WE HAVE MOVED - CHECK OUT OUR NEW HOME!

Please hold the line........the caller knows you are waiting and we are trying to connect you........
Showing posts with label the threat within. Show all posts
Showing posts with label the threat within. Show all posts

Monday, 2 May 2011

The Threat Within


Who is the insider?
But what exactly is the insider threat? What, or rather who, is an insider? Security professionals and government agencies all have their own definitions and all of these that I’ve read differ in their own little way, but fundamentally the meaning is the same.
  
I am not going to quote each and every definition (please use the web links opposite to visit some of the specific sites), but the important thing to remember is that an insider is a person to whom you have given legitimate access to your assets. In my opinion a former employee does not fall into this definition (and so is not an insider) as they no longer have legitimate access. In fact, their activities are likely to constitute a criminal offence in themselves.  

In the counter terrorism arena we talk a lot about capability vs motivation. Terrorists have motivation in buckets but most lack the capability - for example they cannot access the materials to build an effective IED. On the flip-side the insider has the motivation but also the capability as they have the in-depth knowledge of your organisation and the way in which you go about your business.

Companies are understandably slow to come forward and admit about their insider incidents as it could demonstrate a weakness in their internal processes or systems. This weakness could lead to uncomfortable questions from shareholders and governing bodies. The majority of insider incidents are reported by co-workers who experience suspicious activity but many still go undetected.

An Insider can be anyone in your organisation, anyone from the part time cleaner right up to a member of senior management. There is no ‘one size fits all’ profile for the insider, but there are a number of warning signs which could identify that you have a problem (we will cover these in future articles). It is important to remember though that current staff can become an insider, so 'Jim' who has been at his middle management role for 6 years and has a clean record may have a sudden change in personal circumstances (he could fall into financial difficulties) and could become a threat!

There is a massive misunderstanding and a lack of experience when it comes to the insider threat and this stems from no one department taking responsibility for it. The HR department generally deals with pre-employment screening (although in our opinion the security team should), IT systems are taken care of by the IT geeks wearing sci-fi t-shirts and musical ties, and any resulting investigation is dealt with by the security team.

There are various different types of insiders and the threat they pose will be different to each of you but in general they are:
  • Single Action Groups (animal activists or swampy students) – to cause harm, damage or media coverage
  • Terrorists - to cause large scale harm and to maximise media coverage
  • The Lone Wolf - because they want to and can! They are not part of any other group
  • Journalists – to identify an loop hole and to sell more newspapers
  • Foreign Intelligence Service
  • Competitors (corporate espionage) - trying to gain trade secrets, insider trading information or just to gain the upper hand over you
  • Disaffected Staff – revenge for not giving them that promotion/pay rise or someone who thinks they know better then the organisation itself.
  • 3rd Party Facilitation – helping somebody else to gain entry or supplying someone else with the data to commit crime, admin account login/password or giving them your building access card.
  • Unknown Pawns - exploited via various means but one way could be via social engineering or 'water cooler talk'. Normally these types of insider are unaware of the information they are supplying others with.
Why do these people do what they do?

  • Kudos
  • Reward 
  • Personal Mission
  • In the name of Public Interest
  • Identify an issue or wrong doing
  • Revenge
  • Intelligence
  • Facilitation of Crime
The effects of an insider can be far reaching but may include: 

  • Reputational Damage – poor media coverage, loss of investment opportunities
  • Financial Loss – Loss of sales or fines imposed by the ICO or regulating authorities (e.g.: Ofcom or the FSA).
  • Physical Damage
  • Unrest Internally with Staff – potential a lack of trust between staff
  • Loss of Operational Service
  • Loss of IT Service (normally via denial of service attacks)
  • Theft
  • Fraud
  • Poor International Relations
I keep coming back to it, but the single most important factor to consider is that these people have legitimate access, but what does it mean?. For me, this means they have already bypassed the majority of your physical and electronic security measures which protect you. Insiders are placed into organisations for the long term to build your trust, to gain a very in-depth understanding of your processes and the assets they are interested in. Even law enforcement are concerned that people with clean records will join in entry level roles and will raise through the ranks in order to supply serious organised criminals with information to assist them in committing crimes.

There have been numerous incidents of insiders
There are many tools in organisations to prevent these threats and most fall under the security specialism of Personnel Security, some of these are:
  • A robust pre-employment screening regime (most potential insiders can be detected at this stage - especially journalists and people that have clearly lied on application forms or CV’s)
  • Having a staff exit (leavers) procedure
  • Having a positive security culture – where staff are aware of the security risks that your organisation is susceptible to
  • Good policies and procedures, which staff are aware of and read
  • Awareness of the potential warning signs (we will cover some of these in a future articles)
  • Support from the board and senior management
  • A robust security audit process including auditing 3rd party providers (make sure all contracts include a 'right to audit 'clause)
  • Utilising the electronic tools you have in place – system logs, forensic tools etc
Whatever approach you decide for your business, it must be risk-based and targeted. Each organisation’s risk appetite will be different, but one thing for sure is you ‘will’ experience an incident as a direct impact from insider action – it is purely a matter of when, and how significant the impact is.  


The insider threat is a very vast subject and something that is impossible to cover in a single blog post. In my future articles I will give you some more details on this risk but until then expect the unexpected, these people are very difficult to detect but are easier to prevent.

