Insider Threat, le minacce dall'interno Piergiorgio Venuti

Insider threat: identifying and fighting them

Insider threats are difficult to spot because they come from within your organization. Employees, contractors and partners require different levels of login credentials in order to perform their work. Attackers can trick these insiders into accessing them or offering them money to knowingly steal valuable information from the company.

Traditional security solutions focus on protecting the organization from external attackers. This strategy overlooks the damage that an internal resource could do to the organization, whether aware or not. With a Nextgen SIEM solution you have the ability to detect and respond to both external and internal threats, with the help of the UEBA in identifying suspicious behavior.

Insider threat - working in team

Insider threat, the reasons

Employees or contractors identified as at risk are linked to 60% of cases of insider threats, increasing the likelihood that such incidents result in the theft of sensitive company data. Insider threats can be divided into two groups: the distracted and the hostile.

The mechanics of an attack change significantly based on the motivations behind it. It is therefore better to fully understand which characteristics are typical of the motivations behind attacks, in order to be able to stop potential threats before they become violations.

Economic gain

It is clear to each employee how much the data that the company holds can be worth. Here, in the event of a crisis, allowing data to be leaked in exchange for money may seem like a reduced risk. This type of motive must be considered above all when, in times like the present one, an external event (the COVID-19 pandemic) still puts the workplace at risk. With the risk of an imminent layoff, the sale of data that you have access to as an employee is a more than attractive escape route.

Carelessness

Non-compliance with security rules is a very real risk and the most common cause of internal threats. Indolence in compliance with the rules costs organizations an average of $ 4.58mln per year. Threats come, specifically, from some security practices that are not respected, such as failure to log out from the system, writing one’s passwords on paper or reusing them. In this category there are also violations in the use of unauthorized software or a failure to protect company data.

The reasons behind these harmful behaviors are often, unfortunately, particularly simple: security is bypassed by an allegedly greater speed, productivity or, worse, laziness.

Distraction

One type of negligent employee is the distracted one, which is worth treating in isolation because it is more complicated to identify. While the serial behavior of violating the rules is easily identifiable, the distracted, who normally diligently complies with the regulations, is not identified before the only, unfortunate, time when his carelessness does not cost the company an attack that went to successful.

Damage to the company

Among the most subtle insider threats are those of those who have the sole purpose of damaging the company. The motive, in these cases, is usually of a personal nature: an employee who is refused a raise, a disagreement with a superior, etc. The insider then moves to discredit his company, causing damage to its image that results in frightened investors who withdraw their capital or lose customers.

Sabotage and sale of information to third parties

For companies that handle sensitive data, this type of threat is a real risk. Whether the company deals with valuable intellectual property or sensitive data of its customers, there is a high probability that there are those who are interested in having access to that data to use it to their advantage. In this scenario, the actor who wants to get hold of the data recruits an insider to steal it.

Cases that fall under the definition of espionage or media sabotage have been on the rise in recent years. Attacks start from nations such as Russia or North Korea, often involved in this type of trafficking in order to gain political advantages against Western states and organizations.

Defense against insider threats

The defense against attacks that originate from the inside is based on the analysis of the suspicious behavior of those who have access to the systems. The difficulty is found in the non-violent nature of the attacks. It is easy for insiders to not need to breach any security checks, having access from the start.

So how can we immediately catch the threats?

Monitor user access

Insiders with legitimate access choose to abuse their access privileges. Excessive access rights are often granted to reduce the effort that privilege management requires. Avoiding this type of behavior is already a first step in a proactive direction of defense.

Furthermore, with a Nextgen SIEM system it is possible to monitor users with high privilege access to databases, servers and critical applications. At that point it is easier to identify those who abuse their access.

Detect suspicious user behavior

The most sophisticated attacks are based on stealth. To this end, attackers increasingly rely on the compromise of existing internal resources. Once inside the network, they perform lateral movement and steal data under the guise of an internal user.

A system such as that offered by Cyberfero’s SOCaaS allows, among other things, to quickly identify suspicious accounts by detecting abnormal user behavior compared to normal base patterns and the activity of colleagues.

The advantages of a modern system

Shorter response time

Using behavioral analysis it is possible to identify abnormal actions so that we can investigate very quickly.

