January 5, 2016 By Christina Thompson 2 min read

Ever hear the expression “don’t let the fox guard the henhouse”? The farmer knows his chickens are valuable and puts them in a safe coop with a lock and a roof, protecting them from external threats such as opossums, cats and hawks.

But what is the farmer doing to protect from within the coop? There are measures the farmer has to take — starting with not inviting the fox inside to be the guard!

Watch Out for the Insider Threat

The threats that companies often overlook come from the inside. While outsiders were found to be responsible for 45 percent of the cyberattacks recorded in 2014, 55 percent of attacks were carried out by those who had insider access to organizations’ systems.

Download the white Paper: Get Smart to Shut Down Insider Threats

The insider threat encompasses not only malicious employees who want to do harm, but also compromised corporate IDs and credentials — for example, a user who inadvertently clicks on a suspicious email attachment that exposes the system (and possibly the corporate network) to malware is an insider threat.

Additionally, trusted third-party contractors also count as an insider threat since they have access and entitlements to systems and data that mirror those of direct employees. These can include electricians, construction workers or other repair personnel who come into physical locations or have access to networks. Abusing this type of third-party access demonstrates that attackers can steal third-party credentials and gain access into networks.

Given the complexity of securing sensitive data against internal and external risks, data security is not a one-and-done event; it’s an ongoing process that must be continuously managed, monitored, enhanced and audited across the entire organization. Data security must be deployed as a process that integrates with other security practices (in particular, identity and access management and vulnerability management) as well as other critical business processes.

How to Form the Security Program

Just like the farmer building a safe environment for his chickens, organizations must build strong security programs to defend and protect against new and emerging threats — such as SQL injection, cross-site scripting and privileged insider breaches, just to name a few — based on the best practices for database security and compliance.

A strong security program can help protect organizations from the external and insider threat by helping them:

  • Prevent data breaches, insider risk, fraud and unauthorized changes to or the destruction of sensitive data;
  • Monitor privileged users such as database administrators, developers, IT administrators, outsourced personnel, etc.;
  • Virtually eliminate the overhead and complexity of native DBMS, big data and file system audit logs;
  • Automate compliance reporting, vulnerability and configuration assessments and data discovery;
  • Encrypt files;
  • Mask confidential data in test, training and development systems;
  • Redact unstructured data in documents, forms and graphics at rest or dynamically.

More from Data Protection

How secure are green data centers? Consider these 5 trends

4 min read - As organizations increasingly measure environmental impact towards their sustainability goals, many are focusing on their data centers.KPMG found that the majority of the top 100 companies measure and report on their sustainability efforts. Because data centers consume a large amount of energy, Gartner predicts that by 2027, three in four organizations will have implemented a data center sustainability program, which often includes implementing a green data center.“Responsibilities for sustainability are increasingly being passed down from CIOs to infrastructure and operations…

Why maintaining data cleanliness is essential to cybersecurity

3 min read - Data, in all its shapes and forms, is one of the most critical assets a business possesses. Not only does it provide organizations with critical information regarding their systems and processes, but it also fuels growth and enables better decision-making on all levels.However, like any other piece of company equipment, data can degrade over time and become less valuable if organizations aren’t careful. What’s even more dangerous is that neglecting data hygiene can expose organizations to a number of security…

Router reality check: 86% of default passwords have never been changed

4 min read - Misconfigurations remain a popular compromise point — and routers are leading the way.According to recent survey data, 86% of respondents have never changed their router admin password, and 52% have never adjusted any factory settings. This puts attackers in the perfect position to compromise enterprise networks. Why put the time and effort into creating phishing emails and stealing staff data when supposedly secure devices can be accessed using "admin" and "password" as credentials?It's time for a router reality check.Rising router risksRouters…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today