Mimecast released new data revealing that organisations globally believe they are their own worst enemy when it comes to cyber security, with 45% saying they are ill equipped to cope with the threat of malicious insiders and twice as many, 90%, calling malicious insiders a major threat to the organisations’ security.
Mimecast initially found as part of its Business Email Threat Report: Email Security Uncovered that 65% of IT security decision makers globally feel their email security systems are inadequately equipped to handle cyber threats and, this new data makes it clear that malicious insiders represent a major and growing source of this risk and anxiety over security preparedness.
By concentrating predominately on perimeter defense and outside threats, organisations around the world struggle with the risk that comes from their own people, emphasising the need for organisations to implement employee awareness and education as well as creating a cyber resilience strategy that includes both technology and human based defenses. This is evident especially considering this study revealed that nearly half of the organisations polled felt exposed to malicious insider attacks.
The survey revealed that over half of IT security decision makers view malicious insiders as a moderate or high threat to their organisation. One in seven IT security decision makers view malicious insiders as their number one threat. Those who say they are very equipped on cyber security feel virtually just as vulnerable to insider threats as those who believe they are not equipped at all, indicating that the risk of malicious insiders trumps perceptions of security confidence.
“Organisations of all sizes struggle with the risks that are posed by employees being targeted by adversaries to launch and execute attacks to gain access to data or funds,” said Brandon Bekker, Managing Director, Mimecast MEA. “Every day, we trust employees with sensitive information and powerful tools, but we do not give them the effective security education and advanced cloud security solutions that goes hand-in-hand with those responsibilities. As a community we must work together to enact better business processes. This is in part why we launched the Cyber Resilience Coalition, bringing together leading security, data protection and business continuity vendors to help strengthen organisations’ total cyber resilience strategy.
“Another issue we can work together to control is rogue employees who use file-sharing or cloud storage services to steal valuable corporate data, also known as malicious insiders. IT managers have, for too long, not paid due attention to this threat. We must re-evaluate unrestricted access to these services and ensure that other protections are put in place quickly.”
Tips to safeguard against malicious insiders
- Assign role-based permissions to administrators to better control access to key systems and limit the ability of a malicious insider to act.
- Implement internal safeguards and data exfiltration control to detect and mitigate the risk of malicious insiders when they do strike, to cut off their ability to send confidential data outside the network.
- Offer creative employee security training programmes that deter potential malicious insiders in the first place and help others to spot the signs so they can report inappropriate activity to their managers. Then, back that up with effective processes to police and act swiftly in the event of an attack.
- Nurture a culture of communication within teams to help employees watch out for each other and step in when someone seems like they have become disenchanted or are at risk of turning against the company.
- Train your organisation’s leadership to communicate with employees to ensure open communication and awareness.