RSS

Insider security threats: top tips

Article Date:  Jul 04 2008

The recent exposure of insider trading at The Body Shop demonstrates that the greatest security threats to a business can come from within. Martin Baldock, general manager at IT forensics company Data Genetics International, gives his top tips for guarding against the risks.

This week City regulators fined a former Body Shop employee £85,000 for insider trading before the company issued a profit warning in January 2006. John Shevlin, an IT helpdesk worker at Body Shop, had hacked into senior executives’ confidential emails and accessed a draft of the profit warning that the group was about to issue to the stock market. He then borrowed £29,000 – more than his annual salary – to take out short positions on Body Shop shares, netting £38,000 profit.

Security efforts are often expended disproportionately on preventing external IT breaches while potentially catastrophic internal threats are overlooked or ignored. So what can companies do to minimise the ‘insider threat’?

1. Be sceptical
Criminality and deception in the workplace are commonplace, a fact that is not taught at most business schools, nor considered in many contingency plans. Do not underestimate the determination of the fraudster or hacker to subvert or circumvent the control environment.

2. Don’t rush in
If the worst happens, prevent any instinctive and ill-considered responses to the situation and stick to a pre-prepared incident response plan. Confronting any suspect before all of the available evidence has been assembled can compromise the chances of a successful resolution.

3. Test existing systems

Never presume that existing controls and safeguards are effective. Systems are often wrongly configured while procedures are blithely ignored or not followed correctly or with any real comprehension. Consider also that the fraudster or crooked employee may be responsible for devising the controls, managing them, implementing them, enhancing or upgrading them.

4. Beware times of change

Emerging technologies, procedures, methods, products and business alliances bring with them new and often unexpected risks. Sudden changes and periods of rapid uncontrolled expansion are especially dangerous.

5. Don’t forget external threats

Remain vigilant, assess your defences and enhance them if necessary. Hackers, saboteurs, vandals, fraudsters and virus writers who dwell beyond the firewall are a clear and present danger, but are, generally speaking, minor irritants compared to the devastation that a malevolent employee can inflict.

There’s a well-known saying in the investigations industry: ‘There are no small frauds, just ones that have not had the time to grow as yet.’ Experience suggests that whenever a disgruntled employee finds a way around internal controls, perhaps just as a shortcut initially, he or she will exploit it to its full extent over time.

Comments 

There are currently no comments on this article

Sign up and get...

  • Regular GrowthBusiness newsletters
  • Post comments on articles
Sign up

Save time and money with Outsourcery

Discover how streamlining and automating your sales processes can help ensure a shorter sales cycle and improved customer retention. Microsoft Dynamics CRM business software provides fast access to useful data in the office, at home or out at meetings. Download this free whitepaper to understand the business benefits

 

Out with the old, in with affordable.

Bring  in IBM System x3650 M2 Express servers powered by Intel® Xeon®  and dramatically lower IT operating expenses. Use  IBM’s online evaluation tool  to see ROI in as little as three months. Find out more

Google Business Apps   

Google Apps lets your business save time and money by outsourcing email, calendar and office applications to Google. Just tell us a couple key stats about your business, and we'll estimate how much a basic Microsoft Exchange 2007 deployment would cost and what you could save with Google Apps.View Google Business Apps.  

Research

  • From video games developers to firms of architects, creative businesses of all kinds struggle to get adequate financing due to a misconception that they cannot be analysed systematically, claims a new report. The study comes from the Centre for Creative Business (CCB), a joint venture between London Business School and University of the Arts London.

Directors' Pay AIM 2009

What should an AIM company pay its CEO or FD?
What should a non-executive director or chairman expect to be paid?
What benchmarks should AIM remuneration committee members be using when
setting pay?

VCT Special Report 2009

This reports principle aim is to provide business owners seeking funding with information about the amount of funds that VCTs have to invest.

More

Events Calendar

The Media Magnate Awards 2009

26th March, Vinopolis, London

More

More Quick Guides: Technology in Business

The Blackberry presenter

The Blackberry Presenter

It's hard to remember when laptops were thought of as revolutionary devices, enabling executives to throw their computer in a bag, hop on the train and deliver a winning presentation at the other end.

The virtual keyboard

First featured on US crime series CSI: Miami, this keyboard with no keys is now available to purchase.

Google Wave

The latest open-source project to come out of Google, Google Wave promises a new concept in personal communication and collaboration.

Advertisement

Poll

What should Alistair Darling deliver in the Budget?




Have your vote on current issues

People who read this also read

  • Liquidity Drivers on AIM

    In the first ever deep analysis of trading values and volumes on AIM, Growth Company Investor, in association with BDO Stoy Hayward, will be shining their research light on the pre-eminent companies on AIM.
  • Your keys to more cash

    If you want to attract a fund manager and their cash to your business, you need to know how much money they have, what types of businesses they are looking for and, most crucially, how to make the initial contact. GrowthBusiness investigates.
  • Augmented reality

    Viewing your surroundings with the overlay of an annotated computer display has long been a mainstay of science fiction. But now the vision of mixing the real world with computer-generated data is finally here.
  • The falling pound and your business

    In the past six months the pound has fallen by more than eight per cent against the dollar and the euro.
  • Go with the flow: Charlie Mullins

    From the age of nine, plucky plumber Charlie Mullins dreamed of picking up a plunger. The 52-year-old saw his company Pimlico Plumbers recently turn over £13.2 million and his clients include Jonathan Ross and Daniel Craig.

White Papers

12 Key Points to Consider When Selecting a Network Scanning Solution

Discover the 12 key points your company should consider before you evaluate and select a vulnerability assessment solution.

1Z0-040 Oracle Database 10G New Features for Administrators Practice Exam

Oracle 9i administrators can certify on Oracle 10G by passing this exam. The ExamForce 1Z0-040 Oracle Database 10G New Features for Administrators practice exam provides their unique triple testing mode to instantly set a baseline of your knowledge and focus your study where you need it most.

4 Ways to Unlock Your Employees' Performance Potential

Discover four proven ways you can tap into the full potential of every employee.

More