Protecting Your Company’s Data Against Insider Threats

Perhaps because of their incredible scope or their shocking prevalence, data breaches are creating a lot of general  interest.  It seems that a new event happens every week and even though companies rightly fear an attack from an external source, internal threats pose a hidden risk, accounting for a substantial number of data breaches.

While we hear about major incidents in the media, the truth is that no business is immune from the danger of insider threats. Fortunately, companies are quickly recognising this new dynamic.

According to a recent report by CA Technologies, 90% of organisations feel vulnerable to insider attacks. Indeed, the financial impact, the loss of core IPs, and the damage to brand reputation are cascading problems that can shake the very foundation of any SME.

However, since insiders, including employees, suppliers, and partners, are already in the organisation’s trusted network, standard cybersecurity measures usually designed to defend against outside attacks aren’t adequate to protect the organisation from these accidental or malicious “enemies within.”
 
Therefore, organisations need to look into user activity and behavior monitoring and adopt a user-behavior driven data loss prevention strategy to effectively defend against insider threats. Here are ten tips to develop an insider threat prevention strategy:

1. Implement a Risk Assessment Methodology

When it comes to data security, operating without a plan is most certainly planning to fail. In today’s digital environment where data breaches and leaks are uncomfortably common, every organisation needs a holistic approach to data security.

In other words, the only way to effectively protect data is to analyse and evaluate every aspect of a company’s data landscape and to adopt a methodology for continually assessing the risk protection strategies already in place.

This includes identifying vulnerable assets and weak access points, while also observing risk trends and mitigating opportunities to fail.

While implementing a risk assessment methodology requires an all-in approach from the entire organisation, implementing the right technology, like comprehensive employee monitoring software, can be the natural next step to identify and prevent a devastating data loss event.

2. Monitor Employee activity, and respond to Suspicious Behavior

Advances in machine learning and other ancillary technologies allow companies to establish user profiles so that abnormal behavior can be identified and investigated.

For example, frequent late shifts, printing more documents than normal, or copying substantial amounts of data from external drives can be an indication of possible malicious behavior.

Of course, other, more-subtle activity can be a red flag as well. Powerful employee monitoring software equipped with Optical Character Recognition (OCR) and context analysis capabilities can detect when employees research topics related to hacking, an uptick in complaints or angry sentiments expressed through internet chats, or a sudden decline of work-related activities. These signals can all serve as a precursor to the intention to steal data.

While these behaviors may not necessarily indicate a data breach, they could mean everything for early detection, and they are worthy of response and investigation.

3. Collect and save Data for Forensic Examination

When a data loss event does occur, companies need to understand what happened so that they can improve their practices and seal the security holes.

In short, there is both an educational and a deterrence component to data security, and both require digital forensics.  

Therefore, recording sessions when employees access sensitive information, maintaining logs of data access, and sustaining digital activity trails can equip IT admins with the investigative capabilities necessary to evaluate the threat and to fortify protocols to prevent it from happening again.

4. Minimise the threat by limiting access to safe resources

The internet is an expansive ecosystem with a myriad of websites and apps that, taken together, represent both an opportunity and a threat to organizations striving to protect their data.

To limit their exposure, companies should determine and implement a whitelist and a blacklist for websites or apps that are useful or even dangerous. Moreover, for the inevitable gray area between white and black lists, IT admins should be notified when unknown apps are being accessed so that they can evaluate the use and take action if necessary.

5. Classify sensitive data and implement perimeter rules

Not all data is created equally, and some data is more sensitive than others. More importantly, not all employees need to have access to all the organization’s data. Classify sensitive data as such, and limit access to employees who actually need that information.

In a very real way, employees should be on a need-to-know basis, and today’s software can ensure that they only have access to what they need to see. Perhaps more importantly, sensitive data can be protected with additional security measures like tagging and fingerprinting that can, among other features, stop users from sharing secure data.

6. Automate Security Policies to take Proactive Action

Whether they act maliciously or accidentally, employees can quickly compromise their company’s data. Fortunately, by deploying the right software, any organisation can automate policies that proactively prevent this from happening.

For instance, it’s possible to prevent employees from opening PDFs from unknown email senders and to block the upload of company files to personal storage sites like Dropbox or Google Drive.

As a best practice protocol, companies should implement privileged user monitoring to maintain extra vigilance and scrutiny for administrators and other privileged users, ensuring that they don’t create new system rules, open backdoor accounts, increase their system privileges, access sensitive personal information, or edit configuration or system files.  

7. Implement Third-Party vendor Monitoring

Maintaining a modern IT infrastructure frequently involves providing third-party vendors with network access, which can compromise user data. According to a 2018 study by the Ponemon Institute, more than half of companies that experienced a data breach attribute the cause to a third-party vendor.

