Companies spend billions of dollars every year on security and protection from determined hackers who attack their entire network, but experts warn that they should not ignore the most serious threat, for which they are not yet ready: insider trading.
Morgan Stanley, one of the world's largest financial services firms, revealed on Monday that a client's information had been breached. But it wasn't the result of a determined hacker or phishing attack. Instead, Morgan Stanleysaid it was an employee who stole data from more than 350,000 client accounts.
The movement is a catalyst for awakening in companies, which are estimated to have spent $71.1 billion in 2014 on their network security, up almost 8% from the previous year. And while hackers have successfully attacked large companies such as JPMorgan, Target, and Home Depot, experts warn that employees constitute a threat, whether they act deliberately or accidentally.
While the network security industry devises an ever‑growing list of technological methods to protect against intrusions, it turns out there isn’t much that can be done to stop an intruder who already has access to the company’s files, which are otherwise considered highly protected data.
Insider attacks are often characterized in three ways: they are difficult to detect and do not occur frequently. But when an attack truly originates from within, it can be devastating. Security researchers at the Ponemon Institute say that 88% of IT professionals surveyed responded that they struggle to identify insider attacks, and security consultants at SpectorSoft say that fewer than half of businesses are able to observe them.
Few companies disclose attacks of this kind, and when it happens they rarely calculate the damage. SpectorSoft claims that internal attacks (which make up 35% of the total) cost American companies 40 billion dollars for 2013 alone.

