Protect Your Organisation From Employee Data Theft

Too few organisations pay attention to the risk that their own emplyees present to data secuirity and those that do struggle to undestand how to address the challenge. 

According to the current Verizon Data Breach Investigation Report, the percent of data breaches caused by insiders rose to 34 34% in 2018 from 28% in 2017. With just over one-third of all data breaches caused by insiders, the threat is just too serious to ignore.

Not all employees will take company data, but chances are high that if organisations don’t put proper precautions in place, employees will put valuable dat at risk, either intentionally or accidentally. Having a sound understanding of the threats oraganisations face, how they have evolved and which tactics are most likely to be utilised can prepare them to manage these risks more effectively. 

If companies are going to protect themselves from data loss, they must face two uncomfortable truths:

  • It’s likely that any given company is suffering a data loss or theft from departing employees at this very moment. As many as 72% of departing employees admit to taking company data and 70% of intellectual property theft occurs within the 90 days before an employee’s resignation announcement.  
  • Traditional data loss prevention tactics do not work. Why don’t traditional tactics work? One reason is they rely on employees to classify data, which has never worked. Furthermore, when an employee does run afoul of the company’s policies, the reaction is to block their access to data. That response fundamentally contradicts the collaborative, sharing environments of today’s workplace. Exceptions must then be granted, which leaves the company open to risk of data loss.

For example, although McAfee is considered a leader in data loss prevention the company recently filed a lawsuit against three ex-employees accused of stealing trade secrets and allegedly taking them to a McAfee competitor. In this era where data can be moved with a click, it’s essential that all organisations implement a data loss protection strategy that provides simple, fast detection and response capabilities so that organizations can protect themselves from common data loss by insiders.

Organisations must have this ability to mitigate the risks of costly lawsuits or losing valuable intellectual property to competitors. The core of this effort will be the creation of an enterprise-wide insider data theft policy, which includes employee education. 

Customer lists, engineering designs, research findings and analysis and other data belongs to the company, not the worker. Companies must educate their employees about this and making this clear requires a formal, detailed, written policy on what data employees can take home or with them when they leave and what data must remain.

This policy should be part of new-hire onboarding, security awareness training and employee off-boarding.

Next, make sure to develop indicators of insider data compromise. These indicators will differ from organisation to organisation. The policy should include looking for signs of unusual activity such as an increase in data being transferred, accessing files outside of business hours, or attempts to rename intellectual property something innocuous, such as family photos or music.  

While broad rules are important, it’s just as important to establish rules that focus on file types that are likely to have intellectual property enclosed. This can be CAD renderings for an architectural firm, while for a pharmaceutical company it can be years of drug research. Whatever it is for your business, make sure you can monitor the activity of these files. 

Finally,it’s a misconception that departing employees will steal data after they give notice or in the few days leading up to their last day. In fact, the thefts often occur much sooner, some as early as the day they start to look for a new employer.

Many organisations don’t start monitoring employee use of data until after a staffer has given their notice or has been placed on some type of probationary period. This just isn’t good enough.

It’s best to evaluate their actions going back months before they have given notice.In fact, enterprises should create a process for every time an employee is leaving employment, whether voluntary or not.

This is a process the human resources department should initiate. Most companies have an employee onboarding process, but few have similar processes for departing employees. This needs to change. The departing employee workflow should include not only things like the deprovisioning of access, but also an analysis of their data access activity. If suspicious file movement is detected, it should be referred to HR and/or legal to decide how to respond. 

Putting in place a handful of known best practices can greatly mitigate the danger of the trusted insider. and here are some best practices to prevent breaches:  

Keep it clean. 
Many breaches are a result of poor security hygiene and a lack of attention to detail. Clean up human error where possible, then establish an asset and security baseline around Internet-facing assets like web servers and cloud services. 

Maintain integrity. 
Web application compromises now include code that can capture data entered into web forms. Consider adding le integrity monitoring on payment sites, in addition to patching operating systems and coding payment applications. 

