ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Are you ignoring your biggest source of cyber risk?

insider threat
insider threat

Chris Waynforth at Imperva explains why the failure to prioritise internal cyber-security threats is having a major effect on organisational IT security

 

There’s an old saying: “Don’t tell me what you value; show me your budget and I’ll tell you what you value.”

 

A similar principle can be applied to cyber-security. Almost everyone in cyber-security knows that insider threats are a problem. However, new research has found that the vast majority (70%) of organisations in EMEA don’t have a strategy in place for stopping them, while more than half (59%) aren’t even prioritising them as an issue.

 

These figures are baffling when considering the fact that insider threats have been responsible for most (59%) of the data security incidents companies have experienced in the last 12 months.

 

It looks like an inside job

That companies are failing to invest in tools and strategies to help combat insider threats is all the more worrying given the moment that we are in. With the pandemic having shifted so many people to remote working, many employees now operate outside the typical security controls that businesses have in place, meaning it’s that much harder to identify and prevent insider threats. 

 

At the same time, data has never been more exposed, as the explosive growth of APIs in recent years shows. APIs often connect directly to sensitive data and if one is badly configured, whether because of malicious intent or carelessness, it can result in unwanted exposure of important information and act as an invitation to breaches. 

 

On top of that, “the Great Resignation” has created a situation ripe for exploitation, either maliciously or unintentionally. With turnover in the UK at record levels, sensitive data can easily be stolen by ex-employees, either for revenge or to help themselves in their future roles.

 

Other times, important information can simply be taken by accident by a careless employee walking out the door without realising they’re still holding company assets. 

 

Regardless of how it happens, the prospect of a rising number of insider threats should be deeply concerning for any organisation. Previous research has found that a quarter (24%) of the biggest data breaches to happen in the last five years has been the result of an insider threat.

 

What’s stopping you?

As usual, there are a multitude of reasons why businesses are ignoring the dangers posed by insider threats. In many cases, it’s simply a lack of budget (39%), but lack of internal expertise (38%) and a lack of executive sponsorship (33%) are also key blockers.

 

Whatever the reason, the upshot is that most businesses (58%) don’t have a dedicated insider threats team, a shocking statistic, given the scale and severity of cyber events related to insider threats.

 

As a comparison, if you’re a football fan and more than half the goals your team concedes came from set pieces, you’d demand that the manager hire a new specialist coach as soon as possible. 

 

The fact is, although investment in cyber-security has increased for most businesses, most of that spending has focused on combating external threats rather than internal. This lack of investment is doubly damning given how difficult it can be to detect insider threats. Internal users have legitimate access to critical systems, rendering them invisible in the eyes of traditional security solutions such as firewalls and intrusion detection systems (IDS). 

 

A failure to prioritise insider threats has translated into a lack of visibility into how legitimate users are behaving, and what they’re doing with company data, and is a key reason why the majority of cyber incidents are internally driven.

 

Knowing your business inside and out

As with all cyber-security challenges, there is no single magic bullet for dealing with insider threats. However, there are a number of key steps every organisation can take to dramatically reduce the risk of damaging breaches, both malicious and unintentional. 

 

First and foremost, businesses should look at developing a clear and consistent strategy, as well as a dedicated team focused on negating insider threats. But beyond that, they should also ensure they’re implementing:

  • Data governance: Sensitive information can reside in all sorts of formats - structured, semi-structured, and unstructured - so, at minimum, every business needs the ability to discover and classify all data assets across the network so that security controls and policies can be applied. Moreover, good governance should include the pathways to data as well, such as APIs, to provide layered protection. For instance, having full visibility into how these pathways have been configured, who has access, and what traffic is flowing through them so that insider threats are being guarded against from all angles. 
  • Data activity monitoring and access control: Once all assets have been discovered, it’s important to put in place measures to mitigate insider threats by controlling user rights to sensitive data, detecting changes, and blocking or alerting on policy violations. 
  • Data risk analytics: Finally, businesses need to automate the detection of problematic, risky, or malicious data access behavior across data stores through intelligent analytics that can relieve pressure on security teams, rather than complicating their workload with false flags or minor problems.

 

Implementing such measures, along with techniques such as data masking, can substantially reduce any organisations exposure to insider threats, especially when using standardised data controls to minimise any potential blind-spots.

 

A perfect storm?

If you were to draw up the ideal conditions to allow insider threats to flourish, it might well look like the current situation: a surge in people changing or leaving their jobs, spiraling amounts of data being held by most organisations, and a lack of resources or people devoted to tackling the problem.

 

The data is clear - insider threats are a constant and significant danger, yet the vast majority of businesses are failing to get to grips with the problem. 

 

It’s not that insider threats are an insurmountable challenge. With proper resources and a dedicated team almost all insider threats can be mitigated before they become an issue. But that requires businesses to understand the risks they’re exposing themselves to and invest in the right solutions to address them.

 


 

Chris Waynforth is AVP Northern Europe at Imperva

 

Main image courtesy of iStockPhoto.com

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543