The ability to access system preferences allows external vendors to steal company data as well as damage IT infrastructure, but monitoring third-party vendors can protect against inappropriate data use or theft. In addition, companies can suspend a vendor’s credentials, so that they cannot access the network unless they are actively working on a project.  

Collaborating with third-party vendors may be a veritable necessity of the digital age, but that doesn’t mean that sensitive data needs to be compromised in the process.

8. Establish compliance and security Standards

In today’s regulatory environment, data loss isn’t just an existential threat, it’s a practical problem with legal and financial consequences. The implementation of Europe’s comprehensive GDPR legislation, the medical sector’s HIPAA guidelines, and other forthcoming regulations significantly raise the stakes for data protection.
Identifying and examining their protocols can yield helpful strategies for preventing data loss, while simultaneously ensuring that companies remain compliant with their increasingly stringent demands.

9. Integrate DLP and SIEMs for better coverage

When examining a company’s network infrastructure, it’s critical to attain as much security coverage as possible. Therefore, choose a solution that provides a unified insider detection and data loss prevention feature set.

A responsive, real-time DLP framework that seamlessly integrates with SIEMs provides centralized insight into data management protocols and offers real-time alert management for complete security coverage.

10. Train & Educate Employees, Contractors, and Suppliers

Ultimately, data protection is a priority that requires consistent training and retraining to be effective. Although it may look different for each company, outlining the boundaries with a comprehensive Acceptable Use Policy is a natural next step.

Best practice guides, business etiquette initiatives, and onboarding training can reinforce and reproduce company values. When combined with instructive technology that provides on-time warning messages and behavior-shaping monitoring tools, companies can create a dynamic learning environment that educates their workforce on the practice and priority of data security.

In today’s data landscape it’s more important than ever for companies to protect against the insider threats lurking within their companies. To be sure, this starts with hiring the right people who support and adopt the organisation’s data security mindset.

Implementing the right policies and integrating the right technologies can make all the difference. Comprehensive employee monitoring software is the place to start, providing valuable metrics and instituting guidelines to protect against internal threats.

IT Security Central:

You Might Also Read:

Breakthrough Technologies To Combat Insider Threats:

 

« Breaking Down Five 2018 Breaches
UK Launches Long-Awaited Cyber Skills Strategy »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Talend

Talend

Talend is a leader in cloud and big data integration software. Applications include Risk and Compliance management.

PFP Cybersecurity

PFP Cybersecurity

PFP provides a SaaS solution for life-cycle protection based on our IoT security platform and power usage analytics.

Latvian Information & Communications Technology Association (LIKTA)

Latvian Information & Communications Technology Association (LIKTA)

LIKTA brings together leading Latvian companies, organizations and professionals in the field of Information & Communications Technology

NetFort

NetFort

NetFort provides software products to monitor activity on virtual and physical networks.

NetMonastery DNIF

NetMonastery DNIF

NetMonastery is a network security company which assists enterprises in securing their network and applications by detecting threats in real time.

Black Kite

Black Kite

Black Kite (formerly NormShield) provides comprehensive Security-as-a-Service solutions focused on cyber threat intelligence, vulnerability management and continuous perimeter monitoring.

Cyber Seguridad (Cyberseg)

Cyber Seguridad (Cyberseg)

Cyberseg provides specialized Cybersecurity services, including managed services (SOC / CERTs) and solutions for the protection of critical infrastructures.

Institute of Informatics and Telematics (IIT)

Institute of Informatics and Telematics (IIT)

IIT carries out activities of research, assessment, technology transfer and training in the field of Information and Communication Technologies and of Computational Sciences.

BullGuard

BullGuard

BullGuard is an award-winning cybersecurity company focused on providing the consumer and small business markets with the confidence to use the internet in absolute safety.

DisruptOps

DisruptOps

Built for today’s cloud-scale enterprises, DisruptOps’ Cloud Detection and Response platform automates assessment and remediation procedures of critical cloud security issues.

Newtec Services

Newtec Services

IT should be responsive, adaptive, and smart. Now more than ever, you need a business that runs efficiently and can adapt to today's challenges. We can help with custom IT solutions.

AlJammaz Technologies

AlJammaz Technologies

AlJammaz Technologies is the leading Technology Value-Added Distributor, which distributes advanced technology products, solutions and services in area including networking and cybersecurity.

HolistiCyber

HolistiCyber

HolistiCyber provide state-of-the art consulting, services, and solutions to help proactively and holistically defend against a new era of constantly evolving cyber threats.

Guernsey

Guernsey

Guernsey provides a wide range of engineering, architecture and consulting services to multiple markets, including cybersecurity consulting and CMMC certification.

Atlantic Data Security

Atlantic Data Security

Atlantic Data Security is skilled in the analysis, recommendation, deployment, and management of all critical components of the security infrastructure.

StrongBox IT

StrongBox IT

Strongbox IT provides solutions to secure web applications and infrastructure.