ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Mitigating insider threats

Karl Schorn at Systal warns that cyber risks could be closer than you think

 

An insider can be defined as any person who has or previously had authorised access to or knowledge of the organisation’s resources, including people, processes, information, technology, and facilities.

  

Today’s media often speaks of large-scale espionage or intricate schemes; however, the most common insider threat may surprise you. I say this because you—yes, you (with the best intentions)—could unwittingly kickstart a chain reaction of harm that could bring about reputational, legal or financial threats to your business’s standing. 

 

Background to threats

It is believed that two-thirds of insider incidents are caused by employees accidentally, and without malicious intent. Often, this is the result of carelessness, or the result of no effective guardrails in place by the business. 

 

From phishing attacks to emails sent to the wrong person, employees make mistakes that result in confidential data loss for the organisation and, in severe cases, this can lead to reputational damage. 

 

Often, the best defence for accidental disclosure is maintaining a regular cybersecurity awareness programme. Providing users with the knowledge they need to avoid common mistakes could prove invaluable to an organisation. 

 

It is important to recognise that even with the best training in place, it’s also critical to have clear and understandable cybersecurity policies and procedures that protect the organisation from common, yet risky, user activities.

 

For example, if employees are regularly using a variety of file-sharing sites, offering a sanctioned alternative can help support that workflow while keeping the organisation safe.

 

Striking the balance between ironclad policies and employee productivity is often one of the biggest challenges for security teams. 

 

Well-intentioned circumventions 

Unlike unintentional leaks, misuse indicates that someone attempted to circumvent a control, policy or procedure. 

 

It’s important to recognise that sometimes, people unintentionally, albeit for good reason, go around security controls when they consider them too restrictive or difficult to follow. Other times, these actions may be more intentional. 

 

For example, an employee may start using unsanctioned software to share data with a third party who’s requesting access to locked-down data without following procedure. An employee may also use corporate systems outside of agreed auspices for their own monetary gain such as a small business idea using corporate equipment.

 

Both of these scenarios are examples of misuse and could result in illegal outcomes depending on the policies and laws applicable to the organisation. 

 

Having the right policies can help prevent misuse, but it’s difficult to enforce a policy without knowing more about user and data activity across the organisation.

 

Furthermore, weaknesses in the organisation’s IT infrastructure, such as outdated software, unpatched systems, or inadequate security measures can, with little human interaction, result in exposing new vulnerabilities.

 

Having an Information Security Management System, such as ISO27001 when combined with cybersecurity safeguards offers a robust framework to safeguard your organisation’s digital health, and proactively helps you identify who’s doing what, when and why, which can speed the investigation process in the event of system misuse before it’s too late.

 

Monitoring can come in many forms, ranging from a SIEM (Security Information and Event Management) system at a strategic level, down to an EDR (Endpoint Detection and Response) or XDR (Extended Detection and Response) platform at a tactical level.

 

These advanced tools are instrumental in providing deep insights into behavioural patterns or User Behavior Analytics (UBA). When combined with cutting-edge Intelligence, they can be used not only to proactively prevent threats from external sources but also, crucially, to thwart potential internal security breaches. Additionally, by applying a ’Defence in Depth’ strategy, the system layers multiple security measures, creating a robust, multi-faceted defence against various cyber threats. 

 

Equally, data resides in many forms, hard copies, emails, phones, on-prem cloud and portable devices – your organisation must consider these aspects in its planning. 

 

Should the worst happen, and you find your data is compromised or stolen, Digital Forensic Services offers comprehensive assistance with criminal investigations, fraud detection, data recovery and intellectual property.

 

Digital Forensics and Incident Response support play a key role in assuring your stakeholders when navigating companies through the jumble of management of an Information Security Incident but also when forensic analysis is needed to identify and evidence the source of data theft, providing reports to stakeholders, insurers or even in criminal proceedings if so required. 

 

As you can see, addressing both unintentional and well-intended insider events requires a comprehensive approach that combines technological controls, employee training, effective access management, and a supportive organisational culture that prioritises security and integrity.

 


 

Karl Schorn is VP Professional Services at Systal

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543