Financial Services Industry
Industry: Email Alert RSS FeedInsiders Pose Greatest Threat to Network Security
Risk & Insurance, August, 2001 by Michael Capozzi
When it comes to security threats, hackers have received a majority of the attention. But a new survey indicates that the two biggest threats to a company's computer security come from insiders--current employees gaining access to files they're not entitled to and former employees whose company passwords have not been changed.
The survey, conducted on behalf of eWEEK magazine and Haifa, Israel-based security software developer Camelot, specifically found that 57 percent of the respondents that recorded a security breach cited users accessing resources they shouldn't be entitled to as one cause of the breaches, while 43 percent cited breaches as a result of accounts left open after an employee has left the company. Next, at 30 percent, was "been the victim of information theft from your network."
Most PopularCBS MoneyWatch.com Articles
But despite these findings, only 26 percent of respondents reported being "very concerned" about insiders having access to more files than they actually need, while 50 percent reported being "somewhat concerned." Forty percent of respondents reported being very concerned about inappropriate insiders having access to sensitive data residing on their file servers; 37 percent reported being somewhat concerned. By comparison, 55 percent of respondents reported being very concerned about outsiders gaining access to sensitive information; and another 32 percent reported being somewhat concerned.
Businesses with less than 10 employees were the least concerned about insider security issues; 42 percent of respondents within this category said they are not concerned about insiders having access to more files than they actually need, and 35 percent said they are not concerned about inappropriate insiders having access to sensitive data.
"The results of the survey pinpoint a major Achilles heel too often unknown or underestimated by corporations," says Yuval Baharav, president and CEO of Camelot. "The recently publicized external hacks represent a very small portion of the constant infringements a network endures daily. Too often, authorized behavior goes unchecked."
Insurance companies are also starting to realize the threats that insiders pose. The recently published Chubb CyberRisk Handbook, for which Chubb engaged the services of PricewaterhouseCoopers, has this to say: "Studies have consistently shown that insiders pose more of a threat than third-party hackers. One unfortunate reality of our reliance on networking technology is that a single employee can do far more damage today than was ever possible in the past. With employee turnover increasing, and employee loyalty low, the potential for disaster lurks behind each disgrnntled separation."
So what can businesses expect to be covered for?
When looking for help in traditional crime policies and fidelity bonds, risk managers should beware of their exclusions, according to the handbook. "Traditional fidelity bonds and crime policies have a number of important limitations to consider in light of the emerging risks of electronic commerce... The traditional fidelity bond and crime policies exclude coverage for any consequential or indirect losses. Therefore there is no coverage for business interruption for employee dishonesty or extortion-type perils."
The handbook also states that indirect losses as a result of employee or authorized user actions are typically excluded from computer crime policies. "Historically, it has been estimated that 70 percent of the dollar value of crime insurance claims have been paid out under the employee infidelity clause. Employee fraud seems likely to remain the major source of losses for years to come."
- How to choose the right insurance carrier for your business
- Real Estate: Prepare your properties to weather what lies ahead
- Technology: Be prepared if part of your global supply chain goes missing
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- LIFO vs. FIFO: a return to the basics
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Design a commission plan that drives sales - Sales Commissions


