{"id":46071,"date":"2020-03-06T10:18:47","date_gmt":"2020-03-06T10:18:47","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/06\/how-c-level-execs-can-better-understand-insider-risk\/"},"modified":"2020-03-06T10:18:51","modified_gmt":"2020-03-06T10:18:51","slug":"how-c-level-execs-can-better-understand-insider-risk","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/06\/how-c-level-execs-can-better-understand-insider-risk\/","title":{"rendered":"How C-level execs can better understand insider risk"},"content":{"rendered":"\n<p><em>In the digital era, it is easy to be blinded by the lights of new technologies. However, this can cause us to disregard the factors which pose a threat to insider risk. Tony Pepper, CEO, Egress, discusses insider breach risks and suggests the way we understand and manage insider risk needs to change to comply with today&#8217;s data security challenges.   <\/em><\/p>\n\n\n\n<p>Insider data breach risk has existed for as long as companies have but its nature, impact and a business&#8217; ability to control it has changed dramatically in the digital data-driven age. As a valuable commercial asset, data is a target for theft by malicious actors within and outside the business, while as a regulated liability, it must also be protected from accidental loss or exposure. Data security is a board-level concern and gaining a better understanding of insider breach risk helps directors ensure it is managed effectively.<\/p>\n\n\n\n<p><strong>The digital workplace puts data on the front line<\/strong><\/p>\n\n\n\n<p>The first step in understanding the evolution of insider breach risk is to acknowledge the effect of unprecedented transformation of the workplace and employees\u2019 relationship with technology and data. Increased mobility and the rise of remote, flexible working mean human-digital interaction is near constant. This blurs the lines between work and homelife, creating an &#8216;always-on&#8217; culture where employees juggle diverse priorities simultaneously. <\/p>\n\n\n\n<p>At the same time, data volumes have increased exponentially and businesses have become hyperconnected, providing workers with multiple channels for data sharing. Yet, despite these immense changes, employees remain the same; as fallible and fundamentally <em>human<\/em> as ever. So, we\u2019re looking at a world where a single mistake made by a pressured employee &#8211; a mistyped email address or response to a phishing email &#8211; can cause an accidental breach of huge scale and devastating impact, while employees with malicious intent have every tool they need at their disposal. \u00a0\u00a0<\/p>\n\n\n\n<p>We ask our\nworkforce to do more, share more and make snap judgements about data\nsensitivity, appropriate protection and the authenticity of email correspondents,\nall at the relentless pace of competitive business. This is set against a\nbackdrop of punitive data protection regulations. This is a new environment where\ndata is on the front line and risk has increased disproportionately.&nbsp; <\/p>\n\n\n\n<p>This shift means the way we understand and manage insider risk needs to change too. We must view it in the context of the modern workplace and data security landscape and ask: are our expectations of employees\u2019 ability to keep data safe in this environment realistic? Are we adequately supporting the human layer of security?<\/p>\n\n\n\n<p><strong>Concern: IT\nleaders are viewing a new type of risk through an old lens<\/strong><\/p>\n\n\n\n<p>Evidence from our recent <em>Egress Global Insider Breach Survey<\/em> indicates IT leaders are struggling to adapt how they view and manage insider risk in this new landscape. The research asked 500 IT leaders and 5,000 employees about causes, frequency and impacts of internal security breach incidents and views about data risk and ownership. It highlighted discrepancies between IT leaders\u2019 perceptions of insider breach risk and how they are managing it. <\/p>\n\n\n\n<p>A staggering 97% of IT leaders are concerned about this risk. A total of 78% believed employees had leaked data accidentally in the past 12 months and three-quarters believed they had done so intentionally. Looking ahead, 36% said it was likely employees would put data at risk in the coming year. <\/p>\n\n\n\n<p>Despite this\nconcern, when asked what security tools they have in place to mitigate insider\nbreaches, just half of IT leaders said they are using anti-virus software to\ncombat phishing attacks, 48% are using email encryption to protect data and 47%\nprovide secure collaboration tools.