HomeinetData Breaches in companies & three categories of employees

Data Breaches in companies & three categories of employees

Data Breaches in Companies: The rise in the business value of data makes the issue of its protection even more important, with the issue of leaks having significant legal and financial implications. As data breaches are not only due to threats originating outside the companies, ESET has collected data and examples that outline three categories of employees, often responsible for leaks and violations of critical data (Data Breaches) of a company.Data Breach

According to a recent survey by Haystax Technology, 74% of companies are unsure “about how vulnerable the organization is to insider threats,” while 56% of security professionals confidently state that “threats from within the company have been more frequent” in the past year. The carelessness factor is very important.

Cases of data breaches due to human error, such as those in the cities of Norfolk, Suffolk and Cambridgeshire in the United Kingdom, where local authorities recorded over 160 data breaches between 2014 and 2015, or at the US Federal Deposit Insurance Corp. (FDIC) in 2016, demonstrate that innocent employees can cause just as significant losses as malicious hackers.

Another characteristic of employees that can be responsible for data breaches is negligence.

A 2013 Google study found that 25 million Chrome notifications were ignored 70.2% of the time, partly due to users’ lack of technical knowledge – a fact that led the company to simplify the language it uses for its notifications. The 2012 St. Joseph Health data breach, due to “incorrectly configured” security settings, resulted in confidential medical records being leaked online, costing the company millions of dollars.

The third category includes intentionally malicious actions, as demonstrated by the example of the telecommunications regulator OFCOM in the United Kingdom, which in 2016 discovered that a former employee had been collecting data belonging to third parties for six years.

In the same country, the large supermarket chain Morrisons reported a case where a disgruntled employee published the personal data of around 100,000 employees online. Although the incident occurred in 2014, the company is still facing legal repercussions.

According to a survey conducted in 2016 on behalf of Nuix, 93% of respondents consider human behavior to be the biggest risk to data protection.

For this reason, companies can take a series of actions that will limit the risk of data breaches originating from the three above categories of employees.

First of all, to increase employees' awareness regarding the gravity and consequences of their actions.

Secondly, they should take care to protect their data in as many ways as possible – encryption is one of them and is a very important ally in security matters.

Third, there is a need for ongoing monitoring of computer usage and employee behavior to identify unusual or dangerous activities. BOYD programs, which are in operation in many companies, should also be carefully monitored and controlled.

And, finally, companies must in the future adopt a stricter approach to the issue of internal security, understanding that it is a matter of preserving business continuity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS