INSIGHT

Defending from within: a guide to insider threat management

By Valeska Bloch, Sonia Millen
Boards & NEDS Cyber Data & Privacy Employment, Industrial Relations & Safety General Counsel Technology, Media & Telecommunications

Guidance for boards, general counsel and HR on preventing, detecting and responding to insider threat risk 5 min read

Given how hard it is to protect against sophisticated cyber attacks by external threat actors, reducing insider risk can significantly affect an organisation’s overall risk profile. But insider threats present unique challenges for organisations.

To better prevent, detect and respond to insider threats, organisations need to ensure close cooperation between their legal, HR, risk, IT, cyber and fraud functions, and adopt a combination of technical, operational and behavioural measures.

This guide is designed to help general counsel, HR, senior management and boards manage insider risks in a manner that is both legally compliant and ethical.

77% of organisations have reported insider-driven data loss within the last 18-months. More than half of those experienced significant financial impact of greater than $1 million.