Categories

No categories

Prevention of data leaks by superuser

June 08, 2025
Eye23
Book8 min
Background

In the absolute majority of companies, work is organised according to the hierarchical principle: from the top management to the rank-and-file employees. Everyone has his/her own area of responsibility, and everyone does his/her job. It is clear that the company's management and executive staff interact with more important and confidential information.

Privileged users or superusers of databases are often targeted by hackers, and some of them, using their extended rights, can use information not only for business purposes.

According to statistics, the main cause of data leakage is human factor, which accounts for 95% of all incidents. It has long been no secret that it is not hackers who are most often to blame for information leaks, but the employees of organisations themselves.

According to results of the survey on the threat of information leakage by company employees, 90% of surveyed companies did leak confidential data, such as information about employees, documents on financial operations of the company, and databases with customer data over the past year. Most of leaks occurred due to deliberate leaking of data by company's superusers, while others were due to inattention and gullibility. 

The risk of losing or leaking information grows exponentially when staff are transferred to the remote working format and it becomes much more difficult to control the actions of employees. Particular attention should be paid to department managers, managers, employees of the company's information security department, as they have access to the most important data. Also, some incidents happen due to fault of employees who are leaving the company and who, for their own reasons, may take company's confidential data with them.

Speaking of leaks, we should also mention internal data leakage – unauthorised copying of data by company employees. It is impossible to completely protect the organisation from such cases, but you can significantly reduce the risks of an incident. To do this, it is necessary to regulate the use of data for employees:

  • establish liability for disclosure of information;

  • create appropriate documentation, such as a non-disclosure agreement.

The company should introduce the trade secret protection regime and prepare documents clearly stating which information is trade secret, who is obliged to protect and communicate it and how, and what measures will be taken against a violator. Such agreements should be signed not only with employees, but also with contractors and intermediaries.
  • provide access to information according to the hierarchy and responsibilities of employees;
The easiest way to secure valuable information is to differentiate access to data and give employees only data they need for their work. For example, give a manager not entire database, but only contacts of clients with whom he or she interacts, give an smm specialist information not about all the department's projects, but only data about social networks and platforms needed for content creation.
  • exercise enhanced control over those employees who have access to, and frequently work with, sensitive data by virtue of their occupation;
  • control communication channels with specialised systems.

In this case, "special system" refers to the installation of DLP. The DLP system is software solution that monitors data transmission through all communication channels, i.e. it can prevent attempt to transmit data to unauthorised parties.

As an example, consider Anexet Ultimate from Software Limited, the popular DLP system on the market that has gained the trust of customers.

Anexet Ultimate checks all transactions in real time, blocks suspicious activity, notifies security, monitors attempts to transmit information to outsiders, and:

  • monitors the actions of unauthorised users in the system;

  • controls the printing/transfer of files to devices;

  • controls/restricts access of USB and other external devices to the system;

  • recognises text, audio and video files and makes recordings from computer screen or microphone.

Undeniable advantages can also include:

  • 2in1 system (employee control + leakage protection);

  • server requirements are lower than those of competitors;

  • free system test on Anexet Ultimate equipment;

  • training and assistance in finding information leaks;

  • system integration in 1 day.

Solving the issue of data access with simple, i.e. non-privileged users is usually not problem, but rather requires good management rather than technical solutions.

Data leaks caused by privileged company employees are not rare problem, but important cyber threat vector that requires appropriate measures to prevent accidental or intentional loss of sensitive information.

It is recommended that senior management develop the plan to implement the necessary Information Security processes and software, as well as address vulnerability testing of the existing system.

 

Advertisement

Explore the power of Anexet right now!

Start Free Trial