Tuesday, 22 March 2011

Terror Plot BA Employee Gets 30 Years

Rajib Karim, 31, from Newcastle (originally from Bangladesh) a former British Airways software engineer has been jailed for 30 years for plotting to blow up a plane.

I think this is an excellent example of the insider threat (albeit a very serious one). This is someone who joined an organisation with one thing on his mind - to obtain 'critical and urgent information' and to then pass it onto a 3rd party to assist in the planning of an act of terrorism.
Rajib Karim gets 30 years
at her majesty's pleasure 

Karim, who worked at the airline's IT centre in Newcastle (having joined BA in September 2007 as a graduate IT trainee), was committed to martyrdom and even tried unsuccessfully to apply to train as an air steward during the BA cabin crew strike - which presumably would have allowed him to get 'airside' bearing in mind the trial heard Awlaki had emailed Karim asking: 'is it possible to get a package or person with a package on board a flight heading to the US?'

Karim passed on key information about airport security and suggested a crippling attack on BA's computer system. But the terrorist leader he reported to - Yemeni preacher Anwar al-Awlaki (a key figure in al-Qaeda in the Arabian Peninsula and is thought to have orchestrated the unsuccessful October plot to send mail bombs on planes from Yemen to the U.S., hidden in the toner cartridges of computer printers) - had plans for him to supply information to blow up a plane.

The Bangladeshi national, who studied electronic engineering at a university in Manchester between 1998 and 2002 has been described as 'mild-mannered, well-educated and respectful'. He has a British wife and child. The court heard Karim hid his hatred for the West from colleagues by joining a gym, playing football and never airing extreme views. BA colleagues had no knowledge of what he was planning or whom he was involved with, he kept his true intentions a secret. Karim 'kept a low-profile' at British Airways, while at home he was making violent propaganda videos for a terrorist group in Bangladesh, police said.

Throughout the trial, the court heard Karim was under the influence of his brother Tehzeeb who had spearheaded the attempts to contact Awlaki. Police spent nine months breaking the encryption on 300 coded messages found on Karim’s computer. Officers described the task as the 'most sophisticated' of its kind the team had ever undertaken.


He was found guilty last month of four counts of preparing acts of terrorism and sentenced today 25/3/11), he also faces deportation after his sentence is completed. Sentencing him at Woolwich Crown Court, Mr Justice Calvert-Smith said he was a committed jihadist who planned offences 'about as grave as could be imagined'. He said Karim was a 'willing follower' who could have brought serious harm and death to civilians had his planning with others come to anything.


Karim was clearly a disciple of an extremist Islamist (Awlaki) but he was in a very dangerous position having access to the type of information which could have assisted in the plotting of a serious terror attack. In this example he was stopped but what measures do you have in place to detect and prevent these people who are clearly out there!

- Posted using BlogPress from my iPad

Wednesday, 16 March 2011

Insider Threat Most Costly for Organisations

This article was originally posted by 'The New New Internet - The Cyber Frontier' and can be found here. There is also a powerpoint presentation summary of the survey results.

A new cybersecurity survey found that cyber attacks perpetrated by so-called “insiders” — those with inside knowledge or authorised access — are viewed as the most costly and damaging to an organization.
 

The 2011 CyberSecurity Watch Survey conducted by CSO magazine and sponsored by Deloitte found that 33 percent viewed inside attacks as more costly, an increase of 8 percent over last year. The survey reports that while more attacks are caused by outsiders (58 percent), the insider threat is becoming increasingly sophisticated.

The use of rootkits and other hacker tools by insiders jumped from 9 percent last year to 22 percent this year.

Aside from the monetary losses, the insider threat could tar an organization’s reputation, disclose confidential or proprietary information or disrupt critical systems — all of which can be “difficult to quantify and recoup,” the survey finds.

And, even with insider threats likely only to grow, the public is often left in the dark. That’s because about 70 percent of insider attacks are handled by the organizations with no official legal action taken.

“Technical defenses against external attacks and leakage of well-formatted data like social security numbers and credit card numbers have become much more effective in recent years,” said Dawn Cappelli, technical manager of the Insider Threat Center at CERT, the federal agency tasked with monitoring cyber threats. “It is a much more challenging problem to defend against insiders stealing classified information or trade secrets to which they have authorised access or against technically sophisticated users who want to disrupt operations.”

The report also found that, overall, cyber attacks are on the rise. Twenty-eight percent of respondents said have seen an increase in the number of events, according to the study.

But, while attacks are increasing, they are not as financially damaging as in previous years, likely because of strategic and proactive steps that organisations are taking.

Tuesday, 1 March 2011

News - The Threat Within



This is an excellent example of the threat an insider can pose to an organisation (and in this case potentially the public). Rajib KARIM deliberately sought a job in the UK that he could exploit for terrorist purposes.



KARIM was convicted on four counts of engaging in conduct in preparation of acts of terrorism, contrary to section 5 of the Terrorism Act, following a trial at Woolwich Crown Court.






 Security, security assurance, counter terrorism, personnel security,  Security, security assurance, counter terrorism, personnel security,  Security, security assurance, counter terrorism, personnel security,  Security, security assurance, counter terrorism, personnel security,  Security, security assurance, counter terrorism, personnel security,