Interviews

Insider threats

by Mark Rowe

A European ‘Insider Threat’ survey, done in 2014 for Vormetric by industry analyst firm Ovum. found that only nine percent of businesses feel safe from insider threats, with nearly half of UK based respondents (42 percent) acknowledging that it is ‘privileged users’ (system administrators, database administrators, network administrators, etc.) that pose the biggest risk to their organisation. The survey was of more than 500 IT decision-makers at mid and large size organisations in the UK, France and Germany,

According to the firms, insider threats are no longer only traditional insiders with legitimate access rights who abuse their positions to steal data for personal gain. Privileged users who maintain systems and networks are now another concern, as their roles typically require access to all data accessible from systems to perform their work. A third insider threat concern is from the outside-in, with cybercriminals actively seeking to compromise insider accounts (focusing most heavily on privileged users) in order to infiltrate systems and steal data using their credentials.

Andrew Kellett, Principal Analyst at Ovum, the analyst firm which conducted the study, said: “Almost half of European organisations believe that insider threats are now more difficult to detect, with senior IT managers being very worried about the things their own users can do with corporate data. This risk is compounded by the threat by cyber attacks that are targeting user accounts – something that is not going completely unrecognised as 30 percent of organisations cite Advanced Persistent Threats as a primary driver for ramping-up data breach defences.”

Findings of the Ovum survey include:

· Only nine percent of all organisations surveyed feel safe from insider threats and only six percent of UK organisations feel safe;

· 47 percent of organisations now find it harder to detect insider threat incidents than in 2012;

· Controlling access to data poses a broad threat for organisations. For some, non-technical employees with legitimate access to sensitive data and IT assets are the biggest risk (49 percent), while for others even executive management such as the CFO or CEO are the top risk (29 percent);

· Cloud implementations are raising security issues, with the lack of visibility into security measures around cloud-hosted data representing a concern for 62 percent of businesses;

· Big data also poses a risk, with over half (53 percent) of organisations being concerned over the security of big data reports that may contain sensitive data;

· There is some good news: organisations are taking steps to address insider threats, with 66 percent planning to increase IT security budgets as a direct response to this risk.

Daniele Catteddu, Managing Director EMEA for Cloud Security Alliance, said: “Enterprises grow their use of cloud computing to take advantage of the business flexibility and financial advantages it brings. The research shows that they feel that there are additional security risks from this growth, and details how cloud providers can enhance their offerings to better meet enterprise security needs for offsetting insider threats.”

Stewart Room partner in Field Fisher Waterhouse’s Technology and Outsourcing Group, said: “Clearly, compliance requirements, privacy regulations and ongoing data breaches are having a strong effect on organisations. With 66 percent planning to expand IT security spending to offset insider threats, and the challenges they are seeing with protecting data within cloud, mobile and big data environments, enterprises are seeing that their security posture needs to be updated, and are taking steps to do so.”

And, organisations are beginning to recognise that encryption is the most effective technology in preventing insider threats, with the largest proportion of organisations (38 percent) citing it as the single most important security measure.

Alan Kessler, CEO for Vormetric, said: “Despite the growing frequency of insider threat related incidents in the news, the report shows that organisations are still at the early stages of managing this data loss vector. Results show a growing awareness of insider threats, but the rapid growth of sensitive information within organisations, and the use of new technologies such as Cloud and Big Data, makes the prospect of securing data with a growing number of point solutions expensive, operationally complex and an impediment for rolling out new services. With these new technologies, and with the growth of both outside-in threats such as APTs, traditional end point protections and network perimeter security simply aren’t effective. To practically defend themselves, organisations must take a data centric approach, implementing encryption and access controls to limit exposure, and monitoring data access to identify inappropriate user activity using a platform approach that scales with growing data security mandates and requirements without diverting an inordinate amount of IT resources.”

To find out more about the risks posed by insider threats and for more findings from the research: http://bit.ly/1nYr41d

Related News

  • Interviews

    Cyber predictions

    by Mark Rowe

    The year 2017 has been eventful for cyber-security. What of 2018? Simon Bain, CEO of security for IoT product company BOHH Labs,…

  • Interviews

    Victim support

    by Mark Rowe

    Justice, where art thou? One of the problems in answering that question in this country is the very meaning of what people…

  • Interviews

    IT threat overview

    by Mark Rowe

    An IT security firm reports that it detected and blocked more than 1.5 billion web-based attacks and more than 3 billion infected…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing