Why would a tech employee turn to e-crime? Well, often it has to do with feelings of discontentment within their jobs or their lives. How, then, can companies best mitigate insider threats? On this episode of #CyberSecurityInside, Tom and Camille are joined by guest Rick Jordan, CEO and Founder of ReachOut Technology, to take a deep dive; if you’re looking for a fascinating conversation about things like ethical hacking and the human element of cybersecurity, this is it!

They cover:

  • Who gets involved with e-crime groups and why

  • How those e-crime groups can take advantage of disgruntled tech employees to find hacking backdoors

  • Why this year in particular has been especially stressful for security and engineers

  • What companies can do to mitigate insider threats

  • How automation and AI factor into risk management

... and more. Tune in now!

The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.

Here are some key take-aways:

  • E-crime groups are often able to tap into tech employees’ insider knowledge through financial coersement to find hacking backdoors.

  • Even though the e-crime groups are paying these tech employees, the sum they part with often ends up being far cheaper than running their own research and development schemes.

  • The tech employees they target are often discontent with their own circumstances, whether at work or just generally in life.

  • In order to mitigate against cyberattacks, then, you have to have things in place within an organization to boost human morale, as well as a tech element to help combat outside hackers.

  • There also needs to be holistic, big-picture thinking in order to prevent cyberattacks, which requires a more zoomed out approach and (in some cases) more work to ensure employees only have the level of permissions they need to get their specific job done.

  • Monitoring tools can be used for good to examine anomalies within functional groups to find out where workers are getting stuck, thus allowing companies to prevent the frustrations that can lead to employees turning into insider threats.

  • And while AI and automation can be useful tools in tracking and assessing risk, there does still need to be a human element involved in the process.

Some interesting quotes from today’s episode:

“I always equate hackers to like Pablo Escobar, because of all these, like cloaked people in hoods that you see, when you type in dark web and look at the images on Google search. That's not what the frickin’ hackers look like, you know, they look like you and me.”

“For cybersecurity, the human element really is the front door.”

“There's a blending that has to take place for the mitigation within the organization.”

“That's the human element because if they're not as frustrated in their jobs, they're not going to become that discontent threat actor or an insider threat if they're paid well, if they're taken care of, and they feel like they're contributing to something bigger than themselves.”

“If you take a look at the functional groups and look at the anomalies within those functional groups, the data is a lot more accurate and predictable in those ways.”

“It's almost like it's not their fault, because people are humans, and they have struggles. And maybe they made bad choices to get to this point. But now they make even worse choices to try to compensate for the bad choices they made or maybe something wasn't even their fault whatsoever. And they're just having hard times, especially after like, again, this last year, a lot of people were hit hard with the pandemic.”