George Foot

Your Biggest Data Security Threat Could Be….

Biggest Data Security Threat

Your biggest data security threat could be sitting next to you…

Data security is a big concern for businesses. The repercussions of a data security breach ranges from embarrassment, to costly lawsuits and clean-up jobs – particularly when confidential client information is involved.

But although more and more businesses are taking steps to improve data security, few are considering the most likely cause of such a threat: human error. According to our Voice of IT report, human error is perceived to be the biggest threat to an organisation’s IT security.

However, when looking within, there’s not one, but three personas to consider: careless employees, disgruntled employees, and uninformed employees.

Careless employees

failing mobile phones

(Image Source: Shutterstock)

Some of the biggest and most embarrassing data breaches have been from employees taking information out of an organisation and accidentally leaving that information in a public place. In 2008, a USB stick containing a list of passwords for a UK government computer system was found in a car park pub in Staffordshire. The following year, a health worker from Lancashire lost a memory stick containing the personal details of more than 6,000 current and ex-prisoners (while the data was encrypted, the password had been written on the back of the USB pen.) In 2010, an Apple engineer accidentally left a prototype for the not-yet-released 4th generation iPhone in a bar in California. These are just a few of the most famous examples of employees accidentally leaving confidential data in public places.

The lesson here is that companies need to think long and hard about the information they’re willing to allow employees to take out of the business premises. These days, as more and more employees access emails and corporate files from mobile devices, this is especially important. An unlocked smartphone that’s logged into a company system can be just as dangerous as a USB drive with all the information already downloaded onto it.

Disgruntled employees

shutterstock_63966280

Disgruntled employees arguably pose the biggest threat of all. Depending on the seniority of the employee, an employee may not only have access to sensitive company information and documents, but also to networks, admin accounts, and data centres.

According to some cyber experts, the extremely costly 2014 Sony Pictures hack was not an attack from North Korea but the result of a disgruntled employee. Whether or not that’s true is still up for debate, but the fact that Sony is willing to entertain it highlights the fact that some employees have too much power and given an opportunity could cause serious problems.

The Sony Pictures hack isn’t the first example of a disgruntled IT employee wreaking havoc. In 2008, Los Angeles city network admin Terry Childs reset the passwords for the city’s FibreWan network. Childs, a very disgruntled employee, then refused to hand over the passwords and brought the city into a state of digital lockdown for several days.

While obviously Childs is very much to blame here, human error is also to blame on the part of his superiors, who gave him too much freedom and responsibility. The lesson here is that no matter how important an employee is, they shouldn’t be given too much digital freedom, particularly when it comes to admin rights. The more administrators there are for different sections of the business, the less damaging an internal attack will be.

It’s also important to remember that most attacks by disgruntled employees happen after an employee has been laid off. This gives most companies ample time to reset important passwords and prevent an attack from a future disgruntled employee.

Uninformed employees

Data security isn’t something that regularly crosses the minds of most employees.

In 2015, French TV station TV5Monde was taken off the air by hackers purporting to be a part of the Islamic State. TV5Monde’s website and social media accounts were both affected.

The following day, staff from TV5Monde were interviewed to discuss the attack in front of a wall which had several sheets of very sensitive company information stuck to it. According to several sources, the sheets of papers contained lists of the company’s social media accounts and passwords. Other footage from the interviews showed post-it notes on computers containing passwords for other important company accounts.

Ignoring the fact that some passwords were as simple as ‘youtubepassword’, the lesson here is to educate employees regularly on the importance of data security. While most employees won’t ever be interviewed on national television, there may be other ways that they could unwittingly share important company information. In the past social media, accident emails, accidental email attachments, and viruses have all resulted in sensitive company information being leaked outside of the company.

Therefore, proactivity is vital to the wellbeing of IT infrastructure. Along with training employees on best practice, some companies are investing in risk management software – combining big data analytics with an understanding of human behaviour – to identify internal threats before they strike.

