Facing the reality of internal risk: Thwarting insider threats

When we think about IT saboteurs, most of us picture a professional cyber-criminal or hacker bent on stealing confidential information or wreaking havoc. In both cases, the perpetrator is an outside party who breaches the data network of a company, institution, or government entity with malicious intent.

In response to this perception, companies have implemented layers of physical and IT security around the perimeter of their organisations—and yet we are still vulnerable as evidenced by the number of IT incursions we see every day.

Truth is, the reality of IT sabotage is more complex. Forrester Research highlighted in a 2007 report that approximately 70 percent of all data theft is from internal sources – a staggering figure. The trading scandal at Societe Generale in France in early 2008 cost the company an estimated US$7.5 billion, and is the latest headline-grabbing example of how lax security and poor password management can be exploited from within.

In recent years, advances in perimeter security technology—such as packet filters and intrusion prevention and detection tools—have enabled organisations to reduce the risk of external network attacks. However, most companies have done little to counter internal threats—threats that can be even more damaging to a company’s business and reputation, exposing lax policies and inadequate management. To add insult to injury, insider threats are perpetrated by people who at some point were either employed and/or considered trusted by the organisation.

You must be a registered member to access this content.
Please Sign in below or Register now.
NOTE: This Feature is more than 7 days old.
Please login to view the rest of this article

Registered users may log in here.

Login or Register now and get unlimited access.


Why sign up?
  • Unlimited access to SC Magazine content as well as access to to our global resources from SC Magazine US and UK editions.
  • Full use of over 11,000 articles database covering breaking news, video interviews, case studies, research, product reviews and exclusive features with fast and intuitive filtering of results.
  • Personalised "Recommended for you" filters to ensure you have the most relevant content at your finger tips.
  • Daily security bulletin direct to your inbox covering the latest security news from Australia/NZ and around the world.

Register now, its free! We'll never sell your details to third parties and it helps SC Magazine to keep serving you quality stories.
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read