
teissTalk host Jenny Radcliffe was joined by Sarah Norman-Clarke, Head of Information and Cyber Security, Department for Transport as lead guest; Ian Lowe, Head of Industry Solutions, Okta; and Alain De Maght, Chief Information Security Officer & Data Protection Officer, Hôpitaux Iris Sud - Iris Ziekenhuizen Zuid
According to an article in the Infosecurity Magazine, based on the analysis of 6,800 incidents, homeworking has driven a 44% surge in insider threat, as well as a 34% increase in associated costs. WFH involves employees getting more remote access to sensitive data, which they often take with themselves when leaving the organisation. The problem isn’t helped by the fact that an insider incident takes 85 days on average to contain. Some in the audience were of the opinion that the language of insider threat shouldn’t be used to hide poor practices that have been normalised by the rush to enable remote working. The Businesses at work report has, for example, revealed that apps used in a corporate environment are often not connected in the right way and there is no end user policy in place. Moreover, a maturing dark web means that stolen data is easier to sell. Regular checks which are routine in a physical office are impossible to carry out in a hybrid environment, therefore policy breaches and compromised wi-fi networks often go undetected. Security culture has always been a weak link and organisations should from time-to-time step back and assess their processes to see if they follow good practice. Implementing a Zero Trust framework, where no one is trusted just because they have a certain role, is a great way of dealing with insider threat. The focus should be on identity management and not on managing how individuals get access to the corporate system.

Disjointed processes and disconnected systems are a hotbed for data exfiltration committed by employees. Businesses use up to 180 cloud-based applications on average and follow a hybrid approach even within the cloud. With automation it becomes much easier to connect the multitude of disparate apps and secure them. Alain made a mention of NIS2, the EU’s updated directive on cybersecurity. Whether the UK government is about to catch the EU train or is more likely to diverge is too early to say. However, on January 19, 2022, DCMS commenced a public consultation on proposed changes to the UK’s cybersecurity regime. But businesses need to organise their processes for themselves when dealing with JML – e.g., how they collect the laptops of leavers, shut down their accounts or deal with exceptions regarding the use of home broadband networks. Companies need to manage insider threat more proactively and, for example, do some scenario testing or leverage user feedback in order to implement better and more secure systems based – ideally – on security frameworks and standards, as well as ZeroTrust best practices.
One of the golden rules of information security is that if you get a very urgent email, take your time before you reply to it. Three years into the pandemic there are no excuses for failing to implement proper information security measures. However, avoid the mistake of trying to fix everything at one go. You need to identify your risks, grade and prioritise them. Your departure point should be the kind of experience you want to deliver to your JMLs and then you should identify the technologies and infosecurity frameworks required to achieve it. Check out App Protect, a framework that can help you create an efficient security policy against the OWASP TOP10 threats at pace.
Watch on-demand here.

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543