The most popular and comprehensive Open Source ECM platform
Security: Businesses Exposed to Insider Risk
Insider Risk is the general danger of damage or loss occurring to company data. Insider Threat more specifically focuses on users — it is the potential that a user who has authorized access does something either maliciously or unintentionally that causes damage.
Forrester predicts that in 2021 that one-third of all data breaches will be caused by something that happens internal to the company. The report finds that “As firms add capabilities for detecting insider threats, they will also be able to identify and attribute more incidents to insider activity than they were previously. Give specific focus to insider threat defense, emphasize employee experience to avoid turning employees into malicious insiders, and remember that trust is not a control.”
Insider Threats can generally be classified into three types:
- unintentional – these are usually the result of carelessness
- emotionally motivated – caused by individuals that have a personal grudge for some reason. The goal is to damage reputation or to disrupt systems.
- financially motivated – caused by an individual who seeks to profit from their privileged access.
Joe Payne, president and CEO at Code42, said that “Insider Risk affects every organization. It is a byproduct of employees getting their work done everyday – how they create, access and share files in today’s collaboration culture. However, security teams are at a disadvantage: there is a lack of understanding of Insider Risk, which is leading to complacency, failing technologies and inadequate processes. The severity of the Insider Risk problem is being consistently overlooked, evidenced by the sharp rise in risky behavior this year.”