital is all the proof you need that accidental insider breaches can happen, to anyone, at any time and the only way to thwart them is to implement strategic corporate security policies with least privilege.

Leave a Reply

Additional articles

BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,
insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,

Are you a Target? Investigating Security Breaches with Kevin Johnson

Last week, over 1,000 IT security professionals watched as Kevin Johnson, CEO of Secure Ideas, presented his expert opinion on lessons learned from recent, high-profile retail breaches. Here’s a summary of key takeaways from the webcast plus an on-demand recording of the full, 60-minute presentation. Understanding the “why” behind attacks According to Kevin, the primary…

Post by Chris Burd April 17, 2014
Tags:
, , , , ,