# Beware the Insider Threat: Protect Against the Enemy Within
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2018-06-20
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Financial Institutions at Risk: Spotting Insider Threats
Meta Description: Discover insights from Steve Armstrong at Bitglass on detecting insider threats in financial institutions to safeguard against cyber attacks
URL: https://financedigest.com/beware-the-insider-threat-protect-against-the-enemy-withinhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd200618-1-1736840315091-compressed.jpg)

_**Steve Armstrong**, Regional Director UK, Ireland, and South Africa at Bitglass, identifies how to spot insiders who might pose a serious cybersecurity risk, and highlights the steps financial institutions can take to minimise said risk._

**_“It’s never the enemy without that brings you down. It’s always the enemy within.”  Sherrilyn Kenyon_**

It’s fair to say that the banking industry has weathered many storms these past few years; unfortunately, calmer waters won’t be on the horizon any time soon. A major concern for banks and financial institutions is that they are being targeted by cyber criminals who are seeking to steal customer information and slow down online [banking operations](https://www.financedigest.com/stellantis-reshuffles-european-financing-operations-through-new-jvs-with-banks.html "Stellantis reshuffles European financing operations through new JVs with banks"). In April this year, the [Financial Times](https://www.ft.com/content/2e582594-48ab-11e8-8ee8-cae73aab7ccb) reported that seven of the UK’s biggest banks, including Santander, Royal Bank of Scotland, and Tesco Bank, were forced either to slow operations or shut down entire systems due to cyberattacks.

In light of the above, it’s no surprise that a global study of 400 bank executives conducted by the [Economist](https://www.economist.com/) found that 71% of execs are focusing their digital investments on cybersecurity. A separate study by Crowd [Research Partners](https://www.financedigest.com/havas-media-group-partners-with-lumen-research-to-measure-and-optimise-attention-at-global-scale.html "Havas Media Group Partners with Lumen Research to Measure and Optimise Attention at Global Scale") identified “insiders,” or financial institutions’ own employees, as being a significant threat. In fact, 53% of those polled confirmed that they had experienced an insider attack in the last twelve months; additionally, 27% said that insider attacks are becoming a more common occurrence.

These statistics are indicative of the growing [threat that insiders pose to data security](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats"). Unfortunately, organisations typically struggle to detect anomalous or careless employee behaviours.  As such, many must revise their approaches [to data protection](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches "). However, before deploying a new [security solution](https://www.financedigest.com/industrial-cyber-security-solutions-and-services-strong-increase-in-user-base-pans-out-for-north-america-to-lead-market.html "Industrial Cyber Security Solutions and Services – Strong Increase in User Base Pans Out for North America to Lead Market"), it is important to understand four of the most common insider threats faced by businesses today.

**1) Disgruntled workers**

> Often described as malicious insiders, rogue employees are individuals that intentionally [set out to steal company](https://www.financedigest.com/london-set-for-hosepipe-ban-from-aug-24-water-company.html "London set for hosepipe ban from Aug. 24 – water company") data; this may be done out of a desire for vengeance, profit, or even a competitor’s benefit. A high profile example can be found with the [2015 case](https://www.dailytelegraph.com.au/home/formula-1-mercedes-sues-ferraribound-engineer-over-alleged-data-theft/news-story/41eddf3058c2a2655c0834c3b473de51) of a Mercedes engineer that stole highly sensitive data in order to give it to his new employer, Ferrari.

Unfortunately, insiders with malicious intent have an upper hand when it comes to data theft – they have legitimate credentials that will bypass the majority of their organisations’ [security features](https://www.financedigest.com/canada-unveils-new-passport-design-with-more-security-features-nod-to-king-charles.html "Canada unveils new passport design with more security features, nod to King Charles"). If such an individual holds a senior or administrative role, she or he may even have unfettered access to an organisation’s most sensitive data.

**2) The third-party employee**

Third parties are frequently overlooked when organisations are planning their [security strategies](https://www.financedigest.com/security-trumps-obesity-in-britains-first-food-strategy.html "Security trumps obesity in Britain’s first food strategy"). These insiders often act as fully integrated members of an organisation,even when working from distant locations. Some may also have in-depth familiarity with [internal processes and controls](https://www.financedigest.com/international-space-station-thrown-out-of-control-by-misfire-of-russian-module-nasa.html "International Space Station thrown out of control by misfire of Russian module -NASA"), making them just as knowledgeable about security procedures as an internal employee.

**3) Unwilling accomplices**

Compromised credentials are a significant danger for the enterprise.With usernames and passwords in hand, outside parties can enter corporate networks through legitimate [means and evade security](https://www.financedigest.com/open-banking-as-a-means-to-enhance-social-commerce-security.html "Open banking as a means to enhance social commerce security") systems. An example of this can be found with the [global accountancy firm Deloitte](http://www.bbc.co.uk/news/technology-41385951). Recently, hackers compromised the organisation’s global email server using a stolen admin account, granting them unfettered [access throughout the entire system](https://www.financedigest.com/telehealth-monitoring-to-rule-the-the-transseptal-access-systems-market.html "Telehealth monitoring to rule the The Transseptal Access Systems Market") for months before their activities were discovered.

As this example shows, breaches involving credential compromise can take a great [deal of time](https://www.financedigest.com/italys-cdp-and-partners-ask-tim-for-more-time-for-network-deal.html "Italy’s CDP and partners ask TIM for more time for network deal") to identify and remediate. From an IT perspective, it can appear as though account hijackers are simply regular users going about their normal job duties, making it difficult to detect the misuse of corporate credentials.

