For all the investments we make in threat intelligence, perimeter defense, threat mitigation, application security, 3rd party risk, you name it; the behavior of "insiders" continues to be the single greatest source of cyber risk within the enterprise. Often labeled "Insider Threats", those inside the secured perimeter of the enterprise are "trusted" and accordingly, operate with a significant degree of freedom. Unfortunately, that trust is not always deserved and can be exploited by malicious insiders. At the same time, an even greater risk is poised by poor IT hygiene and the simple mistakes of employees in the course of their daily work. Phishing-attacks, unsafe web browsing, insecure communications while accessing enterprise resources from outside the secure perimeter, are just a few examples of "human errors" that can open the door for cyber attacks. A few thoughts for Security Today...
| less than a minute read
Insider Threats - The Data is Clear & Unambiguous
Let’s start with a statistic. A joint study by Stanford University Professor Jeff Hancock and security firm Tessian has found that a whopping 88 percent of data breach incidents are caused by employee mistakes. Similar research by IBM Security puts the number at 95 percent