Lieberman Survey Underscores Internal Security Threats

While the world is distracted with the continuing reports of phone hacking practices and other corporate data breaches,a new survey reveals that hundreds of organizations are now vulnerable to internal threats. According to a recent survey conducted by Lieberman Software, 42 percent of IT staff can get unauthorized access to their organization’s most sensitive information – including the CEO’s private documents. The failing is blamed on management’s naivety when it comes to understanding just how much privileged access their IT departments actually have.

According to 39 percent of the technology professionals interviewed in this study, their senior management does not have the faintest idea what IT can and cannot access. And, a staggering 78 percent admitted they could walk out of the office tomorrow taking highly sensitive information with them.While a third of respondents said they’d still be able to access sensitive information long after leaving the company – as the result of lapses in the organization’s security practices.
 
Commenting on this research Philip Lieberman, president and CEO of Lieberman Software, said “Companies should wake up to the fact that IT holds the keys to the kingdom. Nothing is secret or private unless you establish systems and procedures to lock down data from prying eyes and, according to our study, most organizations don’t. In the good old days the most sensitive data was locked away in a filing cabinet with just one or two trusted key holders. Today, it’s locked away in a virtual filing cabinet, but the problem is that most companies have no idea just how many people have keys to this cabinet. What’s clear from this survey is that management just doesn’t understand the privileges their IT staff have to the most sensitive data. Even the bosses’ documents can be read by 42 percent of IT personnel and, if these guys can’t be trusted – which in some cases they can’t – the directors shouldn’t be surprised when their data gets leaked or exploited.”
 
In the United States, 22 percent of IT workers worry about their job compared to a third of IT workers in the United Kingdom.

The survey amongst nearly 500 IT workers in the U.S. and U.K., was commissioned to unearth sentiment toward ethics in the workplace. It found that there was a strong correlation between job security and the propensity to steal sensitive data.  Nearly a third of people – 31 percent – who were fearful of losing their jobs admitted that they would take sensitive data with them to their next role, compared to just 18 percent of those who felt their jobs were secure.
 
It is worth noting that the smaller the company, the higher the percentage of people who were insecure about the stability of their employment. In companies with less than 1,000 employees, 31 percent of IT professionals strongly agreed to being worried about the stability of their employment, versus 20 percent of respondents at companies with more than 1,000 employees.
 
When comparing the two countries, more IT professionals in the U.K. say they could take sensitive information away with them to their next job – with 85 percent admitting it would be easy compared with 76 percent of their U.S. counterparts. 
 
What drives snooping?

The 15 percent of UK IT professionals compared with just nine percent of US IT professionals, admitted they’d use their admin rights to snoop around the network in an effort to sneak a peak at sensitive data – such as personnel records to try and find out if their job, or a colleague’s job, was at risk.
 
The survey was conducted by Lieberman Software at RSA Conference 2011 and Infosecurity Europe 2011 amongst nearly 500 IT professionals. The full results can be found at Liebsoft.com.

Featured

  • The Next Generation

    Video security technology has reached an inflection point. With advancements in cloud infrastructure and internet bandwidth, hybrid cloud solutions can now deliver new capabilities and business opportunities for security professionals and their customers. Read Now

  • Help Your Customer Protect Themselves

    In the world of IT, insider threats are on a steep upward trajectory. The cost of these threats - including negligent and malicious employees that may steal authorized users’ credentials, rose from $8.3 million in 2018 to $16.2 million in 2023. Insider threats towards physical infrastructures often bleed into the realm of cybersecurity; for instance, consider an unauthorized user breaching a physical data center and plugging in a laptop to download and steal sensitive digital information. Read Now

  • Enhanced Situation Awareness

    Did someone break into the building? Maybe it is just an employee pulling an all-nighter. Or is it an actual perpetrator? Audio analytics, available in many AI-enabled cameras, can add context to what operators see on the screen, helping them validate assumptions. If a glass-break detection alert is received moments before seeing a person on camera, the added situational awareness makes the event more actionable. Read Now

  • Transformative Advances

    Over the past decade, machine learning has enabled transformative advances in physical security technology. We have seen some amazing progress in using machine learning algorithms to train computers to assess and improve computational processes. Although such tools are helpful for security and operations, machines are still far from being capable of thinking or acting like humans. They do, however, offer unique opportunities for teams to enhance security and productivity. Read Now

Featured Cybersecurity

New Products

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3