RSS

Insider security threats: top tips

Article Date:  Jul 04 2008

The recent exposure of insider trading at The Body Shop demonstrates that the greatest security threats to a business can come from within. Martin Baldock, general manager at IT forensics company Data Genetics International, gives his top tips for guarding against the risks.

This week City regulators fined a former Body Shop employee £85,000 for insider trading before the company issued a profit warning in January 2006. John Shevlin, an IT helpdesk worker at Body Shop, had hacked into senior executives’ confidential emails and accessed a draft of the profit warning that the group was about to issue to the stock market. He then borrowed £29,000 – more than his annual salary – to take out short positions on Body Shop shares, netting £38,000 profit.

Security efforts are often expended disproportionately on preventing external IT breaches while potentially catastrophic internal threats are overlooked or ignored. So what can companies do to minimise the ‘insider threat’?

1. Be sceptical
Criminality and deception in the workplace are commonplace, a fact that is not taught at most business schools, nor considered in many contingency plans. Do not underestimate the determination of the fraudster or hacker to subvert or circumvent the control environment.

2. Don’t rush in
If the worst happens, prevent any instinctive and ill-considered responses to the situation and stick to a pre-prepared incident response plan. Confronting any suspect before all of the available evidence has been assembled can compromise the chances of a successful resolution.

3. Test existing systems

Never presume that existing controls and safeguards are effective. Systems are often wrongly configured while procedures are blithely ignored or not followed correctly or with any real comprehension. Consider also that the fraudster or crooked employee may be responsible for devising the controls, managing them, implementing them, enhancing or upgrading them.

4. Beware times of change

Emerging technologies, procedures, methods, products and business alliances bring with them new and often unexpected risks. Sudden changes and periods of rapid uncontrolled expansion are especially dangerous.

5. Don’t forget external threats

Remain vigilant, assess your defences and enhance them if necessary. Hackers, saboteurs, vandals, fraudsters and virus writers who dwell beyond the firewall are a clear and present danger, but are, generally speaking, minor irritants compared to the devastation that a malevolent employee can inflict.

There’s a well-known saying in the investigations industry: ‘There are no small frauds, just ones that have not had the time to grow as yet.’ Experience suggests that whenever a disgruntled employee finds a way around internal controls, perhaps just as a shortcut initially, he or she will exploit it to its full extent over time.

Comments 

There are currently no comments on this article

Sign up and get...

  • Regular GrowthBusiness newsletters
  • Post comments on articles
Sign up

Free mobile broadband is here

Get FREE mobile broadband when you sign up to BT Business Total Broadband Option 2 or 3. You'll have access to the internet wherever there's mobile or Wi-Fi coverage.  Get connected now.

How to Chose the Right Web Solution

Business BuyGuide pre-qualifies Web Solution Providers, checking testimonials and matching the right suppliers with your business needs.
Click a link below to get free, impartial advice and quickly compare up to 6 quotes without obligation.
Click to Compare up to 6 eCommerce Solution Quotes Now
Click to Compare up to 6 Content Management System Quotes Now
Click to Compare up to 6 Software Development Quotes Now
Click to Compare up to 6 Web Design/Development Quotes Now
Click to Compare up to 6 IT Consulting Quotes Now

Spotlight on AIM 2008

This unique research report provides a comprehensive assessment of AIM and reveals the best-and worst-performing stocks on AIM of last year.

VCT Special Report 2008

A comprehensive report on VCTs and over £1 billion in investment trusts just waiting to be invested in fast growth ventures.

More

Events Calendar

Rosenblatt New Energy Awards

25th February, Natural History Museum, Cromwell Road, London SW7 5BD

M&A Awards 2009

18th February, London Hilton, Park Lane, London

M&A Expanding internationally

27th November, Sofitel London St James

More

More Quick Guides: Technology in Business

The future of credit cards

Increasingly, fraud is following the big money online. GrowthBusiness looks at an innovation with the potential to cut credit card crime on the web.

Business card bliss

Every mover and shaker knows that you don’t make a business a success by sitting behind your desk thinking about strategy.

Recording phone calls: what you need to know

From March next year, UK financial institutions will have to record phone calls relating to client orders.

Advertisement

Poll

What's your hope for 2009?



Have your vote on current issues

People who read this also read

  • Business card bliss

    Every mover and shaker knows that you don’t make a business a success by sitting behind your desk thinking about strategy.
  • Q&A: Choosing the right IT support

    I’ve had a few problems with my computers over the past year – bigger problems than I’ve been able to fix and it’s cost me a packet. I now realise we should get some IT support. How do I go about choosing someone reliable and not too expensive? Are there professional certificates that they should have for example?
  • Reducing currency exposure

    Piers Cracknell, commercial director of currency specialist Moneycorp, comments on the pound’s heavy fall against the dollar and assess its probable impact on growing businesses.

  • Why HR makes you sick

    Human resources (HR) professionals are most likely to become ill as a result of work, according to research.

White Papers

10 Reasons Why Your Email is More Secure in a Hosted Environment versus an In-House

Take an in-depth look at the security risks associated with complex business email configurations and how hosted email solutions stack up.

10 Steps to a Successful CRM Implementation

Follow these 10 steps to help ensure that your CRM implementation is a success, from the planning stages to post-deployment improvements.

3 Steps to Creating Personalized Customer Support Experiences

Learn how tailoring support interactions to fit the specific circumstances of an account can not only increase customer satisfaction, but also increase revenue.

More

Free prize draw!

Complete our short survey and you could win a bottle of champagne.

Click here to enter the