**4) The careless worker**

Whiledisgruntled workers clearly [pose a serious threat to organisational security](https://www.financedigest.com/london-police-say-queens-funeral-poses-biggest-ever-security-test.html "London police say queen’s funeral poses biggest ever security test"), a less obvious threat rests with happy, but careless employees. These individuals may inadvertently compromise security by using unsecured public Wi-Fi, losing organisational credentials, clicking on suspicious email links, sharing sensitive information with unauthorised parties, or being followed into the office through an access-controlled door. Each of these mishaps [offers criminals an opportunity](https://www.financedigest.com/c-arms-market-to-offer-ample-growth-opportunities-by-2027.html "C-arms Market to Offer Ample Growth Opportunities by 2027") to breach the enterprise.

**What’s the answer?**

The unpredictable nature of insider threats means that a proactive, multi-faceted [solution is the best form](https://www.financedigest.com/schlumberger-subsea-7-and-aker-solutions-to-form-subsea-engineering-firm.html "Schlumberger, Subsea 7 and Aker Solutions to form subsea engineering firm") of defence. Below are four different approaches to security which, when combined, create robust protections around cloud-based environments.

**Automation**: Reactive tools that rely upon humans to manually analyse [threats are incapable of protecting](https://www.financedigest.com/the-best-ways-to-protect-your-business-from-cyber-threats-in-2021.html "The best ways to protect your business from cyber threats in 2021") data in the high-speed era of the cloud. As such, [automated security solutions are vital for businesses](https://www.financedigest.com/why-no-code-beats-custom-software-and-turnkey-solutions-for-business-automation.html "Why no-code beats custom software and turnkey solutions for business automation") today. These kinds of tools employ machine learning so that they can identify malicious or suspicious behaviours as soon as they take place; for example, when a user suddenly downloads an unusually large amount of data or accesses sensitive [information outside of normal working](https://www.financedigest.com/the-importance-of-information-security-in-a-post-pandemic-hybrid-working-world.html "The importance of information security in a post-pandemic hybrid working world") hours. These tools use an analytical, real-time approach in order to uncover threatening behaviour and take corrective [actions as needed](https://www.financedigest.com/new-uk-pm-will-need-to-take-urgent-action-on-energy-bills-ofgem-ceo.html "New UK PM will need to take urgent action on energy bills – Ofgem CEO").

**[Identity and access management](https://www.financedigest.com/how-to-manage-identity-in-a-hybrid-cloud-environment.html "How to manage identity in a hybrid cloud environment") (IAM)**: To defend against insider threats, it is imperative that organisations verify users’ identities and grant data access to appropriate parties only. Relying upon basic passwords is no longer an adequate [strategy for protecting corporate](https://www.financedigest.com/9-issues-in-corporate-finance-and-strategies-to-overcome-them.html "9 Issues in Corporate Finance and Strategies to Overcome Them") information. Instead, companies need to leverage multi-factor authentication (MFA) and require a second form of verification – like an SMS token sent via email or text message. Other helpful capabilities include contextual access control, which governs [data access by factors like job](https://www.financedigest.com/euro-zone-bond-yields-rise-after-u-s-jobs-data.html "Euro zone bond yields rise after U.S. jobs data") function and geographic location, as well as session management, which automatically logs inactive users out of corporate applications in order to prevent account hijacking.

**Data loss prevention (DLP)**: Cloud DLP is a dynamic tool that [securely enables](https://www.financedigest.com/top-fintech-trends-for-2021-enabling-smart-and-secure-finance.html "Top Fintech Trends for 2021 Enabling Smart and Secure Finance") employees to work wherever they want and whenever they want – from the devices of their choosing. A typical [cloud DLP offering](https://www.financedigest.com/oracle-offers-its-mysql-heatwave-database-and-analytics-on-amazons-cloud.html "Oracle offers its MySQL HeatWave database and analytics on Amazon’s cloud") should include watermarking (tracking), file encryption, redaction, and other features that help ensure that sensitive data never gets into the wrong hands.

**Training**: While technology can be a powerful [way to improve data security](https://www.financedigest.com/behavioral-biometrics-simple-and-secure-way-to-authenticate-consumers-digital-identities.html "Behavioral Biometrics: Simple and Secure way to Authenticate Consumers’ Digital Identities"), another effective tool is far simpler. Regular employee trainings can raise awareness of security best practices and help [keep data](https://www.financedigest.com/the-future-of-cloud-how-to-keep-your-data-safe.html "The Future of Cloud: How to Keep Your Data Safe") protection top of mind for workers. By consistently discussing the [importance](https://www.financedigest.com/as-consumer-spending-increases-convenience-and-security-have-never-been-more-important.html "As consumer spending increases, convenience and security have never been more important") of security and the consequences of failing to uphold security protocols, the threats of data theft and data leakage can be minimised.

Without [maintaining a robust security](https://www.financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-services.html "Maintaining Security and Compliance amid Digital Transformation in Financial Services") posture, banks are susceptible to the insider threats detailed above. However, to achieve such a security posture, organisations must first understand these threats and the dangers they represent. Once this knowledge is obtained, banks can select security solutions capable of defending data in today’s IT landscape, allowing them to confidently and [securely take advantage of the cloud](https://www.financedigest.com/dont-let-the-promises-of-virtual-desktop-security-cloud-your-judgement.html "Don’t let the promises of virtual desktop security cloud your judgement").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

