Home > Security News > Insider security threats come in many forms
Security News:
EMAIL THIS

Insider security threats come in many forms

By Bill Brenner, Senior News Writer
21 Nov 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

As far as Kerry Anderson is concerned, insiders are as big a threat to her company's IT security as worms and spyware -- perhaps bigger. And like malware, insiders come in many variants.
Companies need to make it clear to their employees from day one that they are being monitored.
Kerry Anderson,
vice president, information security group, FMR Corp.

Anderson, a vice president in the information security group at Fidelity Investments Brokerage Company, explained the different types of insider threats and ways companies can address them at the MIS Training Institute's Annual Conference and Expo on Control and Audit of Information Technology in Boston last week. The best way to deal with any potential inside threat, she said, is to let everyone know Big Brother is watching them and that they can be fired for any security violation.

"Companies need to make it clear to their employees from day one that they are being monitored," she said.

Anderson has seen a variety of troublesome insiders in her career at Fidelity and other companies. There's the saboteur who tries to deface critical company data because they have an axe to grind against their bosses or fellow co-workers.

Then there's the sole living expert -- someone who has been around so long they think they own the network. They want everyone to be dependent on them, so they manipulate the network in a way to make other employees come to them to access certain pieces of data or perform certain network functions, Anderson said.
Insider threats:
Five common insider threats and how to mitigate them

Thwarting insider threats


Downloads: Proven Tactics to Repel Emerging Threats

Learning guide: Insider Risk Management Guide: Audit

Anderson has also come across people who have what she calls the hero syndrome. They break something on the network so they can fix it and be seen as life savers.

"If something is breaking every three weeks and the same person is fixing it, I'd start taking a look at them," she said.

Whatever the insider's tactics or motives may be, Anderson said there are some common warning signs to look for, such as someone who isn't getting along with managers or co-workers and may be preparing to leave the company. If someone is leaving under unhappy circumstances, there's always the chance they could sabotage network data on the way out the door, she said.

Companies must also keep an eye on people who may start working hours when nobody else is around. Anyone who suddenly changes their normal work routine bears watching, Anderson said.

Companies must also be prepared to deal with people who create security risks without necessarily meaning to. If the network suffers a security breach because an employee was visiting seedy Web sites on company machinery, for example, there must be a plan for punishment.

"People need to understand that their computers are for business only and that they can be disciplined or even fired for using them for anything that isn't business related," Anderson said.

IT security professionals also need to watch for personal technology that could put the company at risk, she said. Cell phones with embedded cameras, for example, could be used to photograph and transmit sensitive data.

While these are important steps, Anderson acknowledged that companies can't prevent every insider-related incident.

"A lot of internal fraud goes unreported because it's embarrassing," she said.

If there is a security breach, companies must be honest about it and come clean publicly, she said. Otherwise, the company's reputation and the security of their customers could take a bigger hit later.

Tags: Identity Theft and Data Security BreachesVulnerability Risk AssessmentEnterprise Risk Management: Metrics and AssessmentsInformation Security Policies, Procedures and GuidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Identity Theft and Data Security Breaches
Researchers predict SSNs, crack algorithm putting identities at risk
TJX to pay $9.75 million for data breach investigations
Man pleads guilty in online banking hacking scam
White House cybersecurity czar faces major hurdles
Heartland breach cost $12.6 million, CEO says
An inside look at security log management forensics investigations
LexisNexis investigates breach, notifies thousands
Senators hear call for federal cybersecurity restructuring
Former Federal Reserve Bank employee arrested
Attackers cash in on fundamental data handling mistakes, Verizon finds

Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

Enterprise Risk Management: Metrics and Assessments
Align your data protection efforts with GRC
The basics of enterprise GRC project management
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Mature SIMs do more than log aggregation and correlation
Risk management must include physical-logical security convergence
New partnerships, creative thinking help security bust recession
Security budgets take hit in media, tech industry, survey finds
Service-focused security offers best value to organization
Ease the compliance burden with automation
Enterprise Risk Management: Metrics and Assessments Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts