Creating a security awareness program

In this Information Security Threats Ask the Expert Q&A, Ed Skoudis explains how creating a security awareness program can help thwart the insider threat.

I am working on a security awareness and internal security program. Where can I find statistical information on insider threats, lost laptops, etc?
There are periodic surveys about these problems. The following three surveys are good sources to start with:

  • Insider Threat Statistics:

  • 'Insider Threat' Study Reveals That Trusted Employees Are Exposing Co-Workers' Personal Information:

  • Beware of insider threats to your security:

    Each survey describes the persistent and pernicious insider problem of many employees inadvertently or purposely putting their organizations at risk. However, these surveys can be inconsistent, especially the ones that compare the number of external attacks to internal attacks (from employees, etc.). Some surveys show a huge number of external attacks, while others show a preponderance of the latter.

    When discussing this threat with management, emphasize the need to defend against both insiders and outsiders, and how to leverage some tools across both threats, while using other tools that focus predominantly on one or the other. If you put all of your defensive eggs in the outsider threat basket, your organization could be in serious peril. Thus, a blended approach is vital.

  • This was last published in August 2006

