#17unit 1online security and payment system

Insider attacks

Threats originating from within an organization.

5-mark Exam Answer

5-mark answer

Insider attacks originate from within an organization — typically from trusted employees who have privileged access. Laudon and Traver note that insiders are among the largest financial threats to e-commerce firms.

  • 1.Insiders = trusted employees with privileged access
  • 2.Larger financial threat than external attacks
  • 3.Malicious vs negligent insiders
  • 4.Can roam systems without leaving a trace
  • 5.1% of employees cause 75% of cloud security risk

We tend to think of security threats as originating outside the organization, but in fact the largest financial threats to business institutions come not from robberies but from embezzlement by insiders. Bank employees steal far more money than bank robbers. The same is true for e-commerce sites: some of the largest disruptions to service, destruction to sites, and diversion of customer credit data have come from insiders — once trusted employees.

Employees have access to privileged information, and, in the presence of sloppy internal security procedures, they are often able to roam throughout an organization's systems without leaving a trace. Survey results indicate that insiders are more likely to be the source of cyberattacks than outsiders, and to cause more damage to an organization than external attacks.

In some instances, the insider might not have criminal intent, but inadvertently exposes data that can then be exploited by others. A Ponemon Institute study found that negligent insiders are a top cause of data breaches. Another study estimated that 1% of employees are responsible for 75% of cloud-related enterprise security risk, by reusing or sending out plain-text passwords, indiscriminately sharing files, using risky applications, or accidentally downloading malware or clicking phishing links.

Defending against insider attacks is challenging because insiders legitimately have access to the systems they attack. PKI is not effective against insiders who have legitimate access to corporate systems and customer information — a key limitation of technical solutions. Effective defenses include least-privilege access, monitoring of privileged activity, and separation of duties.

A negligent employee reuses a weak password across cloud services and clicks a phishing link, exposing customer data — illustrating how even non-malicious insiders can cause serious breaches.

Insider attacks — both malicious and negligent — are among the most damaging threats to e-commerce. Because insiders have legitimate access, technical tools like PKI have limited effectiveness, making procedural and access controls essential.

insider attacktrusted employeeprivileged accessnegligent insiderembezzlementPKI limitation

The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.