Stop and think for a moment: What have you done that makes you an insider threat?
The digital environment we live and work in is rapidly expanding and dramatically increasing the amount of information users can access. That's why in today’s organization, insiders pose a vast array of threats that must be continuously evaluated and properly addressed. That being said, Not all insider threats are technologically oriented or require hacking or software knowledge and skills, and even more concerning is the rise of non-malicious insiders that pose a threat to our digital assets.
STAT: In one recent survey, nearly 90 percent of organizations asked believe they are vulnerable to insider threats. Approximately 34 percent felt they were extremely or very vulnerable.
One recent survey found that over half of those asked said they were planning on increasing funding to the threat from insiders. While that is an encouraging figure, where they spend the money will be the telling factor. Many organizations have already invested in identity management and access control; however, that does not mean those issues are properly addressed.
Access control and identity management are essential components in an organization’s insider threat risk management program. That being said, There is a common void that has been identified that is often overlooked in many organizations. The point of vulnerability is the multifunction (copier, printer, fax machine and scanner) device.
The following two incidents exemplify reflect one of the more common issues that involve access control and identity management.
INCIDENTS: The first multifunction device incident took place when documents that were sent to the device and received by the device were all stored on the internal storage of the multifunction device. The device did not require a user to enter in their user ID and password to access it the device. Because of that shortfall, anyone with physical access to the device could access, and print or email any document that was sent to it the device and was not deleted by the user or administrator.
The second incident involving a multifunction device was very troubling. Many organizations lease or rent the devices, and at the end of the agreement lease or rental returns it to the company that owns the device and leases/rents it out. One of the devices that had been returned was sold online as a refurbished device. It was purchased and put into operation in a training facility. Once it was in operation, the new owner discovered 1,000 documents that were still present and stored on the device. Based on those documents, the device was clearly located in a human resources department of a large company. It was packed with sensitive personal identifying information PII and protected health information PHI.
In both of these incidents, anyone who could physically access these devices had instant access to all the information that was sent to and stored on the device. It should be noted that some producers of multifunction devices have integrated biometric (fingerprint) identification and access control on their equipment. Often, that requires an integration of physical and digital controls.
Make no mistake about it, the threat posed by insiders is present in every organization, which That makes addressing this threat essential. However, reducing the risk of insider threats is a very complex undertaking. This multifaceted threat consists of malicious insiders, uneducated insiders, careless and negligent insiders and a spectrum of actors.
ClearlyThere is no one universal answer or solution that addresses all aspects of this issue. The only thing that seems to be universal is recognition that insiders pose the greatest risk to cyber security since they are trusted and given access to our information assets. Behavioral modeling coupled with biometrics (facial recognition and fingerprint identification) seems to be a combination that holds the greatest promise of addressing the challenge — but as this continues to evolve, we will see more preemptive cyber security systems.








