#17unit 1online security and payment system

Insider attacks

Threats originating from within an organization.

Learning Objectives

  • Define insider attacks and explain why they are serious.
  • Describe the role of trusted employees and privileged access.
  • Explain why negligent insiders are also a major risk.
  • Compare insider attacks to external attacks.

Explanation

Insider attacks come from trusted employees who have access to privileged information. Bank employees steal more money than bank robbers; the same is true for e-commerce sites. Some insiders act maliciously, while others are simply negligent.

We tend to think of security threats to a business as originating outside the organization. In fact, the largest financial threats to business institutions come not from robberies but from embezzlement by insiders. Bank employees steal far more money than bank robbers. The same is true for e-commerce sites: some of the largest disruptions to service, destruction to sites, and diversion of customer credit data and personal information have come from insiders — once trusted employees.

Employees have access to privileged information, and, in the presence of sloppy internal security procedures, they are often able to roam throughout an organization's systems without leaving a trace. Research from Carnegie Mellon University documents the significant damage insiders have done to both private and public organizations. Survey results indicate that insiders are more likely to be the source of cyberattacks than outsiders, and to cause more damage to an organization than external attacks.

In some instances, the insider might not have criminal intent, but inadvertently exposes data that can then be exploited by others. A Ponemon Institute study found that negligent insiders are a top cause of data breaches. Another study estimated that 1% of employees are responsible for 75% of cloud-related enterprise security risk, by reusing or sending out plain-text passwords, indiscriminately sharing files, using risky applications, or accidentally downloading malware or clicking phishing links.

Defending against insider attacks is challenging because insiders legitimately have access to the systems they attack. Controls include principle-of-least-privilege access policies, monitoring of privileged activity, separation of duties, and prompt revocation of access when employees leave the organization. Laudon and Traver note that PKI is not effective against insiders who have legitimate access to corporate systems and customer information — a key limitation of technical solutions.

Key Points & Important Terms

Key Points

  • Insider attacks come from trusted employees with privileged access.
  • Bank employees steal more than bank robbers — same for e-commerce.
  • Insiders cause more damage than external attacks.
  • Some insiders are malicious; others are negligent.
  • 1% of employees cause 75% of cloud-related enterprise security risk.
  • PKI is not effective against insiders with legitimate access.

Important Terms

Insider attack
A security threat originating from within an organization, typically from a trusted employee with privileged access.
Malicious insider
An employee with criminal intent who abuses access to steal, disrupt, or destroy.
Negligent insider
An employee who inadvertently exposes data through risky behavior such as weak passwords or phishing clicks.
Privileged information
Sensitive data accessible to employees that, if leaked, can harm the organization.