A new Intermedia Insider Risk Report showed that the biggest risk to enterprise IT security is the IT department itself. The report surveyed more than 2,000 IT workers in the U.K. and U.S. earlier this fall. The survey asked questions about whether employees would take data from their companies when they changed jobs, install personal apps on work-owned PCs or operate independently from any tech department for nonapproved purchases.

Results showed IT workers were more willing to go against policy in certain circumstances. For example, almost one-third of IT department respondents would take data if it could benefit them, compared to only 12 percent of the general population.

I am not surprised that IT is its own worst enemy here. Over the years, I’ve met many IT workers who embody this attitude. They don’t feel bound by their own security policies, best security practices or other rules that they create for their fellow employees — and that is a sad and sorry state of affairs.

Malicious insider attacks were also recently designated one of the top four cybercrime trends by IBM Emergency Response Services (ERS). So what can you do about this situation? Here are several suggestions.

Recognize Dangerous Behavior

First, take a look at this report from last year, “Combating the Insider Threat.” It gives some good advice on how to recognize potentially dangerous insider behavior, including tracking a pattern of employees who access the network during off hours, or when IT workers are supposedly on vacation or show abnormal interest in matters outside their scope of duties. They have a number of great recommendations that are very actionable. Some of my favorites include:

  • Deploy data-centric, not system-centric, security. This means you should use your intrusion detection system (IDS) to look more closely at your critical data sources and uses rather than trying to protect your firewalls or servers. Indeed, the report suggested that you “think like a marketer and less like an IDS analyst,” meaning you need to look at what information could be useful to your competitors or other outsiders.
  • Build meaningful baselines. Look at network volumes or frequency of particular recurring patterns. That way, when something abnormal happens — like your soon-to-be-ex-employee downloading 1 TB of customer database — you can actually catch it on tape.
  • Use centralized logging. Logging can detect data exfiltration near insider termination situations. We all can expend a lot of effort tracking what happens when employees are terminated or resign to make sure that their access has been revoked across all systems. Another method is to “announce the use of policies that monitor events like unusual network traffic spikes, volume of USB/mobile storage use, volume of off-hour printing activities and inappropriate use of encryption.” Even if you don’t enact initiatives in each of these areas, at least you’ve put the potential bad actors on notice.
  • Note frequent visits to sites. Frequent visits may indicate low productivity, job discontent and potential legal liabilities (e.g., hate sites or pornography). Don’t go too overboard here, but certainly keep an eye out for this kind of behavior.

Listen to the IT Department

Second, be a better listener and start looking for changes in your corporate culture, even subtle ones. Oftentimes, employee satisfaction (or dissatisfaction) originates from small things: canceling flextime, tightening benefits or micromanagement.

Finally, evaluate your own management style and take stock of recent controversial decisions, as well as why they were so contentious. Perhaps an attitude readjustment is in order to help your own department become more inclusive in its decision-making or operations.

Read the IBM Research Report: Battling security threats from within your organization

More from CISO

CEO, CIO or CFO: Who Should Your CISO Report To?

As we move deeper into a digitally dependent future, the growing concern of data breaches and other cyber threats has led to the rise of the Chief Information Security Officer (CISO). This position is essential in almost every company that relies on digital information. They are responsible for developing and implementing strategies to harden the organization's defenses against cyberattacks.However, while many organizations don't question the value of a CISO, there should be more debate over who this important role reports…

Everyone Wants to Build a Cyber Range: Should You?

In the last few years, IBM X-Force has seen an unprecedented increase in requests to build cyber ranges. By cyber ranges, we mean facilities or online spaces that enable team training and exercises of cyberattack responses. Companies understand the need to drill their plans based on real-world conditions and using real tools, attacks and procedures. What’s driving this increased demand? The increase in remote and hybrid work models emerging from the COVID-19 pandemic has elevated the priority to collaborate and…

Why Quantum Computing Capabilities Are Creating Security Vulnerabilities Today

Quantum computing capabilities are already impacting your organization. While data encryption and operational disruption have long troubled Chief Information Security Officers (CISOs), the threat posed by emerging quantum computing capabilities is far more profound and immediate. Indeed, quantum computing poses an existential risk to the classical encryption protocols that enable virtually all digital transactions. Over the next several years, widespread data encryption mechanisms, such as public-key cryptography (PKC), could become vulnerable. Any classically encrypted communication could be wiretapped and is…

6 Roles That Can Easily Transition to a Cybersecurity Team

With the shortage of qualified tech professionals in the cybersecurity industry and increasing demand for trained experts, it can take time to find the right candidate with the necessary skill set. However, while searching for specific technical skill sets, many professionals in other industries may be an excellent fit for transitioning into a cybersecurity team. In fact, considering their unique, specialized skill sets, some roles are a better match than what is traditionally expected of a cybersecurity professional. This article…