Fear of the unknown is justified but, when it comes to security, the devil you know could be your biggest danger.

By George Foot

George Foot

Vice President Kensington Europe & Global Marketing

George has been a part of Kensington for over 10 years and now serves as the Vice President for Kensington Europe & Global Marketing. George has extensive experience within the consumer electronics industry and possesses a great passion for technology. He is responsible for setting the vision and strategy for the region, Go-To-Market delivery and sales performance.

View Website

CONTRIBUTORS

The Rise Of BI Data And How To Use It Effectively

The Rise Of BI Data And How To Use It Effectively

The Rise of BI Data Every few years, a new concept or technological development is introduced that drastically improves the ...
Data Breaches: Incident Response Planning - Part 1

Data Breaches: Incident Response Planning – Part 1

Incident Response Planning - Part 1 The topic of cybersecurity has become part of the boardroom agendas in the last ...
The Tech Sector Gender Gap

The UK Tech Sector: The Gender Gap

The Tech Sector Gender Gap In conversation with Co-Founder and Creative Director of North West Web Design Studio, MadeByShape Andy ...
Bryan Doerr

Cyber-Threats and the Need for Secure Industrial Control Systems

Secure Industrial Control Systems (ICS) Industrial Control Systems (ICS) tend to be “out of sight, out of mind.” These systems ...
THE AGE OF DATA: THE ERA OF HOMO DIGITUS

THE AGE OF DATA: THE ERA OF HOMO DIGITUS

The Age of Data In our digital era data deluge – soaring amounts of data, is an overriding feature. That’s ...
Let's Look Into A Crystal Ball And See What The Future Holds For Cloud Computing

Let’s Look Into A Crystal Ball And See What The Future Holds For Cloud Computing

Let's look into the cloud computing future Wandering around town the other day I stopped in a psychic's storefront. I had ...
Cloud Comings and Goings

Cloud Comings and Goings

Cloud Power Amazon Web Services – the giant of cloud computing – is on track to do $10 Billion in ...
Big Data Gives Insight to Consumer Trends

Big Data Is a Competitive Advantage in Any Industry

Big Data Competitive Advantage The various ways major companies — and even entire industries — have begun utilizing methods to ...

NEWS

HPE CEO Whitman's surprise exit stumps Wall Street

HPE CEO Whitman’s surprise exit stumps Wall Street

(Reuters) - Shares of Hewlett Packard Enterprise Co (HPE.N) fell 6 percent on Wednesday after Chief Executive Officer Meg Whitman’s ...
Cloud Security Alliance Issues New Code of Conduct for GDPR Compliance

Cloud Security Alliance Issues New Code of Conduct for GDPR Compliance

EDINBURGH, Scotland, Nov. 21, 2017 /PRNewswire-USNewswire/ -- The Cloud Security Alliance (CSA), the world's leading organization dedicated to defining and raising awareness of best practices ...
OVH Announces New Hosted Private Cloud Offerings for US Market

OVH Announces New Hosted Private Cloud Offerings for US Market

OVH delivers next-generation services for hosted private cloud, disaster recovery, and hybridity leveraging industry-leading solutions RESTON, VA--(Marketwired - Nov 20, ...

SPONSORS

Scale your Windows Azure application

Understanding The Importance Of A Flexible Hybrid Cloud Solution

Flexible Hybrid Cloud Solution The cloud computing revolution continues to gather pace, and more and more businesses are coming on-board ...
Has Cybersecurity Become Too Reactive in this Day and Age?

Has Cybersecurity Become Too Reactive in this Day and Age?

Cybersecurity Too Reactive? Cybersecurity today has become far too reactive. The constant innovation of hackers has meant that defenses are ...
Visual Data Analytics Helps To Illustrate The Big Picture

Visual Data Analytics Helps To Illustrate The Big Picture

Visual Data Analytics We’re consistently hearing how valuable data is today, how important it is to the success of every ...