By PJ Bradley
Of all the things that organizations have to protect themselves against in today’s digital landscape, insider threats are among the most insidious and harmful. Most companies with sensitive digital assets are aware of the threat of external actors launching cyberattacks, the dangers of insider threats are less obvious and more difficult to prevent.
Artificial intelligence (AI) and machine learning (ML) have been a hot topic in tech circles for a while, and even more so in the broader discourse for the past year. There are many ways in which AI can automate and optimize processes that may be difficult, time consuming, and costly for humans or traditional cyber defense to handle. Insider threats are one type of risk that can be helped with AI.
About Insider Threats
An insider threat is a risk that arises from an internal actor-an employee, partner, contractor, or even a maintenance or custodial worker-causing harm to an organization from within. This can be either an action or a failure to act, and it can come in a variety of forms.
- Negligent insiders are those who do not intend to cause harm to the organization, but commit an error through ignorance or negligence of sufficient cybersecurity practices.
- Malicious insiders are those who set out to intentionally damage the organization from within, often for financial gain or due to a personal vendetta.
- Credential thieves are outsiders who use tactics like phishing to obtain authorized login information that they use to infiltrate an organization.
According to the Ponemon Institute’s 2022 Cost of Insider Threats Report, 56% of insider threat incidents originate from employee or contractor negligence, 26% from criminal and malicious insiders, and 18% from credential theft. Insider threat incidents arising from employee or contractor negligence are by far the most common, but they also represent the least costly type of risk per incident. Criminal and malicious insiders and credential thieves cost more per incident, but less annually.
Traditional Insider Threat Protection
Insider threats are difficult to prevent due to a number of factors. Insiders of all sorts require authorized access to an organization’s networks, systems, devices, and accounts, and the divide between security and privacy is a fine line for IT professionals to walk. Monitoring all user activity for known threat signatures is far less likely to effectively catch an insider threat than other forms of attack.
Insider attacks make up a significant portion of IP theft, “an illicit activity that manifests through the unauthorized use, reproduction, or distribution of intellectual property owned by others.” One of the most common sources of IP theft is unauthorized access to sensitive areas, which is often achieved via phishing or hacking so credential thieves can infiltrate and steal valuable IP.
Employee misuse of proprietary information like trade secrets, patents, and the like is also a major insider threat. This falls under malicious insider attacks, and can cost businesses a great deal of money, reputation, and competitive edge. Traditional methods of insider threat detection and prevention have often been ineffective in figuring out exactly which user activities present a danger to an organization and which are innocuous or even necessary for the organization to function.
How AI and ML Can Help
Since traditional cybersecurity solutions are largely unable to determine what user behaviors constitute a threat to a company, AI and ML can fortify insider threat programs. While it requires an often “difficult and time-consuming” process of training algorithms on large data sets, an insider threat prevention tool making use of AI can have a significant impact on an organization’s defense if used correctly.
The use of AI enables more precise detection of user behaviors that may lead to serious security incidents. This can lower the volume of false positives and increase the number of risky actions that are stopped before they become major incidents. That way, security and IT teams have more time and effort to spend on problems that they have the power to solve, rather than wading through extreme amounts of security alerts.
Data mesh architecture uses application programming interfaces (APIs), making for streamlined and optimized data collection. This ensures the interoperability, standardization, and governance, using the API framework to expose data at the source in real time. The right combination of AI, ML, and data mesh technology can create a strategy capable of preventing many insider threats.
Conclusion
The nature of insider threats makes them lucrative for bad actors, easy for negligent insiders to cause by mistake, and difficult to prevent. Solutions designed to prevent unauthorized data exfiltration leverage known threat signatures, which are often missing in insider threat situations, but technological advances allow professionals to develop more solutions that can more successfully detect risky behaviors that may indicate the potential to grow into a security event. Using AI algorithms to enhance the functions of threat detection and prevention, organizations can defend themselves against the insidious danger of insider threats.
##
ABOUT THE AUTHOR
PJ Bradley is a writer on a wide variety of topics, passionate about learning and helping people above all else. Holding a bachelor’s degree from Oakland University, PJ enjoys using a lifelong desire to understand how things work to write about subjects that inspire interest. Most of PJ’s free time is spent reading and writing. PJ is also a regular writer at Bora





