Evaluating cybersecurity measures is becoming commonplace in the workplace. Yet despite the intense increase in cyberthreats, some risks – if not many – may be coming from inside the house.
Code42's annual Data Exposure Report revealed the resounding need for data security training development, with 96% of surveyed companies indicating their security training measures need improvement.
“There are no longer walls around our business that we [can] protect; they have melted down,” Code42 CTO Rob Juncker explained to SDxCentral.
Now, 55% of companies “are concerned that employees’ cybersecurity practices will be lax in new hybrid-remote work environments,” and “71% of orgs are unaware of how much sensitive data their departing employees typically take with them,” Code42's report stated.
The company integrated its Insider Risk Trends dashboard to look at the changing risks in an organization “week over week, month over month,” Juncker explained. “So many people in security have been focused on protecting from the outside in. … We decided to actually start paying attention to what's happening from the inside out.”
Juncker says that as companies set up their security programs, invariably, workers run into issues in the way they collaborate, establishing a "drift away from that center line.”
As an organization drifts and risk increases, Juncker says the insider perspective helps “bring everybody back to that true north.”
Pandemic-Propelled ProblemsA key finding from the report disclosed that “61% of IT security leaders say their remote workforce was the cause of a data breach” since the start of the pandemic. Juncker says the COVID-19 cyberrisk shift was nearly immediate. “It was unbelievable how fast we saw that shift happen. … It happened within a week,” he explained.
Code42’s product is based on machine learning (ML) and artificial intelligence (AI) modules and algorithms to measure changes, and "as you think about autonomy, there's not a lot of shift,” Juncker noted.
Mathematical coefficients disclose how much things are changing on a given day. Ordinarily, it’s within hundredths of a percent. When COVID hit, "models were changing by percentages a day," he said. "I mean, it was unbelievable how fast we saw the entire business world be flipped on its head.”
When in-person became unsupportable and people had to find new ways of collaborating, “they went to cloud tools, and they adopted them so fast,” Juncker explained. “In many cases there was no training configuration or controls put in place for them.” In that shift, cloud property became a workplace "wild west."
Juncker noted many businesses also turned toward contractors who pose increased risk “because you don’t have the sense of community or belonging, [and] they’re around for a very short period of time.” Working on their own devices, they often pose similar risks as departing employees. “All of that confounded together created this perfect storm,” he said.
The 3 RisksJuncker attributed much of the report’s key findings to three major “insider risk” issues that aren’t properly addressed in rapidly shifting workplace ecosystems.
One major problem is data leaving an organization with departing employees. A company has a one-in-three chance of losing IP when a worker leaves, according to the report.
Another identified issue is the ubiquitous sharing and collaboration tools most organizations are now adopting. Files over 25 megabytes – which Juncker notes is “not that big” – are often opted to a sharable link format when sending to a coworker.
“Unbeknownst to you, you're actually enabling the sharing of that file with a third party outside of your organization,” he explained. “And in many cases, depending upon how you're set up, that could actually be a public link that anyone can gain access to.”
The third major risk falls down to the “pure speed” at which the workforce is currently operating at. Juncker mentioned that company sales teams – while not exclusively – are often culprits of trying to operate seamlessly wherever they are, downloading reports or contact information to alternate devices.
“A lot of those devices that they're downloading to – if it's their personal device or their mobile phone – aren't under the same security policies,” he explained.
The 3 'Ts'The response – as Juncker describes it – lies in evaluating the risk that every worker poses while still maintaining employee respect, which he boiled down to what his team calls the “three Ts.”
"It's the technology, it's the training, and then finally, the transparency,” Juncker said.
In stressing transparency, he said they “don't want to be Big Brother” for an organization. “With good transparency, we can make sure that users know what we're looking at and why we're looking at it so that they're properly informed about the risks of some of their interactions.”
In offering a compass to help steer organizations back to “true north,” there are different alteration methods that they implement, one being “situational change.”
If someone resigns from a job, there are situational lessons sent to the user describing expectations surrounding data and information for their remaining time. Code42 automates these lessons in efforts to ensure a systematic approach to common mistakes that are often missed.
Another form is “responsive” changes. When someone creates a risk – intentional or unintentional – there is an immediate response to warn the person what exactly that sharing may enable. "It kind of democratizes the security," he noted.
The final form is developing a type of risk literacy. Juncker emphasizes how often workplace trainings are drawn out, and subsequently, employees tune out. Code42 has developed short and targeted videos for different teams within an organization to more effectively inform insider risks.
Comments