Story image

Nearly half of AU organisations not equipped for malicious insiders

19 Aug 16

Mimecast Limited recently released new data that reveals the majority of organisations believe they are their own worst enemy.

Want that in numbers? 40 percent reported that they are ill-equipped to cope with the threat of malicious insiders and more than twice that amount, (with a whopping 91 percent), call malicious insiders a major threat to their organisation’s security.

Entitled 'Business Email Threat Report: Email Security Uncovered', the study from Mimecast made it clear that malicious insiders represent not only a major source of risk and anxiety over security preparedness, but a growing one.

According to Mimecast CEO, Peter Bauer, a common problem amongst businesses is to focus predominantly on perimeter defence and outside threats, while struggling with the risk that comes from their own people.

“Organisations of all sizes struggle with the risks that are posed by employees being targeted by adversaries to launch and execute attacks to gain access to data or funds” says Bauer. “Every day, we trust employees with sensitive information and powerful tools, but we don’t give them the effective security education and advanced cloud security solutions that goes hand-in-hand with those responsibilities.”

Bauer asserts that as a community, we must work together to enact better business processes.

“Another issue we can work together to control is rogue employees who use unapproved file-sharing or cloud storage services outside of their organisation’s security policies thus exposing their organisation to increased risk,” Bauer says. “IT managers have, for too long, not paid due attention to this threat. We must re-evaluate unrestricted access to these services and ensure that protections are put in place quickly to balance security and the needs of the business.”

Some of the additional findings from Mimecast’s research include:

  • Over half (56 percent) of IT security decision makers view malicious insiders as a moderate or high threat to their organisation.
  • 12 percent of security decision makers view malicious insiders as their number one threat.
  • Globally, those who say they’re very equipped on cybersecurity feel virtually just as vulnerable to insider threats as those who believe they aren’t equipped at all (16 percent vs. 17 percent), indicating that the risk of malicious insiders trumps perceptions of security confidence.

There are a number of ways to protect against malicious insiders. Mimecast recommends assigning role-based permissions to administrators, implementing internal safeguards and data exfiltration controls, offering creative employee security training, nurturing a culture of communication within teams and training your organisation’s leadership.

ForeScout acquires OT security company SecurityMatters for US$113mil
Recent cyberattacks, such as WannaCry, NotPetya and Triton, demonstrated how vulnerable OT networks can result in significant business disruption and financial loss.
Ransomware infection? Here’s how you control the damage
Ransomware has evolved to be more sophisticated and targeted, and remains a threat to businesses of all sizes.
Exclusive: Fileless malware driving uptake of behavioural analytics
Fileless malware often finds its way into organisations via web browsers (or in combination with other vectors such as infected USB drives).
'DerpTrolling’ faces jail time for Sony DoS attacks
A United States federal court has charged a 23-year-old man for the hacks on Sony Online Entertainment and other major companies back in 2014.
It's time to rethink your back-up and recovery strategy
"It is becoming apparent that legacy approaches to backup and recovery may no longer be sufficient for most organisations."
Dropbox strengthens security with raft of new partnerships
Integrations will keep customer content protected and secure with tools for controlling identity access, governing data, and managing devices.
Companies swamped by critical vulnerabilities – Tenable
Research has found enterprises identify 870 unique vulnerabilities on internal systems every day, on average, with over 100 of them being critical.
Don’t let your network outgrow your IT team
"IT professionals spend less than half of their time at work optimising their networks and beefing it up against future security threats."