Creating a security awareness program
I am working on a security awareness and internal security program. Where can I find statistical information on insider threats, lost laptops, etc?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

There are periodic surveys about these problems. The following three surveys are good sources to start with:

  • Insider Threat Statistics:
    http://www.schneier.com/blog/archives/2005/12/insider_threat.html

  • 'Insider Threat' Study Reveals That Trusted Employees Are Exposing Co-Workers' Personal Information:
    http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&STORY=/www/story/08-22-2005/0004091867&EDATE

  • Beware of insider threats to your security:
    http://www.viack.com/_download/200408_cdm.pdf

    Each survey describes the persistent and pernicious insider problem of many employees inadvertently or purposely putting their organizations at risk. However, these surveys can be inconsistent, especially the ones that compare the number of external attacks to internal attacks (from employees, etc.). Some surveys show a huge number of external attacks, while others show a preponderance of the latter.

    When discussing this threat with management, emphasize the need to defend against both insiders and outsiders, and how to leverage some tools across both threats, while using other tools that focus predominantly on one or the other. If you put all of your defensive eggs in the outsider threat basket, your organization could be in serious peril. Thus, a blended approach is vital.

    More Information

  • Review five common insider threats and learn how to mitigate them.
  • Learn how to thwart insider threats.
  • This was first published in August 2006