Redouble your efforts. 
2FA everything. Use strong authentication on customer- facing applications, any remote access and cloud-based email. There are examples of 2FA vulnerabilities, but they don’t excuse lack of implementation. 

Be wary of inside jobs. 
Track insider behavior by monitoring and logging access to sensitive data. Make it clear to staff just how good you are at recognising fraudulent transactions. 

Scrub packets. 
Distributed denial of service (DDoS) protection is an essential control for many industries. Guard against non-malicious interruptions with continuous monitoring and capacity planning for traffic spikes. 

Stay socially aware. 
Social attacks are effective ways to capture credentials. Monitor email for links and executables. Give your teams ways to report potential phishing or pretexting. 

While many organisations make the mistake of focusing on the headlines that highlight sophisticated external attackers, they overlook the real risk created by their trusted insiders. Certainly, there’s no foolproof strategy to solve the insider threat problem.

Verizon:             Infosecurity Magazine:      

Top 5 Rules For Laying Out An Employee Cybersecurity Policy:

 

« The Cyberthreat Handbook
False Flag: Russian Hackers Hijack An Iranian Group »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Nuix

Nuix

Nuix specialise in extracting knowledge from unstructured data. Applications include Digital Forensics, Cybersecurity Intelligence, Information Governance, eDiscovery.

BitSight Technologies

BitSight Technologies

BitSight transforms how companies manage information security risk with objective, verifiable and actionable Security Ratings.

Global Cyber Alliance (GCA)

Global Cyber Alliance (GCA)

Global Cyber Alliance is an international, cross-sector effort dedicated to eradicating cyber risk and improving our connected world.

ICTSecurity Portal - Austria

ICTSecurity Portal - Austria

The ICTSecurity Portal is an interministerial initiative in cooperation with the Austrian economy and acts as a central internet portal for topics related to security in the digital world.

Cyber Security Malta

Cyber Security Malta

Cyber Security Malta is part of Malta's National Cyber Security Strategy which aims to combat cybercrime, strengthen national cyber defence and provide cyber security awareness and education.

UNIDIR Cyber Policy Portal

UNIDIR Cyber Policy Portal

The UNIDIR Cyber Policy Portal is an online reference tool that maps the cybersecurity and cybersecurity-related policy landscape.

Network Center Inc (NCI)

Network Center Inc (NCI)

NCI is one of the largest IT solution providers in the Midwest. We specialize in industry specific technology solutions, service, support, and expertise for small to enterprise businesses.

SecureStack

SecureStack

SecureStack helps software developers find security & scalability gaps in their web applications and offers ways to fix those gaps without forcing those developers to become security experts.

YorCyberSec

YorCyberSec

YorCyberSec act as a trusted Cyber and Information Security broker and procurement specialist. We help companies to Reduce Risk, Increase Assurance and Improve Performance.

Abu Dhabi Gov Digital

Abu Dhabi Gov Digital

Gov Digital (formerly Abu Dhabi Digital Authority - ADDA) enable, support and deliver a digital government that is proactive, personalised, collaborative and secure.

Chartered Institute of Information Security (CIISec)

Chartered Institute of Information Security (CIISec)

CIISec is dedicated to helping individuals and organisations develop capability and competency in cyber security.

RMRF Tech

RMRF Tech

RMRF is a team of cybersecurity engineers and penetration testers which specializes in the development of solutions for early cyber threat detection and prevention.

MyCISO

MyCISO

MyCISO is the World’s first SaaS application that will vastly simplify security management for all.

e-Xpert Solutions

e-Xpert Solutions

e-Xpert Solutions is a company specialized in the Information Security field since 2001. Our skills are strong technical expertise and the development of tailor-made solutions.

G-71

G-71

G-71 LeaksID is a cutting-edge ITM technology aimed at safeguarding sensitive documents from insider threats.

Blue Bastion

Blue Bastion

Don’t give cybercriminals the chance to find weaknesses in your company’s cyber security system. Defend your institution from all attacks from all directions with Blue Bastion.