Advertisement
Promo

Become a member of the ZDNet UK community

(ISC)2

View blog's RSS Feed

Security Profession blog

Comment and discussion about the security industry of interest to the security professional. Blogs will be submitted by (ISC)2's management team and Advisory Board members.

Tuesday 29 July 2008, 12:01 PM

Insider security threat not exaggerated

Posted by (ISC)2

I was reading recently some research claiming that the insider security threat had been exaggerated: (http://www.verizonbusiness.com/resources/security/databreachreport.pdf). The report said that the majority of security threats are external and concluded that the insider threat is not the issue we have all long believed.

I think this is somewhat misrepresentation of the real truth. Security professionals have long claimed that the internal threat is the biggest security risk to company information, eclipsing even external breaches such as data leakage and malware. Contrary to this analysis, rather than exaggerated, I think it’s just been misrepresented. The threat of ‘insider’ security breaches is still very real. But rather than being malicious breaches of intention, it is more likely that most insider security breaches are accidental; a result of companies failing to adequately implement policies and validation controls or to educate staff about security policy.

Information security professionals need to assess what the risks are and where they may come from. Underestimating that real threat of internal security breaches is unwise. There are still lots of controls that security professionals should implement to stop the sorts of mistakes that really can, and do, impact security in order that they can, as a colleague of mine once said, stop clever people from doing dumb things.


John Colley, CISSP
Managing Director EMEA, (ISC)2

Comments on this post

(ISC)2
  • (ISC)2
  • n/a
  • Member since: February 2008

Site Activity Rating 3

Contacts

Number of Contacts: 1

Contacts' Latest Discussions

Number of Tracked Discussions: 123

Karen Friar Karen Friar

Comment quarantined

Tuesday 24 November 2009, 3:50 PM

8 comments
Karen Friar Karen Friar

Thanks for the catch

Monday 2 November 2009, 6:00 PM

2 comments
Karen Friar Karen Friar

Disappearing comments and blog posts

Tuesday 29 September 2009, 9:36 AM

5 comments
Karen Friar Karen Friar

Windows 7 versus Vista, XP

Thursday 6 August 2009, 11:40 AM

1 comment

Contacts' Latest Blogs

Number of Contacts Blogs: 1

Avatar Karen Friar

HP workers set dates for strikes

Thursday 3 December 2009, 7:57 PM

2 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters