While nation-state threat actors and external hackers often garner the headlines, insider threats are an often-overlooked threat vector. Rockwell-Boeing, Anthem Healthcare, and Capital One are just a few organizations with damaging data breaches caused by insiders. Insiders such as privileged users, contractors and vendor partners, and trusted executives often have access to the “keys to the kingdom” and know system and process weaknesses to exploit.A 53% majority have confirmed insider threats against their organization in the last 12 months, with 27% stating that insider attacks have become more frequent, according to Cybersecurity Insider’s 2018 Insider Threat Report. Ponemon Institute found that insider threats do more damage for longer than external threats, with an average cost of $8.7 million. Detecting and blocking insider threats and inadvertent insiders are crucial to reduce lost productivity and incident response costs. Managed Service Providers (MSPs) can enable practical cybersecurity approaches, both within their networks and their client’s, to reduce exposure to insider threats and accelerate a rapid response when minutes matter.These types of internal threats can be particularly challenging to detect, especially if organizations have primarily focused on bolstering external security.Nearly two-thirds (64%) of insider threats are caused by users who introduce risk due to careless behavior or human error, according to Dark Reading. Whether intentional or inadvertent, would you even know if someone inside your network compromised or leaked sensitive data?Surprisingly, the healthcare industry is the least likely to encrypt its data, according to the Ponemon Institute. Customize your insider threat program to your industry risk, sensitive assets, and organizational risk appetite.
Blog courtesy of Netsurion, which offers the EventTracker security platform. Read more Netsurion guest blogs here.
Insider Threat Definition
Most information security experts agree that employees and vendors form the weakest link when it comes to organizational information security. MSPs, with their trusted advisor role and unfettered access to client systems, are especially susceptible to insider risks and supply chain targeting. A holistic definition of insider threats enables security organizations to better prepare for the largest possible threat vectors that can lead to costly attacks.“An insider threat is any breach that is caused by or facilitated by an insider,
whether it is an accidental insider or malicious insider.”-- Joseph Blankenship, Forrester Research Principal Analyst
Insider Threat Types
Insider threats often remain undetected for months or years, causing lost revenue, disrupted operations, sagging brand reputation, and public distrust. It is important to understand the types of insiders and their motivations to provide context for prevention. According to Security Insider, there are five fundamental types of insider threats:- Non-responders to awareness training
- Inadvertent insiders
- Insider collusion such as with vendor partners
- Persistent malicious insiders
- Disgruntled employees
Align Security Plan to Risk
Traditional approaches such as security awareness training provide a good foundation, but are insufficient given the possible financial motivation and misconfiguration risks by insiders. Some industry sectors pose more internal risk than others, according to the Verizon Data Breach Investigation Report 2019.- The top industry for past breaches caused by insiders: Healthcare
- The second highest sector for internal threats: the high-tech sector with its vast attack surface, cloud infrastructure, and globally dispersed employees and vendors
- The third highest industry: financial services.