Insider threats are as dangerous as external ones. Watchguard’s Vice President of Identity Carla Roncato asks: Is your organisation ready to mitigate this risk?
External risks, such as cyber scams, ransomware and identity theft, often steal the limelight. Just look at the numbers: our threat lab reports that 105,571 malware attacks have been blocked every day in October 2024, , that’s one incident every second. However, insider threats, while more difficult to detect, can be just as damaging to organisations.
According to data from Statista, insider threats are among the top risks for CISOs and 30% consider them one of the top five most serious cybersecurity risks.
Insider threats can be either intentional, such as data theft or sabotage by disgruntled employees, or unintentional, like accidental data leaks or policy violations.
Employees, contractors, and vendors with insider access can breach security controls, making it easier for malicious actors to gain entry. They can leverage privileges in financial and procurement systems to commit fraud, deliberately or accidentally exfiltrate data, or perform other malicious actions that compromise an organisation’s security.
Of course, implementing proactive measures to mitigate the risks associated with insider threats is crucial to stem this tide.
Expanding attack surface
One of the main drivers of insider threats is the increasing complexity of information technology. As technology grows more sophisticated and more employees access corporate networks, the attack surface expands, making it more difficult for cybersecurity personnel to protect and monitor. The lack of visibility generated by this complexity creates gaps that hackers spot and exploit with ease.
The rise in remote work also makes the task of monitoring daily activities harder and hinders the detection of dishonest behaviour.
Cifas reports that insider threat database (ITD) registrations in the UK increased by 14% in 2023, primarily consisting of dishonest actions by employees (49%), with many organisations citing growing financial pressures as the main trigger.
Against this backdrop, we urge organisations to implement an internal risk management programme, to address the following key areas:
- Policy guidelines: Clearly defining acceptable use of company resources, data handling and consequences of breaches.
- Access controls: Applying role-based controls and the principle of least privilege to ensure that employees only access information they need to perform their role.
- Monitoring and detection: Implementing user activity monitoring tools to identify anomalous behaviour, as well as using machine learning behavioural analytics to detect any deviations from the rules.
- Incident response plan: Designing a plan with specific steps to follow when an insider threat is detected, including the ability to conduct forensic investigations to assess the scope and impact of the incident.
- Culture and training: Fostering a culture of transparency and trust, where employees feel comfortable reporting suspicious activity. Provide training on the risks and consequences of insider fraud and other risky activities.
Addressing insider threats requires an understanding of how external factors, such as AI-driven fraud and social media deception, can influence employee behaviour, making them unwitting risk vectors.
And a rise in increasingly sophisticated phishing campaigns makes it easier to trick employees into sharing information without realising, as these threats are growing more difficult to detect.
Another crucial step businesses should take to safeguard their systems is through strengthening credential protection by implementing multi-factor authentication (MFA).
It is only through a combination of robust technology, ongoing training and proactive vigilance that the risks posed by insider and external threats can be effectively mitigated, ensuring robust organisational resilience in an increasingly complex environment.


Be First to Comment