
Chris Waynforth at Imperva explains why the failure to prioritise internal cyber-security threats is having a major effect on organisational IT security
There’s an old saying: “Don’t tell me what you value; show me your budget and I’ll tell you what you value.”
A similar principle can be applied to cyber-security. Almost everyone in cyber-security knows that insider threats are a problem. However, new research has found that the vast majority (70%) of organisations in EMEA don’t have a strategy in place for stopping them, while more than half (59%) aren’t even prioritising them as an issue.
These figures are baffling when considering the fact that insider threats have been responsible for most (59%) of the data security incidents companies have experienced in the last 12 months.
That companies are failing to invest in tools and strategies to help combat insider threats is all the more worrying given the moment that we are in. With the pandemic having shifted so many people to remote working, many employees now operate outside the typical security controls that businesses have in place, meaning it’s that much harder to identify and prevent insider threats.
At the same time, data has never been more exposed, as the explosive growth of APIs in recent years shows. APIs often connect directly to sensitive data and if one is badly configured, whether because of malicious intent or carelessness, it can result in unwanted exposure of important information and act as an invitation to breaches.
On top of that, “the Great Resignation” has created a situation ripe for exploitation, either maliciously or unintentionally. With turnover in the UK at record levels, sensitive data can easily be stolen by ex-employees, either for revenge or to help themselves in their future roles.
Other times, important information can simply be taken by accident by a careless employee walking out the door without realising they’re still holding company assets.
Regardless of how it happens, the prospect of a rising number of insider threats should be deeply concerning for any organisation. Previous research has found that a quarter (24%) of the biggest data breaches to happen in the last five years has been the result of an insider threat.
As usual, there are a multitude of reasons why businesses are ignoring the dangers posed by insider threats. In many cases, it’s simply a lack of budget (39%), but lack of internal expertise (38%) and a lack of executive sponsorship (33%) are also key blockers.
Whatever the reason, the upshot is that most businesses (58%) don’t have a dedicated insider threats team, a shocking statistic, given the scale and severity of cyber events related to insider threats.
As a comparison, if you’re a football fan and more than half the goals your team concedes came from set pieces, you’d demand that the manager hire a new specialist coach as soon as possible.
The fact is, although investment in cyber-security has increased for most businesses, most of that spending has focused on combating external threats rather than internal. This lack of investment is doubly damning given how difficult it can be to detect insider threats. Internal users have legitimate access to critical systems, rendering them invisible in the eyes of traditional security solutions such as firewalls and intrusion detection systems (IDS).
A failure to prioritise insider threats has translated into a lack of visibility into how legitimate users are behaving, and what they’re doing with company data, and is a key reason why the majority of cyber incidents are internally driven.
As with all cyber-security challenges, there is no single magic bullet for dealing with insider threats. However, there are a number of key steps every organisation can take to dramatically reduce the risk of damaging breaches, both malicious and unintentional.
First and foremost, businesses should look at developing a clear and consistent strategy, as well as a dedicated team focused on negating insider threats. But beyond that, they should also ensure they’re implementing:
Implementing such measures, along with techniques such as data masking, can substantially reduce any organisations exposure to insider threats, especially when using standardised data controls to minimise any potential blind-spots.
If you were to draw up the ideal conditions to allow insider threats to flourish, it might well look like the current situation: a surge in people changing or leaving their jobs, spiraling amounts of data being held by most organisations, and a lack of resources or people devoted to tackling the problem.
The data is clear - insider threats are a constant and significant danger, yet the vast majority of businesses are failing to get to grips with the problem.
It’s not that insider threats are an insurmountable challenge. With proper resources and a dedicated team almost all insider threats can be mitigated before they become an issue. But that requires businesses to understand the risks they’re exposing themselves to and invest in the right solutions to address them.
Chris Waynforth is AVP Northern Europe at Imperva
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543