Threat Intelligence

8/16/2017
02:50 PM
50%
50%

Insider Threats Loom Large for Security Pros

Insider threats pose a greater challenge to security pros than external threats, according to a recent survey.

When it comes to insider threats, 61% of infosec professionals consider it more difficult to detect and prevent these attacks than external ones, according to Crowd Research Partners' 2017 Threat Monitoring, Detection and Response report released this week.

The survey, which queried 400 cybersecurity professionals, found 51% believe internal threats are on the rise over last year, with 61% of respondents attributing them to inadvertent breaches. User training is the leading method among 57% of the survey respondents for tackling insider threats, the survey found.

Slightly more than half of survey respondents point to sensitive data linked to personal devices as the catalyst driving the rise in attacks overall, according to the survey.

Meanwhile, the survey found that 30% of respondents say their organization's policies and practices are adequate in dealing with insider threats. As for an organization's overall security posture, 37% of survey respondents believe their companies are well situated.

Read more about the survey here

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
100%
0%
RyanSepe,
User Rank: Ninja
8/17/2017 | 6:52:37 AM
Internal Access
Insiders already have access to the internal network that sits behind the security safeguards. External entities still have to traverse those safeguards but all of them can be subverted by an internal user clicking on a malicious link in an email. This premise is why user awareness training is paramount at organizations.
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Symantec Intros USB Scanning Tool for ICS Operators
Jai Vijayan, Freelance writer,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3988
PUBLISHED: 2018-12-10
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the...
CVE-2018-10008
PUBLISHED: 2018-12-10
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended...
CVE-2018-10008
PUBLISHED: 2018-12-10
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace br...
CVE-2018-10008
PUBLISHED: 2018-12-10
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jen...
CVE-2018-10008
PUBLISHED: 2018-12-10
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.