Top execs blind to insider threat

Employees remain the biggest security threat to enterprises, warns report

Written by James Murray

Negligent or malicious employees pose one of the biggest security threats to firms, according to a report that reveals over three-quarters of companies have experienced one or more insider-related security problems that were not publicly disclosed.

A global survey of 461 IT and security professionals working at medium to large firms also found that nine out of 10 respondents regarded insider threats as one of their top three security concerns, but half of these staff did not think their chief executive attached the same importance to the issue.

Brian Contos, chief security officer at security management software specialist ArcSight, which commissioned the research, said that because boards have little awareness of the danger from insiders many IT directors find it difficult to get the necessary resources to minimise the risk.

"There is a bit of a generational gap where CEOs don't like to think any of their staff could betray the business, but IT chiefs are more aware that with data no longer locked in silos it is easy for insiders to steal or inadvertently compromise sensitive data," Contos said.

Contos said IT directors need to highlight the scale of the risk and consider adopting enterprise-wide early detection systems alongside traditional measures such as background checks on new staff and monitoring of email usage. He said such systems can monitor the IT use of staff and in some cases physical movements, and detect suspicious behaviour that should be investigated more closely.

However, IT lawyer George Gardiner advised that under privacy regulations firms using such monitoring tools should notify staff that they could be monitored and ensure all checks are reasonable and necessary. He also warned that companies need to consider the possibility that this type of monitoring could alienate staff.

The latest survey follows a separate study last month by data encryption specialist Pointsec highlighting security problems caused by negligent business travellers who lose corporate laptops and mobiles at airports.

The study found a quarter of the machines handed into UK airport lost property departments had no encryption or password security.

Tags:

reader comments

related articles

SBS slammed over monitoring role

National Audit office highly critical of Small Business Service 29 May 2006

 

Email monitoring could breach human rights

Survey says almost half of UK companies could be breaking email laws 18 Jul 2006

Large companies snoop on staff emails – and face legal danger

About 40 percent of large firms are monitoring staff messages, and some are breaking the law 06 Jun 2006

Card fraud factory raided

Devices for stealing Chip and PIN card details found by police 13 Aug 2008

Spammers exploit heightened interest in the economy and US election

Attackers are increasingly using legitimate sites to host their malware 27 Oct 2008

Sun boosts ID management

New product and GRC platform designed to help firms implement roles-based identity management 05 Mar 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation