166 terms · 75/46/45
Threat № 058 · class: trust

Insider Threat

An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.

Term

description · examples · notes

An insider threat comes from a person who has, or once had, legitimate access to an organization's systems, data or premises. That can be an employee, a former employee, an administrator, an associate, a supplier or a partner. The trouble is that the access was not necessarily unauthorized to begin with.

Description

An insider can act deliberately or by accident. One person carries the client database out before leaving the company, another deletes data out of revenge, another sends a confidential document to the wrong person, and another becomes the extended arm of an outside attacker because their account was compromised or they are under pressure.

This is one of the most awkward threats an organization faces, because access controls do not show it. The system can say that a user has the right to open a document, but not whether they have a business reason to copy it at midnight, pack it into an archive and send it out of the company.

Examples

  • An employee copies the client database before moving to a competitor.
  • A disgruntled administrator deletes or alters production data.
  • A user accidentally sends a confidential document to the wrong recipient, because they did not check the address.

Notes

  • An insider threat is not a synonym for bad intent. Ignorance, carelessness and a compromised account can do the same damage.
  • Least privilege, separation of duties and good records are not an expression of distrust towards people but protection of the system against a situation going badly.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 6

Defenses

countered by 18