January 5, 2016 By Christina Thompson 2 min read

Ever hear the expression “don’t let the fox guard the henhouse”? The farmer knows his chickens are valuable and puts them in a safe coop with a lock and a roof, protecting them from external threats such as opossums, cats and hawks.

But what is the farmer doing to protect from within the coop? There are measures the farmer has to take — starting with not inviting the fox inside to be the guard!

Watch Out for the Insider Threat

The threats that companies often overlook come from the inside. While outsiders were found to be responsible for 45 percent of the cyberattacks recorded in 2014, 55 percent of attacks were carried out by those who had insider access to organizations’ systems.

Download the white Paper: Get Smart to Shut Down Insider Threats

The insider threat encompasses not only malicious employees who want to do harm, but also compromised corporate IDs and credentials — for example, a user who inadvertently clicks on a suspicious email attachment that exposes the system (and possibly the corporate network) to malware is an insider threat.

Additionally, trusted third-party contractors also count as an insider threat since they have access and entitlements to systems and data that mirror those of direct employees. These can include electricians, construction workers or other repair personnel who come into physical locations or have access to networks. Abusing this type of third-party access demonstrates that attackers can steal third-party credentials and gain access into networks.

Given the complexity of securing sensitive data against internal and external risks, data security is not a one-and-done event; it’s an ongoing process that must be continuously managed, monitored, enhanced and audited across the entire organization. Data security must be deployed as a process that integrates with other security practices (in particular, identity and access management and vulnerability management) as well as other critical business processes.

How to Form the Security Program

Just like the farmer building a safe environment for his chickens, organizations must build strong security programs to defend and protect against new and emerging threats — such as SQL injection, cross-site scripting and privileged insider breaches, just to name a few — based on the best practices for database security and compliance.

A strong security program can help protect organizations from the external and insider threat by helping them:

  • Prevent data breaches, insider risk, fraud and unauthorized changes to or the destruction of sensitive data;
  • Monitor privileged users such as database administrators, developers, IT administrators, outsourced personnel, etc.;
  • Virtually eliminate the overhead and complexity of native DBMS, big data and file system audit logs;
  • Automate compliance reporting, vulnerability and configuration assessments and data discovery;
  • Encrypt files;
  • Mask confidential data in test, training and development systems;
  • Redact unstructured data in documents, forms and graphics at rest or dynamically.

More from Data Protection

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

3 Strategies to overcome data security challenges in 2024

3 min read - There are over 17 billion internet-connected devices in the world — and experts expect that number will surge to almost 30 billion by 2030.This rapidly growing digital ecosystem makes it increasingly challenging to protect people’s privacy. Attackers only need to be right once to seize databases of personally identifiable information (PII), including payment card information, addresses, phone numbers and Social Security numbers.In addition to the ever-present cybersecurity threats, data security teams must consider the growing list of data compliance laws…

How data residency impacts security and compliance

3 min read - Every piece of your organization’s data is stored in a physical location. Even data stored in a cloud environment lives in a physical location on the virtual server. However, the data may not be in the location you expect, especially if your company uses multiple cloud providers. The data you are trying to protect may be stored literally across the world from where you sit right now or even in multiple locations at the same time. And if you don’t…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today