Does my company need to be more proactive about insiders during hard times?
Simply put - yes. Given stressful situations, people are more likely to partake in risky activity, malicious, criminal or otherwise. While there is no technological panacea, technology can help in detecting the early warning signs of nefarious activities on the network. But instead of just discussing the technology, let's take a closer look at things from a human perspective to understand the non-technical drivers, and why given today's "hard times" it is of even greater importance to be even more proactive with regard to monitoring nefarious insider activity.
I'm not a criminal psychologist, but several have conducted research in this area. Mike Gelles, formerly of the Naval Criminal Investigative Service (NCIS), wrote an excellent paper called Exploring the Mind of the Spy. In it, he examines the personalities of insiders, looking beyond the traditional areas of opportunity, motive, and ability that are generally associated with criminal activity.
Dr. Gelles cites three criteria that can lead to the transformation from loyal employee to malicious insider:
-- A personality or character weakness
-- A crisis - personal, financial or career
-- The absence of assistance during a crisis.
While we won't examine these items in depth, it is clear that we are in the midst of a national financial crisis that has led to personal crises for many individuals affected by the situation - many of whom now have no place to turn for assistance. These individuals may be facing a layoff, a significant drop in the value of their retirement investment portfolio, a foreclosure or significant credit-card debt, all of which can result in increased stress. This stress in turn may also put extra strain on personal relationships. This spiraling situation may put some people in a desperate position, which may lead them to act in nefarious ways.
Given these tough times and their potential consequences, early detection and response are important to protecting valuable corporate assets that may be the target of illegal activity. Technology solutions are available that focus on the needed detection and response. One is security information and event management (SIEM), which is designed to among other things monitor the activity of an organization's IT environment and detect early warning signs of nefarious insider activity.
SIEM looks across multiple things:
-- IT infrastructure - firewalls, intrusion prevention, network gear, VPNs and physical security controls like badge readers, video analytics and RFID;
-- Applications - custom, commercial, Web and non-Web-based applications;
-- Identity management - LDAP, Active Directory and IDM solutions developed by companies like SUN and Oracle;
-- Sensitive data - databases and file servers
Such a wide and deep perspective of the organization's environment can help address many key questions:
-- Who did it?
-- Should they be doing it?
-- How was it done?
-- What was impacted?
-- Who else might be involved?
-- How long has this activity been occurring?
-- What else are these individuals doing?
Companies may look for many things when monitoring for insider activities. Note that every company has a different approach based on corporate culture, sensitivity of data and the like. Also, while technology helps reduce the false positives and bring forward the most compelling events, human interpretation is always needed. Nothing beats human intuition - technology just augments it.
Here are some indicators of potential misdeeds:
-- Accessing/modifying systems outside of job requirements/policy
-- Accessing/downloading unusually large amounts of information
-- Using the identity credentials for someone else
-- Printing sensitive documents
-- Using Webmail, sending e-mails to competitors, and surfing job websites
-- Using services to make browsing anonymous
-- Entering the building at unusual times - early, late, weekends or holidays
Even today, there are large gaps in the security postures of many businesses when it comes to insiders. Businesses that don't take steps to address these gaps are at a grave disadvantage compared to their peers. Their risk profiles are substantially higher, and by the time the problem becomes painfully obvious to them, it may be too late. Taking these proactive preventive measures is important to minimize the impact of a breach by an individual who is acting desperately in these hard times.
Contos is CSO of ArcSight.
References
Latest on Authentication & Access Control
- Rogue SSL certificate exploit puts VeriSign on the spot
- Cisco: Huge international interest in developer contest
- CA to buy data-leak prevention vendor
- Cisco: Cyberattacks growing, looking more legit
- The many faces of multifactor authentication
- Fallen Danish IT star says he acted under threat
- RIM kicks off hostile bid for Certicom
- Cybercrime '09: Too Late to Save Facebook?
- IT fugitive Stein Bagger will be sent back to Denmark
- US Open used Web filtering to prevent online gambling
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- Telstra kicked out of NBN process
- Linux on the iPhone won’t change the world - yet
- A Novell approach to business
- An open storage stack? I like the sound of that
- The mobile clone wars: fighting for a better phone experience
- Stopping the "Clean Feed"
- Identifying web platforms
- Clean Feed ‘not technically possible’
- No Clean Feed - well duh!
- Conroy's content cops still on the cards
Recent comments
- BUY HTC TOUCH MAX 4G AT $260USD, TOUCH G1 AT $250USD,TOUCH HD
1 day 21 hours ago - GrIDsure & Mike Bond's 'old' criticism
2 days 23 hours ago - Ah, the joys of being a digital nomad!
4 days 5 hours ago - Thanks
4 days 7 hours ago - re hope cottage
4 days 13 hours ago - Best CRM I have found
1 week 2 days ago - milbarn
1 week 6 days ago - milbarn
1 week 6 days ago - Compare Usenet Providers
2 weeks 3 hours ago - BUY Nokia N85 AT $240USD, HTC TOUCH PRO AT $230USD, APPLE IPHON
2 weeks 5 days ago - BUY APPLE IPHONE 3G SERIES AT $220USD, 8GB GOLD AT $200USD
2 weeks 5 days ago - BUY HTC TOUCH 3G AT $260USD, TOUCH G1 AT $250USD,TOUCH HD AT $
2 weeks 5 days ago - BUY BLACKBERRY STORM 9500 AT $260USD,BLACKBERRY BOLD 9000 AT $
2 weeks 5 days ago - Re:
2 weeks 6 days ago - Lto-4 Tape
4 weeks 6 days ago - Clarifaction of article
6 weeks 1 day ago - COBOL - Safe Bet
6 weeks 1 day ago - The most effective recycling method is to reuse!
6 weeks 1 day ago - Reduce, Reuse and Recycle!
6 weeks 1 day ago - SOFTWARE
6 weeks 2 days ago