Advanced behavioral analysis: with the UEBA system (included in SOCaaS), security analysts are able to monitor access and activity of users to the most important resources of the company, allowing to find internal threats with the minimal noise for fast detection and response.

Rapid recognition of users at risk

To enable rapid detection of insider threats, security teams need the ability to link a user’s accounts together to create a universal user profile. This is possible with a Nextgen SIEM system. The analysis of user behavior is also compared to that of a group of peers, to identify anomalous behaviors with greater precision, understanding how a user’s activity is different from that of his colleagues.

The threats that start from within the company perimeter are perhaps the most risky due to their low noise nature. Fortunately, with systems increasingly capable of detecting suspicious behavior and aggregating large amounts of employee data, it is possible to take effective countermeasures to combat this type of attack.

Useful links:

Share


RSS

More Articles…

Categories …

Tags

RSS feed: Unknown Feed Unknown Feed

RSS feed: Full Disclosure Full Disclosure

  • Code Security Review tool September 22, 2026
    Posted by E. Kellinis on Sep 22Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple languages. It's backed by an ML classifier trained on real patches […]
  • HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084) September 22, 2026
    Posted by Joe via Fulldisclosure on Sep 22HP Advance / HP Output Central Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file write/delete CVE-2026-89082, CVE-2026-89083, CVE-2026-89084 ================================================================ SUMMARY ================================================================ Vendor: HP Inc. Product family named by HP: HP Advance Products in HP's update table: HP AC Print & Scan; HP Output Central Components:...
  • CFP No cON Name 2k26 - Palma, Mallorca - Spain September 22, 2026
    Posted by Jose Nicolas Castellano on Sep 22No cON Name 2026 - Palma, Mallorca - Balearic Islands ************************************ *****  Call For Papers        ****** ************************************ https://www.noconname.org/call-for-papers/ Exact place not disclosed until a few weeks before due celebration.     * INTRODUCTIONfulldisclosure () seclists org The organization has  opened CFP proposals. No cON Name […]
  • CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2) September 22, 2026
    Posted by Louis Sanchez via Fulldisclosure on Sep 22Posting this as an update rather than a first disclosure. The advisory went public on 2026-08-04 with no vendor fix. Penpot has shipped two releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on 2026-08-27 -- and I re-checked the code this morning: the […]
  • CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work) September 22, 2026
    Posted by Raschin Tavakoli via Fulldisclosure on Sep 22nullFaktor Security Advisory < 2026-09-10 > =========================================================== Title: Pre-Authentication Remote Code Execution in SAP Extended Passport (EPP) processing library Affected Components: ICM, SAP Web Dispatcher, dialog work processes Vulnerability: Stack based Buffer Overflow CVE: CVE-2026-44756 Impact: Critical CVSS 4.0 Vector:...
  • [0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8) September 22, 2026
    Posted by disclosure via Fulldisclosure on Sep 220day Rubbish Research Team is publicly disclosing a vulnerability in TigerGraph Community Edition 4.2.4. Type: Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (CWE-798) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog […]
  • [0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8) September 22, 2026
    Posted by disclosure via Fulldisclosure on Sep 220day Rubbish Research Team is publicly disclosing a vulnerability in Teltonika RutOS 00.07.06.21. Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact: root command execution on the router, with command output reflected into the JSON response Authentication: authenticated administrator Full technical analysis and […]
  • APPLE-SA-09-14-2026-10 Xcode 27 September 22, 2026
    Posted by Apple Product Security via Fulldisclosure on Sep 22APPLE-SA-09-14-2026-10 Xcode 27 Xcode 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149040. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Xcode IDE Available for: macOS Tahoe 26.6 and later Impact: An […]
  • APPLE-SA-09-14-2026-9 Safari 27 September 22, 2026
    Posted by Apple Product Security via Fulldisclosure on Sep 22APPLE-SA-09-14-2026-9 Safari 27 Safari 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149039. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Safari Available for: macOS Sequoia and macOS Tahoe Impact: A malicious […]
  • APPLE-SA-09-14-2026-8 visionOS 27 September 22, 2026
    Posted by Apple Product Security via Fulldisclosure on Sep 22APPLE-SA-09-14-2026-8 visionOS 27 visionOS 27 addresses the following issues. Information about the security content is also available at https://support.apple.com/149038. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Accelerate Framework Available for: Apple Vision Pro (all models) Impact: Processing […]

Customers