Should I be concerned?

With technology being a part of our professional lives, it is important to be educated as knowledge is definitely power when using technology in the workplace. This week, let’s look at insider threats.
An insider threat is when someone with legitimate access to company systems or information misuses that access in a way that harms the organization, intentionally or negligently. Insider threats may include employees, contractors, vendors, or partners.
Insider threats may result from malicious intent or negligence, causing data breaches, financial losses, loss of confidential information or customer trust, and legal consequences. Even small security gaps, such as unnecessary file or folder access, can make it easier for someone to steal or misuse sensitive information.
Insider threats happen for various reasons. Some act for financial gain or out of frustration, while others simply take shortcuts or ignore security rules, exposing sensitive information. It is everyone’s responsibility to minimize risk due to insider threats.
Next, we’ll take a look at some of the most common types of insider threats. Remember, your first action should be to report anything suspicious immediately.
Malicious insiders are those who may believe they’ve been wronged in some way either by the business, the boss or even a fellow worker. They can also be motivated by financial gain and decide to act on it. These acts are intentional and include leaking/deleting sensitive information, selling credentials or engaging in other types of sabotage.
Acts of negligence are more common than those of malice, yet both pose severe risks. Unintentionally leaving a laptop unlocked, setting a Dropbox or Google Drive folder to “publicly accessible,” or sending confidential data on an unsecured device may have serious consequences.
Any employee leaving the business can pose a major threat by stealing sensitive data or intellectual property or by engaging in other harmful activities.
Some employees may find security policies overwhelming at times. As a result, they may take steps to circumvent critical security controls. Circumventing these controls can increase your business’ risk of a cyberattackor worse.
If an outside group targets your business (like we have seen recently with Banks and telecommunication companies), they may exploit an employee’s unique privileges. The employee involved may be tricked or coerced, through bribery or blackmail, into acting as an insider threat.
External vendors, contractors, and consultants may be granted access to sensitive data, and may not always have your company’s best interests in mind.
While motivations vary, the specific harm caused by an insider threat typically falls into one of these four categories:
You should only provide access to anyone in your business with the information and systems necessary for the role.
When access is too broad:
Limiting access helps reduce the risk of insider threats.
Insider Threats sometimes involve warning signs that coworkers may notice. Behaviors like these display suspicious activity patterns that deserve immediate reporting and should never be ignored. Here are some to look out for:
1. Accessing files unrelated to the person’s role;
2. Downloading or copying large amounts of data;
3. Attempting to bypass security rules;
4. Expressing frustration within the business while seeking sensitive information;
Controls help prevent an insider threat from causing harm by blocking actions through methods such as:
Ensuring employees only have access to the specific files needed for their role.
Using Multi-Factor Authentication to ensure a stolen password isn’t enough to get in, and locking computers automatically after a set amount of time unused.
Using security features to monitor and block the unauthorized transfer of sensitive data, while automatically detecting and preventing the movement of confidential information beyond organizational boundaries.
Procedural controls help enhance security with policies that guide employee behaviour and reporting, like:
Never leave passwords written in notepads, post-it notes or books – even if you think you have a clever system to hide them in unlocked drawers.
Having a safe, confidential way to flag suspicious behaviour.
If you see someone engaging in malicious activity, report it so it can be addressed quickly. Report the incident immediately, even if you think it may have been unintentional.
Everyone in your business relies on each other to stay safe and secure. Ensure that everyone plays their part by staying alert to suspicious activity and reporting concerns immediately, even if they seem unintentional. You may wish to share this newsletter with ALL employees, regardless of role, to ensure all are educated.
Here at Shorlink, we have high-level encrypted protocols in place to ensure protection for our business and our clients. You should too!
We strongly recommend reviewing your security protocols to ensure that same standard of security is shared yourself. Also, ensure your IT knowledge and education is updated to serve your business the best.
Also, your business should have a safe and confidential process for reporting potential insider threats. Communication of these processes and personnel is critical for keeping your organization safe.
Ignoring what you believe to be minor, can lead to catastrophic results! If something doesn’t feel right, ensure that you communicate with the appropriate staff so they can help.
Report unusual behaviour! Proof isn’t needed! Early reporting helps investigations and prevent potential insider threats.
If you are concerned, and unsure what steps to take, please contact Wayne in the office on (07) 4242 1412 to discuss further.