Top execs blind to insider threat

Employees remain the biggest security threat to enterprises, warns report

Written by James Murray

Negligent or malicious employees pose one of the biggest security threats to firms, according to a report that reveals over three-quarters of companies have experienced one or more insider-related security problems that were not publicly disclosed.

A global survey of 461 IT and security professionals working at medium to large firms also found that nine out of 10 respondents regarded insider threats as one of their top three security concerns, but half of these staff did not think their chief executive attached the same importance to the issue.

Brian Contos, chief security officer at security management software specialist ArcSight, which commissioned the research, said that because boards have little awareness of the danger from insiders many IT directors find it difficult to get the necessary resources to minimise the risk.

"There is a bit of a generational gap where CEOs don't like to think any of their staff could betray the business, but IT chiefs are more aware that with data no longer locked in silos it is easy for insiders to steal or inadvertently compromise sensitive data," Contos said.

Contos said IT directors need to highlight the scale of the risk and consider adopting enterprise-wide early detection systems alongside traditional measures such as background checks on new staff and monitoring of email usage. He said such systems can monitor the IT use of staff and in some cases physical movements, and detect suspicious behaviour that should be investigated more closely.

However, IT lawyer George Gardiner advised that under privacy regulations firms using such monitoring tools should notify staff that they could be monitored and ensure all checks are reasonable and necessary. He also warned that companies need to consider the possibility that this type of monitoring could alienate staff.

The latest survey follows a separate study last month by data encryption specialist Pointsec highlighting security problems caused by negligent business travellers who lose corporate laptops and mobiles at airports.

The study found a quarter of the machines handed into UK airport lost property departments had no encryption or password security.

Tags:

reader comments

related articles

SBS slammed over monitoring role

National Audit office highly critical of Small Business Service 29 May 2006

 

Email monitoring could breach human rights

Survey says almost half of UK companies could be breaking email laws 18 Jul 2006

Large companies snoop on staff emails – and face legal danger

About 40 percent of large firms are monitoring staff messages, and some are breaking the law 06 Jun 2006

UK councils fall short on data protection

Little encryption and poor disaster recovery plans 12 Oct 2007

Check Point puts ForceField around browsers

ZoneAlarm plays in the sandbox 10 Oct 2007

Sun boosts ID management

New product and GRC platform designed to help firms implement roles-based identity management 05 Mar 2008

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation