Insider Threats – What You Don’t Want to Think About October 22, 2024 – Posted in: Cyber Security, IT Support – Tags: , , ,

You have done all the right things to secure your data. You’ve implemented all the recommendations to protect your perimeter and keep the bad actors out, you’ve made sure everything is up to date, you’ve paid for the AntiVirus software that’ll protect you in case something slips past the outer defences. There is one more threat though. One that no-one wants to think about. The insider.

The Insider Threat

Your staff are your greatest asset. You chose them. You may have directly trained them. You want to trust them. And for the most part you can, but you cannot be certain and you need to protect your business. You might have seen the recent (Oct-2024) article from the BBC on an insider attack made by an employee at TikTok who tried to – and possibly succeeded in – compromising their multi-million dollar AI project. Even such a large company with layers of security can fall foul of the insider attack.

Insider attacks are the most expensive and devastating, though thankfully far from the most common, form of cyber attack.

What Can You Do

Once you’ve put in place policies to explain to your staff what they can and can’t send to who, how they can use (or not use) USB sticks and you’ve provided training to reduce the chance of someone making a mistake you are left with deliberate attacks. These might be malicious or they might be desperate. Blackmail and threats are becoming more and more common. Some as simple as the spam emails that claim to have images from you from a webcam and threaten to release it – easy enough to debunk if you don’t have a webcam – or as complex as a directed catfishing to obtain personal details for blackmail.

The only way to protect yourself from this kind of attack is to set up your systems on the principle of least privilege. The idea is that you give each person, no matter their seniority, access to only what they need access to in order to do their job. This not only protects you in the case of a potential insider attack, but it also protects you if a malicious actor gains access to someone’s credentials and accounts. By making sure no-one has access to what they don’t need you limit the potential damage they can do and the data they can leak. Any access to a dataset constitutes a risk – if that risk is offset by the requirement to complete a task then it is a risk worth taking. If there is no requirement to access the data, the risk is absolutely not worth taking.

If you need help protecting your business, developing an appropriate access system or would like to discuss any other IT Support needs you might have please give us a call on 01245 265100 or email us at .