Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

11/1/2010
05:26 PM
50%
50%

Tackling Insider Fraud From The Outside-In

Companies should use the same technologies that authenticate external customers to monitor employees and watch for insider attacks

IT managers spend a lot of their time dealing with malicious code and violations of corporate policy, but insider fraud in the workplace is a major problem that frequently shows up on their radar screen, as well.

In 2009, the average company lost nearly 5 percent of its revenue to fraud perpetrated by employees, according to the 2010 Report to the Nations on Occupational Fraud and Abuse (PDF). Asset fraud -- stealing company resources -- represented 90 percent of the incidents, but only averaged $135,000 in losses per company. On the other hand, financial fraud makes up only 5 percent of all cases of corporate fraud, but it is the most damaging, with a median loss of more than $4 million, according to the report, which is published every two years by the Association of Certified Fraud Examiners (ACFE).

Employees can be tempted by their privileged access to data, says Ben Knieff, director of product marketing for fraud products at Actimize. "They have a high level of access, which gives them a greater opportunity to commit fraud," he says.

The report found that 85 percent of fraud was committed by individuals with no prior records of abuse. Even so, there are a number of proactive steps that companies can take.

Limit Access To Critical Data
Data is difficult to tame. Companies that attempt to control the flow of information inside the company could be setting themselves up for failure, says Shane Sims, director at PricewaterhouseCoopers' forensic practice.

"Data has leaked out everywhere. It is not in the central locations like [companies] think it is," he says. "People have exported it; it is on user systems and in data warehouses and on share points. So to me, tackling the insider threats starts with understanding what kind of data you have and where it is."

Even if companies cannot successfully control the movement of data inside their networks, finding out which employees are accessing the most important data can be enough to prevent the most significant potential fraud, he says.

"Continually do background checks for the high-risk people that have access to the crown jewels," Sims says. "The economic downturn has created the most fertile fields for insider fraud."

Use The Inside Advantage
Companies should not treat external attacks and internal fraud as two different problems. They need to deal with insiders in the same way they deal with external fraud, Actimize's Knieff says. While insiders have an advantage in terms of knowing the network and corporate policies, companies can also collect a great deal of information that would not be available outside the network.

"Because it is an insider, an institution has a chance to deal with the problem with more information than you would normally have with external fraud," Knieff says.

Background checks, monitoring employee usage of assets, and other intelligence can be used to find hints of whether a worker has turned or could turn rogue.

"An employee might be a star employee for a long time, and he may have some life-changing event away from work -- you have to look for spikes in behavior," he says.

Tap Your Employees
Employees can be a big benefit to companies in detecting malicious behavior by other employees.

In about 40 percent of cases, insider fraud was flagged by a third party, and half of those tips were made by an employee, according to the ACFE report. Customer complaints represented about 18 percent of tips. In many cases, signs of the fraudster's actions are evident. The study found 43 percent of perpetrators are living beyond their means and more than a third of fraudsters have had financial problems.

The statistics should underscore that companies should not rely on any particular technology, says Rich Baich, principal with Deloitte's security and privacy practice. "The real power is in the collaboration and integration of the information created by [security] products, when combined with internal information," he says. "You have to have some technologies in the place. But if you really think there is a technology today [that can solve your problems], the bad guys will find a way around it."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark Reading,  8/13/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15239
PUBLISHED: 2019-08-20
In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifi...
CVE-2019-15227
PUBLISHED: 2019-08-20
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-15237
PUBLISHED: 2019-08-20
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVE-2019-15228
PUBLISHED: 2019-08-20
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
CVE-2019-15229
PUBLISHED: 2019-08-20
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.