Call Us 703-591-6668 ☰ ˟
Logo
Call Us 703-591-6668
  • Home
  • Get A Quote
    • Automobile
    • Business & CommercialImage of right arrow
      • Commercial Auto Insurance Quote
      • Business Owners (BOP) Quote Form
    • Homeowners
    • Insurance
    • Recreational Vehicle
    • Watercraft & Boat
  • Blog
  • Resources
    • Refer a Friend
    • Important Links
    • Insurance Glossary
  • About Us
    • Location Map
    • Privacy Policy
  • Contact
    • Contact Us
    • Join Our Newsletter
Auto Icon

Auto

We browse through a wide variety of coverages and find the right one for you.

Learn More
Home Icon

Home

We browse through a wide variety of coverages and find the right one for you.

Learn More
Business Icon

Business

We browse through a wide variety of coverages and find the right one for you.

Learn More
RV and Boat Icon

RV & Boat

We browse through a wide variety of coverages and find the right one for you.

Learn More
Commercial Auto Icon

Commercial Auto

We browse through a wide variety of coverages and find the right one for you.

Learn More
Home > Blog > Are You Protected From Insider Attacks?
TUESDAY, FEBRUARY 27, 2024

Are You Protected From Insider Attacks?

It is often said in the cyber security world that your employees are your biggest security risk. Workers with access to sensitive information, including contractors that have access to the company’s network, may be aware of existing security weaknesses and can exploit them more easily than an outsider. In the case of the 2013 Target data breach that resulted in stolen credit and debit card numbers of more than 40 million people, hackers stole network credentials of one of Target’s HVAC subcontractors in order to infiltrate the company. Similarly, three AT&T contractors accessed customers’ personal records in April 2014 in order to remove their devices from AT&T’s network so they could be resold.

While these two recent examples are of high-profile companies, many more insider attacks go unreported or happen to smaller businesses. Many are the result of negligent employees with no malicious intent. According to the Ponemon Institute, 27% of data breaches are the result of human error, which includes negligent employees or contracts. And according to IBM, human error was a contributing factor in 95% of all recorded cyber incidents.

Insider threats clearly pose a big threat to companies of all sizes, but they don’t receive nearly the amount of headlines that external incidents do. A traditional cyber security policy will cover customer notification and litigation costs from the result of external incidents, but what if your business is attacked by an insider?

Why Do Insider Attacks Happen?

There are essentially two types of insider attacks—those with malicious intent and others that occur because of human error:

Malicious insider attacks: There must be a certain level of trust between a company and its employees, but sometimes employees abuse that trust. An employee may steal sensitive data for one of the following reasons:

  • To get revenge on a boss or another employee
  • To take the company’s intellectual property to his or her next job
  • To sell the company’s proprietary information

Because the employee may already have access to the company’s network or devices, an attack can be carried out much more easily from the inside.

Whatever the reason for the attack, companies should be on the lookout for characteristics of insiders who may become a threat, which include the following traits:

  • Introversion
  • Greed or financial need
  • Reduced loyalty
  • Inability to assume responsibility for their actions
  • Consistent frustration or disappointment

Individuals that exhibit these characteristics may reach a point at which they carry out malicious activity against the organization. One of the best preventive measures is to train employees to recognize and report behavioral indicators exhibited by peers or business partners.

Human error: Whether from negligence or ignorance, human errors that lead to an attack account for a large percentage of insider attacks. As previously mentioned, system misconfiguration, poorly chosen usernames and passwords, and lost business-related devices are all examples of human errors. In addition, the following are ways in which human errors can lead to an inside attack:

  • Being tricked into giving a hacker information leads to an attack. This is called social engineering, and it includes phishing or scamming.
  • Sending sensitive documents to the wrong recipients
  • Being undertrained on how to use company software
  • Working long, stressful hours that can lead to increased errors or forgetfulness

Insider Attacks as a Cyber Insurance Coverage Gap

Because the cyber insurance market is relatively new and constantly changing, policies may differ widely in terms of whether or not a company is protected from an insider attack, potentially leaving a big coverage gap.

The best way to plug that gap is to know exactly what your policy covers. Some policies may exclude an attack perpetrated by any employee or may only offer coverage if it is carried out by an executive. Others may exclude coverage for an attack when the insider uses or accesses unauthorized devices or systems.

Some industries are also more susceptible to attacks than others are, and that may affect the policy language and certain exclusions. For example, the IBM study notes that companies in the finance, insurance and manufacturing industries carry the highest incident rates and are generally more susceptible to an attack than companies in the retail and public sector industries, so some policies may exclude insider attacks in certain industries.

We Can Help

At Transworld Insurance Group, we know cyber coverage can be difficult to understand. Let us walk you through coverage to make sure your business is protected from an attack.

Posted 10:00 AM

Tags: cyber
Share |


No Comments


Post a Comment
Required
Required (Not Displayed)
Required


All comments are moderated and stripped of HTML.

NOTICE: This blog and website are made available by the publisher for educational and informational purposes only. It is not be used as a substitute for competent insurance, legal, or tax advice from a licensed professional in your state. By using this blog site you understand that there is no broker client relationship between you and the blog and website publisher.
Blog Archive
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021

  • home insurance(9)
  • auto insurance(9)
  • boat insurance(6)
  • motorcycle insurance(3)
  • business insurance(3)
  • renters insurance(3)
  • homeowners insurance(2)
  • mechanics(1)
  • contractors(1)
  • life insurance(1)
  • cyber(1)
  • bop(1)
  • car insurance(1)
  • health insurance(1)
  • renter's insurance(1)
  • construction(1)
  • recreational vehicle insurance(1)
  • flood insurance(1)
  • storm damage(1)
  • construction inusrance(1)

View Mobile Version

Contact Us Today!
703-591-6668

Resources

  • Products
  • News
  • About Us
  • Refer A Friend
  • Our Carriers
  • Blog
  • Contact Us

Contact Us

10803 Main St, Suite 500
Fairfax, VA 22030

P: 703-591-6668 | F: 703-591-3898
© Copyright. All rights reserved. | Powered by Insurance Website Builder