As the so-called Great Resignation seems still to be in full swing, one critical topic is often left out of conversations — cybersecurity concerns specific to the employee exodus. However, security practitioners and analysts warn that insider threats tied to the Great Resignation can pose a substantial risk to organizations.

“We think about two-thirds of all breaches are actually caused by insiders, and typically when it matters is when someone's leaving the company,” Code42 CEO Joe Payne told SDxCentral. “That's why it's so closely tied to the Great Resignation, so closely tied to the insider risk problem, and it's become so pervasive right now.”

Security hasn't been “part of the conversation,” said Justin Fier, director of cyber intelligence and analytics at Darktrace. “For years, we've been dealing with customers where there's just a disconnect between the security team and HR,” he said.

Surveys from security vendors like Tessian and Code42 reveal how ubiquitous the problem has become. In the U.S., 40% of respondents said they had taken data with them when leaving a job, and 58% of them use the data for their new job, according to Tessian’s recent report. Plus, Code42 found 60% of surveyed employees admitted they took data from their last job to help the current role, according to Payne.

Meanwhile, nearly three quarters (71%) of surveyed organizations don’t know what and/or how much sensitive data departing employees take to other companies, and almost all (96%) of them experience challenges in protecting corporate data from insider risks, according to Code42’s 2022 Data Exposure Report.

Another Code42 report found 87% of organizations never even asked employees who were leaving if they'd taken any data.

Intentional and Unintentional Insider Threats

The Great Resignation can pose “a mix of malicious and accidental insider threats,” including data theft from disgruntled employees, fraud as a result of privileged access, privacy abuses, and leaking of sensitive data, according to Forrester principal analyst Heidi Shey.

“The unintentional is probably the most common,” Fier said. “A lot of companies need to do a better job educating their workforce on what's intellectual property and what they're allowed to keep and what they're not.”

Mauricio Sanchez, research director of network security at Dell’Oro Group, also listed direct and indirect data loss, stale identities, and business continuity as security scenarios that enterprises should consider during this period.

Not all the companies update their identity repositories frequently and delete employees that have left, Sanchez explained. If they don't do this, then stale identities present an opportunity for both direct and indirect forms of data loss.

Additionally, in remote and hybrid work models, employees are likely to accumulate a lot of corporate data on their own digital devices that may never be returned once they resign, Sanchez added. “If an employee was lax in syncing/backing up their data to central corporate servers/cloud, then an enterprise may find itself with data gaps that are difficult to fill.”

The pandemic also has transformed the office and overturned the notion of a defensible perimeter.

“One of the biggest things that's changed in the last two and a half years is where we store our data and how we operate … because there is no perimeter,” Fier echoed, adding that “the acceptance of all this SaaS and cloud-based technology has introduced a large amount of risk.”

Code42 has around 700 clients using its software, and every one of them has data exfiltration stories — including the insider risk vendor itself, Payne said.

He detailed two incidents over the last several months, one of which involved a senior executive exporting files into an external drive, and then asking Code42 to figure out what information they cannot take when leaving, Payne said.

Additionally, organizations should also watch data coming in from new hires, he warned. The Code42 security team recently flagged a new employee who uploaded a bunch of proprietary documents from their last company. This turned out to be an unintentional threat.

The team later found out that the employee plugged their phone into their previous employer's laptop to charge it, and inadvertently uploaded corporate files to their iCloud account. Then when the employee plugged her phone into her Code42 computer to charge, they downloaded all the other organization's files onto Code42's machine.

Malicious Insider Risks Pose the Biggest Threat

Despite stories of accidental data exfiltration, malicious insider risks, which might be less common, post “the biggest threat with this mass resignation that we’re seeing,” Fier said.

Disgruntled employees leaving a company could decide to “take matters into their own hands,” stealing and selling information, or taking a list of clients or protocols to competing companies, he added.

Fier used one of his company’s customers as an example. Darktrace saw that an employee from a large hotel chain accessed its competitor’s Microsoft SharePoint account. It turned out the employee used to work for the competing hotel chain. They still had access to contracts and other information, and had tried to steal the data and bring it to the new job. Darktrace notified both companies, and the employee was fired.

What Can Business Do to Defend Insider Threats?

So, what should businesses do to protect themselves from both intentional and unintentional insider threats?

“I wish there was an easy panacea for improving the security posture against the threats posed by the Great Resignation, but no differently than any other security risk, it can be mitigated by embracing the right strategies and combination of people, process, and technology tactics,” Sanchez said.

Technologies such as data storage, device and file encryption, strong segmentation as a part of a  zero-trust architecture, data-loss prevention, and cloud access security broker technology are good starting points, he added.

“The Great Resignation underscores the need for more organizations to adapt faster to the new normal and rapidly move toward a zero-trust mindset,” SecurID Chief Product Officer Jim Taylor echoed.

Fier also said he expects to see greater investment into anomaly detection services and others that bring better visibility into corporate data.

And on top of the technology, organizations should implement proper training and off-boarding policies. IT, security, and HR teams should work together to set up a collaborative process to shut down employee access to sensitive data during their last few weeks.

For insider threat hunting, Fier encourages security teams to work with HR to profile and spot the people that are most likely to become disgruntled employees, and “watch them a little bit closer to look for those anomalies when their patterns change.”