The footage includes insight from across the Scottish information security community, including Police Scotland, RBS and Brodies LLP. The film explores the growing risk of the Insider Threat, looking at some of the key challenges it poses for organisations.
One of the principal problems is the sheer breadth of the threat, a point highlighted by ZoneFox CTO, Matt Little: “Insiders can be anybody, the most typical that we’ve seen are the disgruntled employee. But it could also be that user that’s clicked a link in an email and their account is now being used to exfiltrate data. Or it could be a partner who told you that their security was very robust – but isn’t quite as robust as you thought.”
The difficulties of preventing Insider Threats has led to a strategic shift in the way organisations are trying to address the problem. Little notes that Gartner have recently reported a spending increase in detection and response tools, indicating their favour over traditional blocking tools, which have failed to address the Insider Threat effectively.
Businesses are concentrating on improving the visibility and insight of their systems, drawing together crucial information into a form which can be monitored and understood. This allows them to identify unusual activity against normal behaviour patterns.
While technology can offer valuable assistance, the human engagement element is also crucial. A threat with so many permutations requires a collective response, with buy-in across the organisation: “Insider threat is more a collaborative workload” said Mark Hilson, IT Manager at Briggs Marine, adding: “it’s not just IT. HR are very much involved in that.”
Engaging staff in the security process is key to preventing future breaches, which means there is a real necessity for skilling your workforce appropriately. Martin Sloan, a partner of law firm Brodies, said: “It comes down to getting the appropriate training for your staff. This makes sure your staff are aware of what’s going on, what they should be doing, what they should be looking out for.”
Some leaders also highlighted the impending changes in data protection regulation coming in the form of GDPR. Ross Johnston, Security Architect at RBS, noted that the increased sanctions of GDPR presented new avenues to explore for users’ security: “It’s really going to change the ways around our data – how we monitor it, manage it, protect it.”





