Insider threats continue to pose a high risk to today's companies, and a recent study from SailPoint demonstrates exactly why management doesn't trust its own staff, as a recent survey found that 20% of employees would sell their corporate passwords.
SailPoint, a Texas-based identity and access management company, surveyed 1,000 employees at private companies in the U.S., U.K., France, Germany, Austria and the Netherlands. This is the second consecutive year that SailPoint has conducted the study, and all numbers were up from last year.
The survey responses revealed that, globally, one in five employees would be willing to sell their corporate passwords for a good price, up from one in seven last year.
Worryingly, some employees wouldn't even bother to negotiate a good price; 44% of the 20% (who said they would be willing to sell their codes ) wouldn't even ask for more than $1,000 (€900).
And to spread the damage even further, about 65% of all respondents said they reuse corporate passwords across multiple work-related applications, meaning that leaking/selling passwords could cause harm to multiple parts of a business's operations.
But employees wouldn't even need to sell their own password, because 32% said they share their corporate password with other colleagues, so a dishonest employee could very easily sell someone else's password and avoid being held accountable in the event of a data breach.
The irony is that SailPoint asked employees about data breaches involving their own data. As you might expect, people don't like it when their data is leaked.
85% of employees said they would react very negatively if their personal information was compromised by another company, while 84% report being concerned about sensitive data being shared about them.
But the study's disturbing findings don't end there, SailPoint also revealed that 42% of employees surveyed admitted to using corporate credentials after leaving a previous job to gain access to their former employer's network.
Even worse, in their current workplace, 33% of all employees admitted to purchasing and then using (for work) SaaS solutions without IT knowledge or consent. 70% of these employees also admitted to uploading company data to cloud services so they could access it outside of work.
Now I think you can understand! Now you know why corporate executives rank their employees as the most dangerous factor when it comes to data breaches.


