How to fight the three kinds of insider threat

By

Kevin Coleman

and

Independent Software

CACI-ISS has been awarded a Navy contract to provide technical services for command, control, communications, computers, intelligence, (C4I) surveillance and reconnaissance electronic projects. (Navy)

External threats to the systems and information assets of organizations have become the norm in cyber security. Today, more and more of those responsible for cyber security are increasing their attention on the threats emanating from inside of their organizations. Insider threats have been a significant challenge for a number of years now. The attention to this multifaceted threat increased significantly after Edward Snowden’s disclosure of National Security Agency activities. This has even led the private sector to sit up and take notice of insider threats within their organizations. The largest number of insider risks are in three distinct areas:

  1. The Malicious Insider Threat.
  2. The Casual Insider Threat.
  3. The Accidental Insider Threat.

Here is an actual example of each of the three types.

Malicious: A contract employee was hired in the IT department to assist with a temporary increase in workload. After a few weeks some suspicious activity was noticed and an investigation began. The security department digitally documented the contract employee copying large amounts of company data and transferring it via FTP to a remote server that was later determined to be one that he had set up. The individual was arrested and it was later discovered that he had done similar things before and had a criminal record. The company thought the contract resource firm had done a background investigation prior to providing the resources to the company. The contract employment firm thought the company would conduct the background investigation prior to accepting the employee.

Casual: An employee assigned to client management and support received an offer from a competitor. The employee accepted that offer and gave the customary two-week notice. During that period, the employee copied the client account profile information and emailed it to a personal email account. When asked about this, the employee explained it as a desire to keep in contact with the individuals with whom a good relationship had developed over the years. While that fits the definition of theft of corporate data, a study found that a substantial percentage of individuals do similar things and see nothing wrong with it.

Accidental: An employee working for a company that adopted a “bring your own device” policy routinely accessed sensitive corporate information and also received it via email. Some of those files were opened and stored on the employee’s device. The employee backed up the device to a home PC. When this was done some of their employer’s digital assets were backed-up as well! When the employee’s personal PC was compromised, the corporate information was taken. As the employee docked the device, it was backed up on an ongoing basis and that data was exfiltrated. The employee had no malicious intent and was actually compliant with the organization’s policies.

As the world becomes more data intensive, the treasure chest of digital assets and the value of data continues to increase, It is a sure bet that insiders of all persuasions will be more drawn to obtaining this corporate property. Some in the private sector address the threat head-on while others have chosen to deflect attention to the damaging actions of insiders.

Examples of deflection: One insider incident was labeled a “data leak” and others were called “data spills.” This seems to be an effort to get away from all the attention data breaches receive today. Changing what we call these increasingly damaging thefts does nothing to address the problem.

Organizations must create a formal program to address the multiple facets of insider threats. All too often the cyber security department shies away from what is necessary to properly address this problem – an enterprise approach that integrates other parts of their organization. That is critical to properly address this threat. The insider threat is far more expansive than many organizations realize!