Quick: Which is more dangerous: A sophisticated attacker who penetrates your enterprise network from the outside, or a disgruntled worker who chooses to steal or damage data from the inside? The debate continues to rage, and we’ll probably never come to a definitive answer. But one thing is for sure—enterprises today are paying at least as much attention to the threats from inside their trusted computing environments as they are to attacks originating from the beyond their borders.
With all of the hype surrounding the “insider threat,” however, many enterprises overlook one of the most basic truths about security: No two attacks are exactly alike. And, just as external attackers range from teenage script kiddies to highly skilled agents of organized crime, the insider threat can range from well-meaning employees who turn off their antivirus software to a disgruntled IT administrator who plants a logic bomb designed to sabotage his company’s data. This report won’t solve your insider threat problem, nor does it discuss all options for defense. However, we will have a thorough discussion of the types of insider threats your organization may face.
By the time you finish reading it, we hope you’ll have a better understanding of the broad nature of these threats, the risks associated with each-—and be more familiar with one up-and-coming defensive technology. The first step to building a strong defense, after all, is understanding the nature of the danger at hand.