3 Reasons Your Employees Can Be More Dangerous Than Hackers – Insider Threat

Insider Threat to your Business

Who poses the biggest cybersecurity risk to your business? If your first thought was a Kremlin cyber-warfare unit, or a dark-web king-pin, you are wrong. The most likely source of a data breach at an SME is one of its own employees aka the insider threat.

According to recent research 54 per cent of breaches at small and medium-sized businesses come from an employee or contractor’s negligence. The number, alarmingly, had increased from 48 per cent when firms were asked the question a year earlier.

If you add in the 7 per cent of breaches that are caused by malicious insiders, then 61 per cent of all data breaches come from people on a company’s own payroll. That is almost double the number that are caused by hackers, who account for 33 per cent.

In reality the number which originate from employees could even be higher – in an astonishing 32 per cent of cases firms said they couldn’t even determine the root cause of a data breach. That is arguably the most disturbing statistic of all. If you don’t know how your data leaked, how can you protect yourself in future?

SMEs were asked: What was the root cause of data breaches at your company?

How do employees cause breaches?

Those numbers might surprise you, but in our experience they ring true. So how do employees cause breaches? Generally, there are three ways.

The first is carelessness. There’s a hundred ways to lose a laptop. Someone can leave it on a train or in a pub, and if the password is easy to guess it can be a goldmine. Once a thief is in you can be certain that he’ll strip it of every bit of data he can – emails, passwords, addresses, dates of birth. Given that he’s already nicked a laptop, he probably won’t hesitate to flog the lot to a fraudster.

The second is being too trusting. On their private email people are always on their guard for phishing emails. But work ones? The company’s systems will filter out anything dodgy, won’t they? It is because people make this assumption that phishing attacks from work emails are so successful. Once they are in, fraudsters don’t exactly shout about it. We’ve all heard too many stories about high-turnover businesses who didn’t realise for months that money was being nicked.

The third common cause of data breaches is revenge. It’s far less common than a cock-up, but as I mentioned above, it accounts for 7 per cent of data breaches at SMEs. If a disgruntled employee decides to pinch personal data or mangle your CRM system, for example, the damage could be irreparable.

How can we help ?

It’s not too difficult to stop any of this happening. All you need are proper systems and training, but we see time and time again that SMEs decide that they can save money on IT security. That’s understandable, but the cost of not doing it properly could be far higher.

To talk to us about how to protect yourself from the insider threat and data breaches today by getting in contact with us here or calling 07958 545129

Past Blogs

Outlook flags your important email

Outlook will flag your most important emails

How much time do you and your team waste sorting through emails each day, trying to figure out what really matters? If you are like most business owners, the answer is...
Can your staff access too much?

Half of staff have too much access to data

Here is a question worth asking yourself. Do you know exactly who in your business can access your critical data right now? And just as importantly, do they actually...
Windows 10 hit ends of life in just over 2 weeks

Free Support for Windows 10 Ends in Just Two Weeks – Here’s What Your Business Needs to Know

Free Support for Windows 10 Ends in Just Two Weeks – Here’s What Your Business Needs to Know What would it take to bring your business to a halt?It’s not always a major...
Better passkey integration in windows

Passkeys will be better integrated in Windows

When was the last time you thought about how you log in to your business accounts? Or how secure those logins really are? For years, passwords have been the standard....
New hire? New security risk

New member of staff… new cyber security risk?

   When you bring someone new into the business, your first thought is usually about getting them set up to succeed. A laptop, email account, access to the right...
Microsoft to Introduce a Unified Naming System for Hackers

Microsoft to Introduce a Unified Naming System for Hackers

Have you ever tried to follow a crime documentary where the main suspect keeps changing names? It’s confusing—and that’s exactly what’s been happening in the world of...
Is your antivirus genuine?

Warning: That Antivirus Website Might Be a Scam

Warning: That Antivirus Website Might Be a Scam When you’re doing your best to protect your business, downloading antivirus software seems like the sensible thing to...
Notepad's Quiet

New Formatting Tools Coming to Notepad: What It Means for Your Business

New Formatting Tools Coming to Notepad: What It Means for Your Business When was the last time you wished Notepad could do a bit more—like make text bold or add a...
Still using Windows 10 ?

Still using Windows 10? Here’s why you need to act now

Imagine if one of your essential business tools suddenly became unsafe overnight. That’s exactly the risk many businesses are facing with Windows 10. Time is running...
Strengthen Your Password

Your Business is Only as Secure as Your Weakest Password

Let’s be honest—do you know for a fact that none of your team members are still using passwords like “12345” or “password123”? If you’re not 100% sure, you’re not...