Internal Staff A Growing Threat?

By Ray Birch

PORTLAND, Ore.—The risk of data breaches from internal staff is growing, reports one cybersecurity firm, which says the average cost for an internal breach is $8.7 million.

Feature Internal Fraud low res

And that figure represents losses that are discovered, said Tim Erlin, VP of product management and strategy at Tripwire. Erlin said unlike external breaches that are typically discovered after they happen, internal breaches often can go undetected and are sometimes not reported by companies when they occur.

“It’s always difficult to get clear data on how often specific types of breaches occur,” he told CUToday.info. “Organizations are understandably reticent to share the details of what they perceive as an embarrassing incident. We have seen regulatory changes drive more reporting, but that doesn’t necessarily mean those regulatory bodies provide transparency into breaches either.”

Erlin said one of the best data sources is the Verizon Data Breach Incident Report (DBIR), which is published annually.

“This report uses data collected from more than 46,000 security incidents and just over 2,000 confirmed breaches in which data was known to be compromised,” Erlin said. “The most meaningful data point from the DBIR is that 34% of breaches involved an internal actor, while 69% were perpetrated by external attackers. That rounds out to about 700 confirmed breaches last year where the attacker was internal to the organization.”

A Growing Trend

And that percentage is slowly rising.

“It is a growing trend, but not especially rapidly,” said Erlin. “The percentage of breaches involving internal actors in 2017 was 25%, and today is up to 34%.”

As CUToday.info recently reported, a former employee of The Desjardins Group is suspected of stealing information on 2.7 million members who are part of Desjardin credit unions in Quebec and Ontario, Canada that includes names, addresses, birth dates, social insurance numbers, email addresses and information about transaction habits. Desjardins representatives have said passwords, security questions and personal identification numbers were not compromised.

Erlin emphasized no accurate data exists on how successful internal crooks are when they commit their crimes.

“The frequency of success is entwined with data on frequency overall,” he said. “The fact is, we really only know about attacks that are identified. It’s not possible to say how many attackers, whether internal or external, are successful because the successful ones aren’t generally discovered. Data theft isn’t like stealing physical property. Data can be stolen, and still remain right where it was to begin with. As a consequence, unless disruption is the primary objective, successful attacks might go undetected.”

The Inside Advantage

Why are internal thieves successful when they get away with their crimes? Erlin said often the key is they have advantages over crooks who don’t work for the company.

erline

Tim Erlin

“With insider attacks, success is most attributable to the fact they have authorized access to the systems and resources they’re trying to attack,” explained Erlin. “An outsider has to go through multiple steps just to gain the access the insider already has to begin with. Each of those steps is another chance for an attacker to be discovered, thwarted and potentially caught. An insider starts with an advantage.”

Also, many organizations are much less diligent about monitoring the activity of authorized users, noted Erlin.

“That means when an insider does something unauthorized or suspicious, it’s less likely to be noticed,” he said.

Catching Inside Jobs

How are internal thieves typically caught? Erlin said they are detected in many of the same ways outsider attacks are discovered.

“These internal criminals undertake some action the security team notices or they expose themselves in how they use data after it’s been taken,” he explained. “For insiders, this often takes the form of trying to access data they don’t normally use or trying to exfiltrate data from the organization. Of course, an attack can be discovered without identifying the attacker as an individual. In this case, insiders are at a disadvantage. While it’s reasonable to think an inside attack is less likely to be detected, when they are detected, it’s more likely the attack will be attributed to a specific individual.”

Steps to Take

Erlin outlined what steps companies can take to defend against internal threats.

“There are specific technical controls that can be put in place to help defend against insider attacks,” he said. “The first action to take is to ensure user permissions are distributed using a principle of least privilege, meaning that users are only able to take actions and access data necessary for their job. It’s common for users to have access they don’t strictly need. If access control is well provisioned, it becomes much more feasible to monitor for users doing things they shouldn’t be doing.”

Erlin added diligent monitoring is an important part of combating insider threats.

“While many tools look for clear attack activity, monitoring for changes that are simply suspicious is a good way to identify activity that’s authorized, but not appropriate,” Erlin explained. “Change monitoring is most effective when coupled with a change management process. Identifying changes that occur, but aren’t part of an approved change ticket, can uncover not only insider threat activity, but also other factors that affect system stability overall.”

Section: Standard
Word Count: 1119
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Internal-Staff-A-Growing-Threat