Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Security officers now require a more comprehensive insider threat solution

By Tom Miller
August 11, 2020

COVID-19 has initiated a whole new host of cybersecurity threats. Twitter was one of the latest victims, its employees allegedly being targeted so that hackers should take over the accounts of certain verified users. And just before that, a June 25 story in The New York Times detailed the way in which a foreign entity is attempting to infiltrate American business by taking advantage of remote employees whose organizations – more than 400 million worldwide – use virtual private networks (VPNs).

This should be a wake-up call – especially for cybersecurity officers. What were once considered sufficient safeguards to keep sensitive information secure, are now beginning to prove insufficient in this world of remote work. 

Twitter’s situation, for example, shows the danger of having a risk management strategy too heavily focused on mitigating external threats. In addition to the external actors that have learned to penetrate this first line of defense, acts from internal actors can be just as dangerous to a business’ bottom line – even if that’s not their intent. Insider threats from negligent actors that mistakenly send sensitive information to the wrong email address, for example, reportedly make up 62 percent of such incidents. 

A lesser percent of insider threats come from disgruntled and disengaged employees who may have experienced a negative disruption to their personal finances and/or who are under acute stress. This possibility isn’t completely lost on the majority of cybersecurity professionals, with 67 percent expressing in a WSJ Pro Research survey that they were concerned about malicious employees.

Still, it is not enough to be concerned. When major data breaches occur, cybersecurity professionals are held at least partially responsible – just look at what happened to the chief information security officer serving Capital One at the time of the company’s 2019 breach – and with an above-average amount of threats facing organizations because of COVID-19’s transition to remote work, it’s imperative that security officials make efforts to address threats arising from all sides. 

In addition to strengthening firewalls and exploring VPN alternatives, security officers should focus significantly more attention on insider threat prevention. Under normal economic, social, political and public health conditions, employee stress frequently drives otherwise loyal employees to steal or even inflict physical violence due to personal life challenges like the loss of a loved one, unforeseen expenses, or because they’re being bullied or harassed. Those normal stressors are still occurring, but today, they’re occurring in conjunction with a pandemic, widespread unemployment, and in the midst of nationwide unrest.

The continuous monitoring of employee stress makes it possible for security officers to see how an employee is being impacted by these challenging circumstances. Customizable solutions allow security officers to search for activities of interest – finances, criminal history, etc. – in real-time, and do so compliantly when consent is built into the system.

Receiving real-time alerts, security officials can call the appropriate business personnel – usually Human Resources and occasionally Legal – into interventional action before an employee intentionally commits an act that puts the organization in jeopardy. This shifts the role of a security official from being one that retrospectively manages risk, looking for threats as they occur and swiftly shutting them down, to one that proactively manages and prevents risk from ever taking place.

This is the kind of innovative diligence that organizations need to safely navigate not only the new few months of remote work, but the future. Protections against external threat will remain important, as will training that keep employees from making negligent mistakes. However, what will make the greatest difference is a solution that lies somewhere in the middle – in the precious space in which a good-hearted employee is driven to transition into a malicious actor.

KEYWORDS: COVID-19 cyber security information security insider threats risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Tom Miller is CEO of ClearForce, an organization that protects businesses and employees through the continuous and automated discovery of employee misconduct or high-risk activities.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

2026 Women in Security

Security’s 2026 Women in Security

Denise Platon. Image courtesy of Platon

Denise Platon — Women in Security 2026

Women in Security: Julia Stuyt

Julia Stuyt — Women in Security 2026

Glowing AI square

Security Experts Discuss the Hugging Face, OpenAI Incident

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • authentication-freepik

    Passwords aren’t enough: Why businesses need to build more comprehensive security

    See More
  • business travel

    Iowa State-Sponsored Abroad Trips Now Require Registration for Security

    See More
  • American Airlines

    American Airlines and Delta Now Require all Passengers to Wear Face Masks

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • Security of Information and Communication Networks

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing