In this episode of Cyber Security Inside, Tom and Camille once again speak with Dr. Eric Cole, CEO and Founder of Secure Anchor Consulting. This time, the topic is insider threats. Some insider threats are a result of bad actors, while others stem from more innocent and unwitting insiders.

What can CISOs do to prevent, detect, and track down these insider threats? Let’s find out.

Here are some key take-aways:

• There are really two sides of cyber security: prevention and detection. Everything else generally falls under one of these two categories.

• You’re going to miss things with prevention technology, which is why you have to have a detection piece in place. And you have to focus on both inbound and outbound traffic if you’re going to detect both outsider and insider threats.

• One of the biggest issues with detection is a lack of resources. IT is being bombarded by sometimes thousands of alerts daily, and they’re simply not equipped to handle them all. The proposed solution is to tune down false positives and focus on the biggest threats.

• In situations where you can’t possibly address every threat, you have to make sacrifices and choose to address the most impactful threat.

• When determining a hierarchy of importance with server-based threats, malicious code that’s impacting the operating system that runs every time you restart the system will take priority over something that isn’t a threat when the computer’s turned off. With network-based threats, again, you need to determine which threat has the most impact and address that if you can’t address each.

• There are two types of insider threats: the malicious employee and the good intentioned employee inadvertently doing bad things. Both can cause damage, but how you approach each differs. With malicious employees, prevention through limiting and controlling access is the best approach. With employees who are inadvertently causing harm, the best approach is detection, because they won’t be covering their tracks.

• CISOs and CIOs need to understand where the damage is caused and use that information to build better security. Always have the mindset of “There’s a creative way to get this done.”

• Threat hunting is an approach that some businesses take — somewhat in the same spirit as a hackathon. With threat hunting, you assume your network is compromised and then find the adversary. The thing is: many times, businesses that do this actually end up finding an insider threat.

• Focusing on the base core components rather than the specific threats and exploits keeps you flexible and more open to see and spot potential issues.

Some interesting quotes from today’s episode:

“Most companies want to focus all their energy on prevention — on stopping the adversary. The problem is you can only prevent things that are 100% bad, 100% of the time. Which means if something is bad 90% of the time, you can't prevent it because that would be blocking 10% of legitimate traffic.”

“I call it the car alarm issue. When we used to be able to go to malls, and you were walking through a mall, if somebody's car alarm was going off, what did you do? You just kept walking. You didn't call the police. Because they go off with such high frequency we become numb to it. We totally ignore it. And that's the problem with detection.”

“I would rather catch the 10% that are most significant than miss 100% because of the noise.”

“Now this is where world-class security engineers get themselves into trouble because they can't help but say, ‘But they're both important!’ Yes, they're both important. But if you can't do both, greatest good. You sometimes have to make sacrifices.”

“When you're talking about the deliberate malicious insider, because they know they're causing harm, they're going to cover their tracks. So in that case, you really have to focus a lot on prevention. Limit the access that they need to do their job…Go with the principle that we call ‘least privilege’ — only give people the absolute minimal access they need to do their job.”

“If you go in and look at Edward Snowden, when you do the analysis post-mortem, 80% of the data that he stole that harmed this country, he did not need access to to do his job.”

“On the accidental insider — the one that is thinking they're doing good, but inadvertently causing harm — that’s where detection is powerful, because they don't know they're doing harm, so they're not going to try to cover or hide themselves.”

“What I find today is if somebody needs something to do their job and you just tell them no and block it, they're going to do it anyway and just treat it as a covert mission. So what I would do in that situation is, I would go to them and say, ‘Listen, what functionality do you need? Don't tell me, you need a USB drive. Tell me what are the actions that are needed’.”

“How specifically the threat works, how specifically the exploit propagates, I don't care because it would be too much work. I'm going to focus on those base core components. And once again, based on my experience, it works most of the time.”