Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Hapless User: Secure from the inside out
Articles

The Hapless User: Secure from the inside out

ISBuzz TeamBy ISBuzz TeamNovember 20, 2017Updated:November 20, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
UK’s Best Cyber Security Talent
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The current cyber-threat landscape is increasingly complex, with cyber-attacks becoming far more widespread, sophisticated and more straightforward to execute. In such an environment, organisations face a catch-22 situation: it’s becoming harder to detect hidden threats early, yet early detection is essential to mitigating the loss of confidential and sensitive data – not to mention the damage to a brand’s reputation.

Over the past few years, we’ve seen several high-profile organisations succumb to crippling security breaches. Each incident acts as a reminder that malicious attackers do not discriminate and no organisation is safe, no matter the size or industry. What’s more, it’s become abundantly clear that there will always be cyber-criminals intent on causing harm to businesses and individuals, whether for monetary gain or personal incentive, such as influencing a politically-focused event.

Organisations are starting to wake up and move security higher up the priority list. Companies are beginning to invest in more sophisticated security solutions – focusing on preventing external threats – to help negate the chances of hitting the headlines for the wrong reasons. However, while this is obviously a step in the right direction, it’s only one piece of a much larger and more complicated puzzle.

An inside job

Not enough attention is paid to those within an organisation that could potentially pose a security threat. According to a recent IDC study looking at business views on security breaches, only 12 per cent of respondents were worried about the threat posed by an insider. However, employees are responsible for almost half of all data breaches that happen today. So, why is there such a disconnect?

The disparity is concerning in itself. Insider threats should be equal to, if not more of a concern to organisations than external threats, simply because they threaten both customer and employee trust. Moreover, insiders have privileged access to extremely valuable and often sensitive data in order to carry out their jobs in the most efficient way possible. This makes it more difficult to detect suspicious activity and anomalies on the system.

Despite this, there is still a level of reluctance by organisations to invest appropriately in tools to address the insider threat. Organisations often perceive individual device-level monitoring to be extremely expensive, with a tendency to foster an atmosphere of distrust among staff. Additionally, if a substantial amount of focus is being placed on individuals, businesses feel that it often fails to provide a holistic view of risky behaviour.  Businesses are focusing more on investing in technologies designed to protect a more traditional network-based perimeter, as opposed to one that is focused on detection and response.

Whether an enterprise faces a sophisticated Advanced Persistent Threat (APT) or insider threat, indications of breaches can be gathered by analysing data. The aggregation and collection of data has never been more crucial. If an organisation can glean its data from all IT systems and applications and correlate it, valuable insights that help to differentiate between normal and abnormal behaviour can be used to uncover even the most concealed breaches.

Culture shock 

At a cultural level, there must be a conscious effort to shift focus away from the outcome of a breach to concentrate on the issue’s source – user behaviour. When users are educated about safe data management practices and IT managers can audit their progress, the company stands a significantly improved chance of warding off threats.

Having the ability to conduct real-time analysis of user behaviour and machine-generated data can aid in detecting a potential breach, whether accidental or intentional. It enables precautions to be implemented, procedures to be executed, and in turn, a substantial amount of damage to be mitigated. Responding to an anomaly immediately demonstrates the organisation’s competence to both identify and deal with cyber-threats. Moreover, it can serve as a constructive way of educating the user community in spotting a potential breach and figuring out a way to deal with it, as well as retaining customer trust in your organisation.

Businesses should be allocating more resources to identifying the hapless users within their organisation and ensuring that they educate them with behaviours that exemplify a solid security strategy. If security is embraced as a part of the corporate culture throughout an organisation, maybe then we’ll start to see improvements and a reduction in the number of security breaches.

[su_box title=”About Matthias Maier” style=”noise” box_color=”#336588″][short_info id=’103681′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}