Ciberseguridad 3

The Enemy That’s Already Inside

Firewalls ISO 27001 Cybersecurity

    The Threat No One Wants to Name

    34% of security breaches are caused by people inside the organization. Sometimes maliciously. More often, through negligence.

    We talk about firewalls, external attackers, and ransomware groups. Yet 34% of breaches originate from within: dissatisfied employees, contractors with excessive access, or people who make mistakes with devastating consequences.

    Insider threats are especially difficult because people with legitimate access do not trigger the same alerts as external attackers. They know the systems, processes, and shortcuts, and often have more access than they need.

    The Most Uncomfortable Problem

    34
    %
    of breaches originate internally
    308
    K
    average cost per incident
    77
    days
    average detection time

    Three Insider Threat Profiles

    No malicious intent. Sends documents to a personal email, uses weak passwords or plugs in an unchecked USB device. Unintentional error is the most common cause.

    Their credentials have been stolen or they are being manipulated. They act as an insider threat without realizing it. Behavioral analytics are required to detect them.

    The employee who exfiltrates data before leaving, or the administrator who plants a backdoor. Only 14% of cases, but with the greatest reputational impact.

    How to Reduce Risk Without Destroying Trust

    No one should have more access than necessary. Reviews should be quarterly and automated, not annual and manual.

    Detectar anomalías: descargas masivas fuera de horario, accesos a recursos inusuales. La analítica de comportamiento reduce el tiempo de detección de 77 a 7 days.

    89% of former employees retain active access after leaving. Access lifecycle management is just as important as onboarding.

    Control what data can leave, through which channels and where it can go. Not to spy, but to protect critical assets in a proportionate and documented way.

    There is a direct correlation between dissatisfied employees and insider risk. People management is also security risk management.

    standard-quality-control-concept-m
    “Zero Trust no significa desconfiar de tus empleados. Significa verificar siempre, independientemente de quién sea la persona o desde dónde acceda.”
    John Kindervag, Creator of the Zero Trust Model
    Fraud Scam Phishing Caution Deception Concept

    How Does ISO 27001 Help You Prepare for Emerging Threats?

    Subscribe to our newsletter