ITensure IT-Services Cybersecurity Insider-Threats

Insider threats are becoming more frequent, trickier to detect, more damaging, and more costly. You are not alone. Cybersecurity Insiders states that 68% of organizations feel vulnerable to insider attacks.

§ There are 5 well-known insider threat incidents published in 2020:

Shopify data breach — Two Shopify support team members abused their access rights to obtain customer transaction records from merchants. The data contained customers’ personally identifiable information.
öö Damage: 1.27% drop in Shopify’s stock price.

Insider trading at Amazon — The senior manager of Amazon’s tax department was found to have been disclosing Amazon’s confidential financial data to family members so they could trade on it.
öö Damage: Bad publicity due to insider trading.

Stradis Healthcare attack — The ex-vice president of finance at Stradis Healthcare was accused of gaining unauthorized access to the Stradis Healthcare package shipping system. He modified and deleted documents on the shipments of personal protective equipment for medics.
öö Damage: Cost to restore data and renew operations. Delay in supporting COVID-19 pandemic management.

Twitter hack — Hackers conducted a chain social engineering attack on Twitter employees, stole their credentials, and gained access to the Twitter administrator tool. Then the attackers posted scam messages on over 130 popular profiles and got $180,000 from Twitter users before the company’s cybersecurity team sealed the breach.
öö Damage: 4% fall in Twitter’s stock price.

An attempted attack on Tesla — A Tesla employee rejected a bribe of $1 million to install malware and cooperated with the FBI to investigate the case.
öö Damage: Tesla is lucky of this time.

§ The types of people in the organization who are most likely to present or introduce an inside threat:

Privileged users and administrators — These users hold the keys to the organization’s infrastructure and sensitive data and to detect.

Regular employees — Regular users can misuse corporate data, install unauthorized applications, send confidential emails to the wrong address, become victims of a phishing attack, etc.

Third parties and temporary workers — Vendors, business partners, and temps may evade cybersecurity rules and practices or may violate them unknowingly. Hackers gain inside access via a low-level security third-party vendor.

Privileged business users and executives — Company executives can abuse their privileges, access, and knowledge for insider trading, personal gain, or corporate or government espionage.

§ How to manage Insider Threats?

Businesses can take advantage of automated insider risk management tools and solutions. With the right tools, a company will monitor and detect abnormal behaviors in real-time and keep records for later analysis.

An insider risk management solution can:

Identify any abnormal behavior – detects unusual activity and report unexpected behavior. There are tools based on artificial intelligence or machine learning and help see and act on the earliest indicators.

Manage the access of sensitive resources for privileged users. Include manual access approval procedures and multi-factor authentication.

Effective user training can increase employees’ awareness of threats, reduce the number of incidents caused by negligence, and give users enough knowledge to recognize and report the risks.

Participate in community threat intelligence sharing to identify and exchange detected risks and attacks between organizations. It allows companies to prepare for possible threats and help each other with investigations.

Before working with vendors, assess their cybersecurity levels, know their employees’ access, and use sensitive data. Establish the responsibilities and practices to follow. Continue to monitor vendors’ activities.

With appropriate procedures and tools in place, the goal is to identify, respond to an insider threat and mitigate it before it leads to considerable damage.

WE ARE HERE TO PREVENT, PROTECT, EDUCATE.

How Can We Help?

Susie Chow – ITensure
Call/Text: (714)633-9454