About Us | Contact Us
View Cart

The Threat From Within

By Vigilize | Monday, March 2, 2020 - Leave a Comment

One of the biggest data security threats you face comes from inside…


An article review.


We spend a lot of time thinking about the threats to our network posed by hackers: from ransomware and phishing scams to data breaches, we often view the culprit as being some unknown person or organization… someone possibly not even in the same country.

The unfortunate truth is that, according to several recent reports, the biggest risks to network and data security come from your own employees.  Verizon’s annual Data Breach Investigations Report, for example, says that over a third of data breaches in that year involved employees.  A similar annual report from Code42 says that when asked anonymously, over half of the IT workers polled said that data breaches in their organization had been caused by their own employees.  A third report funded by Observe IT and Proofpoint says the number of insider cybersecurity incidents increased by nearly half over 2018, and cost businesses roughly $11 million in damages.

One reason you might not have heard as much about insider threats is because we want to trust our employees.  An atmosphere of mistrust can actually contribute to insider threats, as employees already feel they’re being treated as a threat to the company.  Another problem is that some employee incidents are simple mistakes that lead to a breach, and are not malicious in intent…and that means combating insider threats involves both awareness training and security controls.

If you’d like to know what the FFIEC has to say on the subject of internal threats, we have a guidance summary available for download here.

 


Original article composed with data from reports by Verizon, Code42 and Observe IT.


same_strip_012513


 

Latest News
      Alternatives From 2020 Conferences The 2020 Update Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Each year as we go to various conferences throughout the Midwest ranging in scope; from small banker conferences that Dan himself moderates, to hacker conferences like Defcon.  We […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office.  
    The IBA Presents an infotex Workshop: Tech-Shop (A Virtual Workshop for Banks IT Geeks) Live Workshop Time for a workshop for the technical side of the community-bank. Time for a workshop full of command lines and configurations, acronyms we are forbidden to use around management, and even dark-web jokes. Time for a workshop where we […]
    An Analogy… …About Taking Better Notes Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . An interesting set of metaphors arose out of our efforts to improve our time management practices at infotex.  In the spirit of sound strategic planning, we as a team decided […]
    A Webinar-Movie In our current world of uncertainty there is at least one thing that is certain. Business needs to continue, and that means that it is important for managers to be able to meet with their team even if everyone is working remotely at this point. In this Webinar-Movie, Dan will compare virtual meeting […]