Home > Ask the Security Experts > Expert Archive: Security Management Questions & Answers > Is insider activity or outsider activity a bigger enterprise threat?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is insider activity or outsider activity a bigger enterprise threat?

Mike Rothman, past SearchSecurity.com expert EXPERT RESPONSE FROM: Mike Rothman, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 09 September 2008
In Verizon's 2008 Data Breach Investigations Report, I read that 73% of data breaches involved outside activity. Most security pros I talk to consider insider activity to be the biggest threat. Do you think this perception -- and subsequent over-focus on inside activity -- could be partly responsible for so many breaches?


BROWSE BY TAG
Expert Archive: Security Management,   Identity Theft and Data Security Breaches,   Enterprise Data Protection,   Information Security Management,   Security Awareness Training and Internal Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Expert Archive: Security Management
What is the GISP certification and how does it compare to the CISSP certification?
Using a QSA to write up a PCI DSS report on compliance (ROC)
How can gap analysis be applied to the security SDLC?
Comparing cheap security products and appliances to costly appliances
What are some tips on protecting my security budget in a poor economy?
What value do research firms provide to their subscribing enterprises?
What certificate offers the best ROI for an IT project manager?
How does information security prevent fraud in the enterprise?
Differences between an SAS 70 data center and a Tier III data center
What does the future of the endpoint encryption market look like?

Identity Theft and Data Security Breaches
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy

Security Awareness Training and Internal Threats
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management
Data breach avoidance begins with security basics, panel says

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Don't read too much into the data that Verizon released early this year. There were some interesting aspects of the study, but it's important not to draw generic conclusions. (There aren't many generic environments, so trying to use generic data to make decisions is pretty dangerous.)

The distinction between insiders and outsiders isn't very useful. Security pros just shouldn't trust anyone. Proper controls must be in place to protect data from both internal and external attack vectors. Whether the right number is 73% or 27% doesn't matter if an insider has created a breach. Or an outsider, for that matter.

Reading deeper into the Verizon report (pdf), it's clear that many of the breaches could have been avoided by updating devices on a timely basis and making sure configurations were locked down. Again, both of these issues are pretty simple security practices. People should focus on protecting important data rather than making artificial delineations between insiders and outsiders.

The last point is that Verizon's data set is skewed toward outsiders. Many insider attacks are never reported, nor do they bring in fancy forensic investigators (like Verizon) to clean up the mess. Yet, when the breach happens from outside, organizations usually have to disclose and tend to bring in outside experts.

Verizon's study definitely has value; it's opened up the eyes of a lot of people. But it's important to put it in the proper frame of reference and make sure to draw the right conclusions.

More information:




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts