All the latest UK technology news, reviews and analysis

RSA highlights insider threat confusion

by Phil Muncaster

25 Aug 2009

Be the first to comment

  • Tweet this
Security
Most security incidents are down to unintentional data loss

Most chief security officers are misdirecting their focus on malicious insider security incidents when the majority of insider threats are committed accidentally by staff and trusted third parties, according to new research commissioned by RSA Security.

Analyst firm IDC interviewed around 400 IT decision makers globally for the survey, and found that the majority were unsure of the sources of internal risk and struggled to quantify the impact in financial and business terms.

Just over half thought that most insider threats were accidental, compared to 19 per cent who believed them to be deliberate. However, 82 per cent were unable to specify whether incidents arising from contractors and temporary staff were accidental or not.

Many respondents said that threats such as the spread of malware from within the enterprise was a major concern, but the largest number of incidents came from unintentional data loss though employee negligence, while the incidents that had the most impact involved out-of-date privileges and inappropriate access rights.

Chris Young, senior vice president at RSA, argued that to mitigate the risks of insider threats, especially those which might have been caused with no malicious intent, organisations must take a risk-based approach to information security.

"Companies need to take an information risk approach and not an infrastructure protection approach. This requires enterprise-wide policies on protecting information and categorising risk," he said.

"The chief security officer needs to make sure that only the right people have access to the right information, although there is always a balance between security and convenience."

Young also stressed the importance of coupling this strategy with comprehensive education and awareness-raising programmes so that "security is everyone's job".

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

0%

11%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer

Java Developer Thomas Cook Online is the business unit...

Contract Systems Administrator, Windows £320 per day

Contract Systems Administrator, Southampton My...

PHP Web Developer, PHP, to £30k + 30% bonus

PHP Web Developer required to join my market-leading...

Java Developer x2, Spring, Hibernate, £40K

Java Developer x2, Spring, Hibernate, Swindon, £40K...

To send to more than one email address, simply separate each address with a comma.