SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Data Warehousing

Corporate databases at greater risk of insider attacks

Corporate databases at greater risk of insider attacks

By:  Jaikumar Vijayan  On: 27 Oct 2008 For: Computerworld US(NA) Creator

Bad times bring out inside badies. When economies falter, IT managers have better batten down the hatches against insider threats, according to security experts

About a year ago, a senior manager at Pilz GmbH left the company to work at a rival firm -- and took some classified data about an unfinished vision-based camera safety system with him.

If it hadn't been for the honesty of executives at the rival business, more than five years of research and development work would have gone down the drain, said Steve Farrow, managing director at Pilz, which is in Ostfildern, Germany. "It would have impacted our product development and allowed one or two competitors to catch up with us much more quickly," he said. Farrow didn't identify the rival company.

The incident is a classic example of the threat rogue insiders pose to your data and systems at any time. But as the faltering economy forces companies to turn to job cuts, wage and bonus freezes, outsourcing and other belt-tightening moves, the risks are multiplying, analysts said.

"All of these [cost-cutting measures] increase risk for the company from an insider perspective," said Shelley Kirkpatrick , director of assessment services at Management Concepts Inc., a consulting firm in Vienna, Va. "When there is uncertainty, it creates stress for employees [and] makes the company more vulnerable."

Thus, corporate executives must be very vigilant, especially today, in learning what warning signs to look for and how to respond to them, said Matt Doherty , a senior vice president at Hillard Heintze LLC, a Chicago-based security consulting firm.

Red flags could include an employee who suddenly starts working long hours for no obvious reason, or someone seeking access to systems and information not needed in his job. IT managers should also be on the lookout for employees who print out large volumes of data after hours or who send information to themselves via e-mail.

Doherty also said it's important that companies train supervisors to spot distressed employees. "It's critical for a supervisor to be aware of the employees -- who they are and what's going on in their lives. It's really about keeping a finger on the pulse," he added.

Kirkpatrick suggested that companies set up a cross-functional team consisting of IT, human resources, corporate security, legal and operations department managers to quickly deal with potential insider attacks.

"There are [often] warning signs. But they are not always listened to," she said.

Ted Julian , vice president of marketing at Application Security Inc., a New York-based vendor of security tools, added that companies should have controls to monitor privileged user activity to make sure managers and technology professionals with elevated access rights don't "rob you blind." "Some sort of monitoring on your most sensitive systems is a must," he said.

Several recent incidents show that the threat of data theft from insiders with privileged access should not be underestimated.


Sign up for our Newsletters
Tags: monitor












Print |  Views: 901   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jaikumar Vijayan Jaikumar Vijayan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Can the Olympics really threaten your IT security?
Can the Olympics really threaten your IT security?Fortinet says the higher volume of digital traffic flowing during the Olympics will attract the attention of cyber criminals and increase your risk of being attacked. IDC Canada analyst David Senf also weighs in on the issue
Remote workers too risky, say IT managers
Remote workers too risky, say IT managersNearly nine in 10 IT managers fear the security risks caused by remote working practices, new research has revealed. The main concerns stem from the fact that hackers can use remote connections as a "back door" into the company network or to the risk of the corporate network by the use of unauthorized software and Internet access.
It's time for a new password
It's time for a new passwordUsers hate passwords. They don't like entering them to gain access to a system; they don't like inventing new ones every 30 or 60 or 90 days; and they really don't like having different passwords for different systems. The more active and mobile the user, the more often they must enter passwords, and so their resentment grows.
What laptop reviews won't tell you
if the doctor is to be believed, our first child will arrive on time in about two weeks. that means we are officially late setting up the nursery, which involv
blog comments powered by Disqus