July 14, 2015 By Michelle Alvarez < 1 min read

Imagine a scenario: In a single day, a disgruntled employee downloads sensitive or confidential company documents, announces his or her resignation, and gives the inside scoop to a journalist friend. The revelations hit the headlines, and the company’s legal and public relations teams spend millions trying to repair the company’s tarnished brand.

While you’re busy guarding the perimeter, insiders can cause your business significant damage and financial loss. Whether breaches are caused by malicious individuals or just carelessness on the part of the employee, the 2015 IBM Cyber Security Intelligence Index found that 55 percent of attackers are insiders (nearly half are inadvertent actors).

This report, researched and written by the IBM Managed Security Services Threat Research group, examines the risks posed by individuals inside your organization who have access to proprietary information or sensitive data. What exactly are these insider threats, what types of damage and financial loss can they cause, and what can organizations do to protect themselves?

Read the full research report: Battling Security Threats From Within Your Organization

More from X-Force

Strela Stealer: Today’s invoice is tomorrow’s phish

12 min read - As of November 2024, IBM X-Force has tracked ongoing Hive0145 campaigns delivering Strela Stealer malware to victims throughout Europe - primarily Spain, Germany and Ukraine. The phishing emails used in these campaigns are real invoice notifications, which have been stolen through previously exfiltrated email credentials. Strela Stealer is designed to extract user credentials stored in Microsoft Outlook and Mozilla Thunderbird. During the past 18 months, the group tested various techniques to enhance its operation's effectiveness. Hive0145 is likely to be…

Hive0147 serving juicy Picanha with a side of Mekotio

17 min read - IBM X-Force tracks multiple threat actors operating within the flourishing Latin American (LATAM) threat landscape. X-Force has observed Hive0147 to be one of the most active threat groups operating in the region, targeting employee inboxes at scale, with a primary focus on phishing and malware distribution. After a 3-month break, Hive0147 returned in July with even larger campaign volumes, and the debut of a new malicious downloader X-Force named "Picanha,” likely under continued development, deploying the Mekotio banking trojan. Hive0147…

FYSA – Critical RCE Flaw in GNU-Linux Systems

2 min read - Summary The first of a series of blog posts has been published detailing a vulnerability in the Common Unix Printing System (CUPS), which purportedly allows attackers to gain remote access to UNIX-based systems. The vulnerability, which affects various UNIX-based operating systems, can be exploited by sending a specially crafted HTTP request to the CUPS service. Threat Topography Threat Type: Remote code execution vulnerability in CUPS service Industries Impacted: UNIX-based systems across various industries, including but not limited to, finance, healthcare,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today
Press play to continue listening
00:00 00:00