Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How to spot the Insider Threat
Articles

How to spot the Insider Threat

ISBuzz TeamBy ISBuzz TeamMarch 19, 2015Updated:July 8, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Sol Cates CSO Vormetric
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When the first revelations of former contractor Edward Snowden came out, it was a watershed moment for the debate on privacy and surveillance. For the data security industry, his actions revealed that insider threats remain all too difficult to detect and prevent. Yet, in the two years since the initial disclosures became public, the message to businesses about their lack of ability to deal with a data breach of this nature is yet to sink in. Indeed, we only need to look to the recent Morgan Stanley data breach to see what happens when yet another ‘trusted’ insider goes rogue.

The threat of an insider tampering with data systems has been a constant worry for IT managers over the years: an assortment of employees or associates of an organisation can either maliciously or accidentally put data at risk. Privileged users or ‘super-users’, however, invariably complicate matters. While their presence is often essential – performing key tasks like software installation, system configuration, user creation, networking, resource allocation and more – having access to private or sensitive information is not. We know that Snowden did not have to do anything extravagant – like bypassing firewalls or hacking into private databases – rather, the weak access control assigned to his policy gave him ‘unfettered access’ to systems and the data stored within them.

Unfortunately, our research confirms that the insider threat landscape is becoming more difficult to deal with as the range of miscreants moves beyond just the risk posed by employees and privileged IT staff. The advent and success of Advanced Persistent Threats (APTs) has led to a worrying spate of breaches wherein the access controls of privileged user accounts are being compromised by malicious outsiders. By hijacking legitimate credentials needed to gain access, illegitimate activities that cause operational harm and steal data can be carried out undetected for a long period of time. Unfortunately, a secret of contemporary system and network technical management is that it is very difficult to identify and track this twofold type of misconduct since sophisticated hackers manipulating the credentials of powerful administrators can create and delete multiple accounts, and even modify security event logs.

Further complicating the situation is that many business partners, suppliers, and contractors are often granted inappropriate access rights, or third-party service providers are being endowed with excessive admin privileges. Unfortunately, unless properly controlled, all of these groups have the opportunity to reach inside corporate networks and steal unprotected data. Encouragingly, however, when asked in our 2015 edition of our annual research into the Insider Threat, carried out by Ovum and Harris Poll, about who poses the biggest internal threat to corporate data, it appears that awareness is growing, albeit not as quickly as one would hope: 55 percent of business respondents globally said ‘privileged users’, 46 percent said ‘contractors and service providers’, and then ‘business partners’ came in at 43 percent.

An interesting point to note is that the research shows UK insider threat concerns are far higher than those expressed by our European neighbour Germany. And, although less worried than the UK (or US) about data breaches, Germany had the highest rates of past data breaches – 27 percent – in the region. Interestingly, though spared the levels of public exposure when a US data breach occurs, forty percent of UK companies revealed they had fallen victim to significant data breach or failed a compliance audit in the last year. And, as a result, 50 percent of UK organisations confirm that they were looking to increase spending on security and data protection in the year ahead. When considering IT security spend to counter the risk posed by insiders a burgeoning issue for businesses to consider is the continued growth of cloud and big data use across enterprise operations. We know that the direction of travel for new applications is predominantly towards choosing a cloud-based alternative rather than upgrading previous-generation on-premise options. Equally, big data strategies are increasingly being introduced to gather analytical intelligence from previously untapped sources. Concerns arise, of course, because the data volumes involved not only grow and become increasingly distributed, but also because there is a general lack of control over origins, provenance and establishing who is reasonable for governance.

While news about the malicious hacking trade and the actions of elusive cyber-criminals continue to grab headlines, it is high-time businesses took heed of the insider threat and put the necessary data protection measures in place to control and monitor the actions of their most powerful users. Encryption technology allied to strong access controls and key management is needed for all important data sources. Further, coupling a data-centric solution with data monitoring or intelligence gathering capability can also be essential to identifying unusual data usage and access patterns that may indicate a problem. While accepting that there continues to be concerns about performance from IT and business users when considering the deployment of data protection solutions, the requirement to keep company data safe – and thus reputation intact – must be the overriding factor.

by Sol Cates, CSO, Vormetric.

About Vormetric

Vormetric

vormetric

Security-conscious enterprises and government agencies turn to Vormetric for protection against both insider threats and the new breed of cyber threats, such as Advanced Persistent Threat (APT) attacks – across their physical, virtual and cloud environments.
The best way to protect what matters is to take a data-centric security approach, implementing access policies with fine-grained controls, deploying advanced encryption, key management and vaulting technologies to lock down critical data and continuously gathering security intelligence to identify emerging issues in real-time.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}