Five steps to protect company data from desperate employees tempted to steal secrets Five steps to protect company data from desperate employees tempted to steal secrets - RSS feed from Security Park
(04/08/2009)

According to figures released by the Office for National Statistics, redundancies for the three months to April 2009 were up 36,000 over the quarter and up 191,000 over the year. However anxious these times may be for employees, employers should not be complacent and expect loyalty in return for a regular pay packet. In fact the opposite could well be true - as the saying goes “desperate times call for desperate measures”.

In a recent Cyber-Ark survey into “The recession and its effects on work ethics”, a staggering sixty percent admitted they would take valuable data with them, if they could get away with it, were they faced with redundancy or the sack! Remarkably, 40% confessed to having already snooped around the networks and downloaded sensitive company secrets from under their bosses nose in anticipation that they could lose their job. Top of the list of desirable information to steal is customer and contact databases, with plans and proposals, product information, and access/password codes all popular choices and as having a perceived value – either monetary to an unscrupulous third party or as a negotiating tool in securing a new position.

In a separate Cyber-Ark global survey into “Trust, Security & Passwords”, 35 percent of IT workers admitted to accessing corporate information without authorisation. The types of information this audience would target was proprietary data and information that is critical to maintaining competitive advantage and corporate security. Ominously, 1 in 5 companies confessed having experienced cases of insider sabotage or IT security fraud.

When staff take data and cause a security incident, it tends to be filed away as an example of an “employee gone bad.” In reality it constitutes a failure of the organisation to uphold its responsibility on behalf of the business to manage, control and monitor the power it provides to its employees and systems or indeed have any controls actually in place to actually manage and control staff from causing breaches. The failure stems from the ‘perception of control’ an organisation has over their most sensitive networks, systems and devices versus the stark reality that this control is most often not in place across the organisation. So, what can be done to protect sensitive data from an increasingly unsettled, and to some extent desperate, workforce?

To significantly cut the risk of these insider breaches, employers must have appropriate systems and processes in place to prevent prying personnel.

One approach to address this challenge is a privileged identity management holistic approach using solutions such as digital vaults, especially valuable for users with high levels of enterprise/network access as well as those handling sensitive information and/or business processes. Instead of trying to protect every facet of an enterprise network, digital vault technology creates safe havens – distinct areas for storing, protecting, and sharing the most critical business information – and provides a detailed audit trail for all activity associated within these safe havens. This encourages secure employee behaviour and significantly reduces the risk of human error.

For organisations serious about preventing internal breaches, be they accidental or malicious, here are five steps to protecting company data from desperate employees tempted to steal secrets:

1- Establish a Safe Harbour

By establishing a safe harbour, or vault, for highly sensitive data (such as administrator account passwords, HR files, or intellectual property including corporate databases), security is built directly into the business process independent of the existing network infrastructure. This will protect the data from the security threats of not only nosy employees snooping around for information they should not be privy to, but also from hackers.

A digital vault is set up as a dedicated, hardened server that provides a single data access channel with only one way in and one way out. It is protected with multiple layers of integrated security including a firewall, VPN, authentication, access control, and full encryption. By separating the server interfaces from the storage engine, many of the security risks associated with widespread connectivity are removed.

2- Automate Privileged Identities and Activities

Ensure that privileged administrative and application accounts, and their underlying passwords are actively managed, secured, changed regularly, highly guarded from unauthorised use, and closely monitored, including full activity capture and recording. Once these privileged identities are being managed, make sure to proactively monitor and report actual adherence to the defined policies, and adopt the well-accepted security axiom of ‘Trust, but verify’ . This is a critical component in safeguarding organisations and helps to simplify audit and compliance requirements, as companies are able to answer questions associated with “who” has access and “what” is being accessed.

3- Identify All Your Privileged Accounts

The best way to start managing privileged accounts is to create a checklist of operating systems, databases, appliances, routers, servers, directories, and applications throughout the enterprise. Each target system typically has between one and five privileged accounts. Add them up and determine which area poses the greatest risk. With this data in hand, organisations can easily create a plan to secure, manage, automatically change, and log all privileged passwords.

4- Secure Embedded Application Accounts

Up to 80 percent of system breaches are caused by internal users, including privileged administrators and power users, who accidentally or deliberately damage IT systems or release confidential data assets. Many times, the accounts leveraged by these users are the application identities embedded within scripts, configuration files, or an application. The identities are used to log into a target database or system and the fact that these credentials, are traditionally hard-coded, in clear-text and usually never changed is often overlooked within a traditional security review. Even if located, the account identities are difficult to monitor and log because they appear to a monitoring system as if the application (not the person using the account) is logging in.

These privileged, application identities are being increasingly scrutinised by internal and external auditors, especially during PCI- and SOX-driven audits, and are becoming one of the key reasons that many organisations fail compliance audits. Therefore, organisations must have effective control of all privileged identities, including application identities, to ensure compliance with audit and regulatory requirements.

5- Avoid Bad Habits

To better protect against snoopers, organisations must establish best practices for securely exchanging privileged information. For instance, employees must avoid bad habits (such as sending sensitive or highly confidential information via courier). IT managers must also ensure they educate employees about the need to create and set secure passwords for their computers instead of using sequential password combinations or their first names.

The risk of internal data misuse from snoopers can be significantly mitigated by implementing effective policies and technologies. In doing so, organisations can better manage, control, and monitor the power they provide to their employees and systems and avoid the negative economic and reputational impacts caused by an insider data breach.

Opinion piece submitted by Mark Fullbrook, UK Director Cyber-Ark Software

Related topics:  Authentication and identity management   Data management and data security   Knowledgebase   Security management and policies 


print versionPrint version | email this to a friendEmail to a friend | related articlesRelated articles


Data breaches: Trends, costs and best practices gives you all the latest information on securing personal and corporate data, key recommendations for immediate action to improve data security, and how to respond to data breaches.


Other Security news and resources


Security News Suppliers Directory Jobs forum Classifieds Knowledge base White papers Research library Security books Special reports Security interviews Security companies Security events Security links Security market

Product channels

Access Control Biometrics CCTV Intruder Alarms IT Security Manned Guarding Perimeter Protection Physical Security Remote Monitoring Security Services Fire, Health & Safety Other Security Products

IT Security white papers and research library

Access Control  Authentication  Data Management  Data Security  Digital Signatures  Email Security  Identity Management  Internet Security  Intrusion Prevention  Network Security  Remote access security  Security Management  Security Policies  Security Software  Security Threats  Virus Detection Software  Virus Protection  VPN  Vulnerability Assessment  Wireless Security 

Security books, guides, standards and toolkits

RFID and Smart Cards books, guides and reference documents  Biometric books, guides and reference documents  CCTV books, guides and reference documents  Intruder alarms and intrusion detection systems books, guides and reference documents  Monitoring and surveillance books, guides and reference documents  IT Governance, ISO 27001 ISO 17799 and BS 7799 toolkits  Fire, Health & Safety books, guides and reference documents





Ensure that you conduct an effective information security risk assessment that is in line with ISO 27001 by purchasing vsRisk™ Risk Assessment Tool

Need a
Security reference book?
Find it on Amazon
Security books

Article search

Directory search


add your company
Google

ISO 18028 (Network Security Management)
Home | About | Contact | Submit article | Advertise | Newsletter | RSS | Search