Introduction
The cyber security threats and attack vectors are becoming complex with advanced TTPs (Tactics, Techniques and Procedures) by the external bad actors. However, errors caused due to human mistakes are the most common and costly sources of cyber security risk for the organisations. Whether the error is due to ignorance, carelessness or malicious intent, human mistakes can compromise data, availability, or operational efficiency of the IT function, thereby disturbing the CIA (Confidentiality, Integrity & Availability) of data/information. Falling prey to social engineering techniques is one of major challenges. Techniques such as impersonation, phishing, or baiting are tried by the attacker, a success of the technique by manipulating or deceiving people results in revealing sensitive or personal information, or granting access or permissions to unauthorized parties. A well-executed social engineering can enable offenders to bypass multiple layers of cyber security measures deployed and gain access to your IT system, data, or resources.
Insider Threats
One of the major and critical threat associated with human errors is termed as insider threats. The Cybersecurity and Infrastructure Security Agency (CISA) defines insider threat as “the threat that an insider will use their authorized access, intentionally or unintentionally, to do harm to the department’s mission, resources, personnel, facilities, information, equipment, networks, or systems.” An insider is a person, who has authorized access to or knowledge of an organization’s resources, including personnel, facilities, information, equipment, networks, and systems. Insider threats generally originates by misuse of their legitimate access unintentionally leading to cybersecurity incidents, intentional actions or by an external cyber offender by hacking/hijacking the systems or account credentials.
An insider is a trusted person in an organisation such as employees, auditors etc and also those to whom the organization has given information access such as contractors, external consultants, outsourced agencies etc.
Let’s examine the various types of Internal Threats.
- Unintentional threats
These are unintentional threats from the insiders without any malicious intent.Negligence: This unintentional Insider Threat is caused by negligence, generally by insiders who are having legitimate access to the information and security policies. Examples include:- Negligent storage, misplacing or losing of any removable media having critical information,
- Allowing someone for physical/logical access to secured area through “piggybacking” or “tailgating”.
- Ignorance of security alerts, updates and patches by responsible person.
- Mistyping an email and accidently sending to an unauthorised person.
- Unknowingly clicking on a hyperlink or opening an attachment in a phishing email.
- improper disposing of sensitive documents.
- Intentional threats
Intentional threats are often originated from insiders with malicious intent to harm an organization for personal gains or taking action against a personal grievance. Some of such grievances include lack of recognition, punitive actions or termination. The motive and actions may include data leakage, peer harassments, damage of equipment etc. - Other Threats
Collusive Threats –Collusive Threats involves collaboration of an external actor with one or more insiders with a malicious intent. These incidents often involve cybercriminals collaborating with an insider or several insiders to enable fraud, intellectual property theft, espionage, or a combination of the three.Third-Party Threats –These include threats from external third party entities such as contractors or vendors who have provided with some level of access to facilities, systems, networks, or people to accomplish their work deliverables as per the contract or mode of association. They are not direct members of the organisation.
Preventive and precautionary measures taken in Information Security policy
Measures to prevent, protect, and prioritize the security threat from insiders are included as part of our Information Security Policy. The policy combine both technical and non-technical security controls. Some of such actions taken include implementation of Multi-factor authentication (MFA) for critical access, Privilege Access Management (PAM) to ensure protected access to production systems with least privileges, disabling access to USB drives, SD card, external drives on laptops and/or desktops unless explicitly required and pre-approved etc. Cybersecurity best practices are also to be followed in general as per our Information Security practices, such as candidate screening, Background verification while hiring, onboarding & offboarding practices, security awareness trainings, continuous assessment of security posture etc.
However, the key success in combating Insider threats is the awareness among the members in the organisation. Proper handling and safe-guarding of sensitive information and proper password etiquette to be ensured by all the members. Each member of the organisation shall weaponise themselves through self-awareness related to malicious acts of cybercriminals.
-by Jyothish Jolisa
VP (Information Security) & CISO