&nbsp; <\/p>\n\n\n\n<p>IT leaders appear\nresigned to a degree of inevitability when it comes to insider breaches,\nacknowledging the sustained risk but not adopting new strategies or\ntechnologies to mitigate them. They\u2019re viewing a new risk through an old lens\nby continuing to focus on static prevention strategies aimed at securing the devices\nand network layers, rather than addressing the human layer where mistakes are actually\nmade. Effectively they are adopting a risk posture in which employees putting\ndata at risk is deemed acceptable. From a board-level perspective, this must be\ncause for serious concern. <\/p>\n\n\n\n<p><strong>Components: Analysing the human layer<\/strong><\/p>\n\n\n\n<p>Employees\noffer considerable insight into insider breach risk. Our research found 27%\nsaid they or a colleague had accidentally leaked data in the past year and 29%\nhad deliberately breached company policy when sharing data.<\/p>\n\n\n\n<p>The effect of the mobile, always-on culture was reflected in reasons employees gave for accidental data leaks. A total of 23% said they had done so because they were using a mobile device and the same percentage said they were under pressure when they made the error. One in five cited tiredness as the cause of their mistake. The ever-growing risk from phishing emails was a factor in 41% of accidental data breaches, while 31% admitted accidentally sending data to the wrong person. These figures are needlessly high given the availability of security tools that use contextual Machine Learning to prevent misdirected emails, stop the wrong attachments being attached, alert users to phishing emails and help employees use encryption tools correctly.<\/p>\n\n\n\n<p>Reasons\ngiven for deliberate breaches reflect everyday frustrations and ethical frailty\nin the workforce. A quarter took a risk and shared data against company policy\nbecause they didn\u2019t have the right tools to share it safely, while 46% took\ncompany data with them when they went to a new job. These responses show\nemployees are not being supported to share data safely and that a significant\npercentage should be monitored more closely based on breach risk.<\/p>\n\n\n\n<p>C-level executives should also recognise the diverse personality types that present varying risks. Our research showed that, on average, more senior employees are more likely to intentionally breach data sharing rules. A total of 78% of director-level employees said they had done so in the past year, compared with 10% of clerical workers. In contrast, 44% of clerical staff have misdirected an email, while only 20% of directors admitted to making this mistake. <\/p>\n\n\n\n<p>Another\naspect affecting insider risk is employees\u2019 attitudes to data ownership. Our\nresearch found only 41% understand that data belongs exclusively to the\nbusiness. Others felt it belonged to departments, teams or individuals that had\nworked on it. This proprietary view explains employees\u2019 tendency to take data\nwith them to new jobs or take risks when sharing data.<\/p>\n\n\n\n<p>Again, this points to the need to support and manage the human layer of data security. In a pressurised, connected workplace, it\u2019s not realistic to expect that employees will get things right every time, or that they will always act honourably in accordance with company policy. At Egress we understand this and we have developed contextual Machine Learning tools that provide a safety net for users to prevent breaches, protect data and ensure regulatory compliance against the new generation of human-activated breaches \u2013 without compromising productivity. <\/p>\n\n\n\n<p>Gaining a\nbetter understanding of insider breach risk means executives must recognise how\nit has evolved; understand how employees view data ownership and the different personalities\nin the workforce that put data at risk; and ultimately ensure IT leaders are deploying\nsolutions that mitigate today\u2019s risks, not those of the past. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the digital era, it is easy to be blinded by the lights of new technologies. However, this can cause us to disregard the factors which pose a threat to insider risk. Tony Pepper, CEO, Egress, discusses insider breach risks and suggests the way we understand and manage insider risk needs to change to comply [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":46072,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[1643,11443,11444],"class_list":["post-46071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-data-security","tag-egress","tag-insider-breach-risk"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=46071"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46071\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/46072"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=46071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=46071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=46071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}