Register | Forgot password?
Switch to Arabic
Monday, November 30 - 2009

New market research challenges CXOs to think differently about insider risk

  • United Arab Emirates: Wednesday, September 23 - 2009 at 11:56
  • PRESS RELEASE

Accidental security incidents by company insiders happen more frequently and has the potential for greater negative impact than malicious insider attacks according to new IDC findings announced today by research sponsor RSA, The Security Division of EMC.

Article continues below
  • Ahmed Abdella, Regional Manager, Middle East, North & West Africa, RSA.
    Ahmed Abdella, Regional Manager, Middle East, North & West Africa, RSA.
The IDC White Paper also shows a misalignment of security concerns by a majority of CXOs who give higher priority to protecting against malicious insider attacks over investing to prevent more frequent and potentially more damaging accidental insider security incidents.

The just-released IDC White Paper, "Insider Risk Management: A Framework Approach to Internal Security," sponsored by RSA addresses insider risk - the potential threat that an organization is exposed to by internal users who have access to critical systems and confidential information. While aware that users create information security risks within their organizations, external threats often overshadow the importance of protecting against internal risks. The new research uncovers a misalignment of CXO security concerns with the greater number of internal breaches and the threat posed to a business' bottom line by accidental security breaches, inappropriate access and misuse of information by its employee base.

Among the global IT decision makers that responded to the survey, the majority indicated they were unclear on the sources and intentions of internal risk and struggle to quantify the potential financial consequences and workflow impact. Of the organizations surveyed, 52 percent characterized their insider threat incidents as predominately accidental, only 19 percent believed the threats were deliberate, and the remaining 26 percent believed they were an equal combination while 3 percent were unsure. However, when asked to rank their top threats almost 82 percent of CXOs were unsure if incidents from contractors and temporary staff were accidental or deliberate.

"Employers view their relationship with employees as one of trust and recognize their people are their biggest asset,"


said Chris Christiansen, Program VP, Security Products of IDC.

But, the vast nature of an organization's infrastructure, coupled with a dispersed, often global employee base, and complex internal user mix of employees, consultants, partners and outsourcers make addressing the risks posed by its internal users the biggest security challenge that CXO's currently face: whether the risk is intentional or not, it's there. It's real."

Other insightful results from the white paper highlight the number of insider security incidents from within an organization. In the previous 12 months, 400 respondents admitted to 6,244 incidents of unintentional data loss, 5,830 Malware / Spyware attacks from within the enterprise, and 5,794 incidents of risks created by excessive privilege and access control rights. In total, the number of internal security incidents from the respondents came out at 57,485 in the previous 12 months. The survey results show that almost 40 percent of organizations plan to increase spending on initiatives to reduce internal security risks over the next 12 months and as few as six percent will decrease spending. These results indicate there is not a single solution to best address internal security risks but rather a need to take a comprehensive risk management approach to better understand the organizations' risk profile and where to best put controls in place.

"Security is everyone's job, not just the job of the security team," said Ahmed Abdella, Regional Manager, Middle East, North & West Africa, RSA. "Internal risks are growing and to remain competitive, CXOs must change the way they defend their business and expand security priorities to address the heightened need for protection from risk both intentional and accidental from an insider. CXO's must adopt a holistic strategy to mitigating insider threat that focuses on protecting critical information from misuse, leakage and loss by internal users, whether accidental or deliberate."

Although the increased sophistication of data breaches by determined fraudsters are prevalent, this new data highlights that unintentional data loss and information security controls affects the operational integrity of an organization to a greater degree than intentional, malicious attacks.
Also consider reading:
Log in to request more information from EMC Middle East

Notes and media contacts

About RSA
RSA, The Security Division of EMC, is the premier provider of security solutions for business acceleration, helping the world's leading organizations succeed by solving their most complex and sensitive security challenges. RSA's information-centric approach to security guards the integrity and confidentiality of information throughout its lifecycle - no matter where it moves, who accesses it or how it is used.

RSA offers industry-leading solutions in identity assurance & access control, data loss prevention, encryption & key management, compliance & security information management and fraud protection. These solutions bring trust to millions of user identities, the transactions that they perform, and the data that is generated.

for more details:
Rachel Watts
The Portsmouth Group
+971 4 369 3575

Disclaimer:

Articles in this section are primarily provided directly by the companies appearing or PR agencies which are solely responsible for the content. The companies concerned may use the above content on their respective web sites provided they link back to http://www.ameinfo.com

Any opinions, advice, statements, offers or other information expressed in this section of the AMEinfo.com Web site are those of the authors and do not necessarily reflect the views of AME Info FZ LLC / Emap Limited. AME Info FZ LLC / Emap Limited is not responsible or liable for the content, accuracy or reliability of any material, advice, opinion or statement in this section of the AMEinfo.com Web site.

For details about submitting your stories, please read the guide - all content published is subject to our terms and conditions