Categories

No categories

How to recognise an insider in a company and prevent his activities?

May 09, 2025
Eye23
Book8 min
Background
The law, of course, protects your business from trade secret theft, but it does so post facto, when the money is finally lost and your reputation can no longer be saved. Experts at the University of New Mexico's cybersecurity lab divide insider attacks into two types: situational, i.e., isolated information leaks that occurred due to negligence or system failure, and planned. In other words, in one way or another, they are the result of malicious intent. ‘The mole could be anyone: your right-hand man or another economist whose name you don't even remember.

According to a report by Secure Automatic Technologies, 99% of European organisations have experienced financial losses at least three times in their history due to insider activity. In the Insider Threat 2023 report from the American Insider Threat Association, 74% of organisations surveyed say insider attacks have become more frequent. And an equal number say they are at least vulnerable to insider threats. More than half of organisations have experienced an insider threat in the last year, and 8% have experienced more than 20 threats. It also notes that 61 per cent of bankruptcies in the US today are caused by insiders, with the threat becoming particularly acute at times of large contracts.

Types of insiders

"An insider" is an employee of an organisation who has access to information that is not publicly available. An insider is an employee of an organisation who has access to information that is not publicly available.

Anyone can become an insider (i.e. anyone at all). However, behavioural psychology and HR profiling make it possible to identify a mole at the interview stage or prevent data theft in an already established team. Personnel psychologists distinguish six types of insiders: negligent, manipulated, resentful, disloyal, moonlighting and embedded employees. Quite situationally, who can be considered the least dangerous link on this scale?

"Negligent" employees may leak information inadvertently (and it may be irreparable), while the activities of «embedded» employees are aimed directly at undermining your business.

  • "Negligent" insider is the most common type of business insider, also called "careless". Typically, this is a rank-and-file employee who performs a stream of mechanical work. Violations of security policy are unmotivated, mostly the unintentional removal of information from an organisation's digital loop. The incident itself is not that dangerous, but the threat will increase if sensitive data falls into the wrong hands. A careless email or a sticker with login details for a corporate network account carefully taped to a work computer monitor is another matter.

  • "Manipulated" insider or "Pinocchio". Just like in Carlo Collodi's fairy tale, the main problem of this type of employee is naivety and excessive gullibility. Everything opposes the manipulated employee: starting with colleagues and ending with what is nowadays called "social engineering" (banal scamming). Let's imagine: a call is made, the voice on the other end of the line introduces itself as the director of a real branch of the company, describes the problem in maximum detail and asks (in the name of efficiency, of course) to bypass the existing commercial security policy and send critical documents to his personal e-mail. Without even thinking about the possible threat, our "Pinocchio", rubbing his hands with anticipation of a substantial bonus, sends the file directly to the competitor's e-mail. Done – the leak has taken place.

  • "Offended" ("saboteur"). This type of employee does not seek to steal your company's information, nor does he care at all about the value of intellectual property or the practical benefits of unauthorised use of databases. He seeks to cause harm in any way he can. The grievance driving such an employee could be anything: insufficient pay, unappreciation in the team, inappropriate place in the office hierarchy... The employee does not intend to leave the company, he will stay ‘in the shadows’ until he has done maximum damage. For example, he may falsify or destroy important documents, steal office utensils, or loiter in the workplace. Based on his own ideas about the value of information, this employee determines what data it makes sense to steal and to whom to pass it on. Often it is the press or shadow structures.

  • "Disloyal" insiders. Most often coincide with the "offended" type, but who have firmly decided to change their place of work or open their own business and become a bold competitor. For some reason it has become customary that an employee leaving the commercial department takes with him a copy of the client base, and from the economic department – the financial one. This is the soviet habit of "leaving souvenirs from the desk" and should be got rid of. The most common way of embezzlement is "industrial necessity". Disloyal employees differ from "offended" insiders in that, having stolen information, they do not hide the fact of theft, and sometimes use it as a guarantee of a comfortable dismissal with compensation and positive recommendations.

  • "Part-time workers" insiders, i.e. the type that EY experts were talking about. These are employees who are in dire need of money. In fact, it is the most capacious type of insider. This includes people who have decided to make a couple of thousand, as well as those who have become insiders involuntarily, as a result of blackmail, extortion or influence of third parties. Depending on the conditions, they may fake a production necessity, and in the most severe cases, they may hack or bribe other employees.

  • "Embedded" insiders or spies from Hollywood Cold War thrillers. As an example, one of Anexet's recent cases: the company was engaged in the production of piece goods using CNC (numerical control) machines. The customer suspected the development department of "leaking" technical documentation, namely drawings, to competitors. The difficulty was that these were not just drawings, but programmes, according to the algorithms of which the machines worked. The software was loaded into the equipment through a local network directly from the company's office. In the machine itself, it was sorted into folders, from where the operators took them and loaded them into the processing software. The nuance was that the racks of the machines were sealed and sealed shut, with only the monitor, mouse and keyboard coming out. It was physically impossible to connect the reader directly to the computer. It turned out that the mouse was connected to the machine via USB. A co-worker found a similar device and fitted a scrap USB hub inside the mouse, into which the spy stick was plugged. Over the course of a month, the spy device stole information and then went to a competitor. Anexet discovered the reason for the leak even at the stage of test use.

How to counter the insider threat

If you divide negligent employees into those who are finished and those who can still be saved, Anexet's HR group recommends that your HR department pay close attention to "negligent" and "manipulative" employees. Perhaps they simply lack an information security culture. They don't realise the damage their ill-considered gesture can do to your business, while the "resentful", "disloyal", and "cossacks" should be disposed of as soon as possible. Mostly the "offended", as you will never benefit from their activities again.

Install a DLP system. The software will create a powerful secure digital loop around your organisation's internal network and will signal any attempts to take confidential information outside the perimeter of the enterprise. The system provides for filtering and analysing traffic by statistical and semantic value, which makes the search for disloyal employees, insiders and employees undermining the economic security of your business automatic. Acting within defined security policy, the DLP information protection system will notify authorised personnel when protocols are breached, whether it is an e-mail with questionable content or the printing of confidential documents. The audit and monitoring function of the DLP system will allow you to track employee activity at the workplace and identify weaknesses in the security system.

Monitor accounts that are not up-to-date. Often, information leaks are caused by employees who have left the organisation and still have valid login details. However, they may not be the perpetrators – logins and passwords can fall into the hands of current employees who are committing illegal acts from within the organisation and diverting suspicion away from themselves. To identify such individuals, use bait and pay attention to "traces" of their work. Conscious insiders tend to delete large amounts of files in an attempt to disguise their activities. The DLP system saves the entire chronology of employee activities and offline backs up all files on the corporate network.

A common method of identifying insiders is bait-and-switch. An attacker is constantly "scouring" the corporate network in search of critical information. You can "leave" an array of extremely valuable files in the public domain and see who sends the archive to USB, cloud or print.

How do you recognise an insider?

It is not only the functionality of DLP systems that can recognise an insider; it can be done even at the interview stage. Similar universal tools – interviews and experiments – can be used for this purpose. An interview means a survey processed using the sociometric methodology. The same methods can be applied in an already established team. Samsung's HR service analyses the corporation's staff for risk by means of a simple verbal questionnaire: "Who would you not take on a business trip?" or "With whom would you share a new creative idea?". Repeated surveys can be conducted but using different questions to ensure reliability of the information. By observing an individual's choices, it is possible to study his or her typology of social behaviour in the group. The sociometric technique does not require more than 15 minutes.

The experiment consists in deliberately creating special conditions for the observed person in order to determine by his actions in certain situations how egocentric he is, whether he can empathise with other people.

Remember that sensitive information in wide-access environment is like an ice cube – at each stage the ice gets smaller, and your hands are in the water. DLP (data leakage prevention) systems can help you deal with this and other possible threats. Their main task is to detect, control and prevent potential threats, protect important data and monitor employees at their workplace. Our DLP system is an affordable solution in this area.

You can familiarise yourself with Anexet free of charge for 30 days. All necessary information is available at the link.
Advertisement

Explore the power of Anexet right now!

Start Free Trial