Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

How to use employee personal data monitoring to close security gaps

By Rob Shavell
cyber data
April 21, 2021

Employee personal data has long been recognized as a vulnerable threat vector for modern enterprise cybersecurity. However, even though more employees than ever avail themselves of identity theft and credit monitoring services, their employers are rarely any safer.

While employees are increasingly concerned about personal identity security, the incidence of both identity theft and phishing attacks continues to soar. The number of identity theft cases more than tripled since 2018, and phishing attacks grew by a whopping 350% during the COVID-19 quarantine. Crucially, 38% of respondents in a recent study said their coworker fell victim to a phishing attack within the last year.

This paradox emerges because of the reactive nature of most personal information protection solutions and a misunderstanding of the benefits they bring to businesses. Rather than network protection, the actual service offered by many identity theft and credit monitoring solutions is more akin to remediation.

As a result, identity theft and credit monitoring scarcely increase personal data security for employees or their organizations. From our experience working with enterprise CSOs in every sector, we have even found that companies who rely too much on these kinds of services frequently become more rather than less vulnerable to cyber threats. The more employers feel protected by ineffective systems, the further employees are likely to stray from cyber hygiene basics.

With more powerful malware, a tightening regulatory environment, and greater consumer security consciousness raising the stakes for organizational cybersecurity, understanding how personal data monitoring impacts cybersecurity has never been more vital.

 

Identifying Security Gaps Caused by Employee Private Data Online

As the gap between real protection and false security widens, organizations need to appraise their personal information security posture critically. Figuring out what works in protecting employee privacy is becoming increasingly important as social engineering scams used by threat actors continue to evolve.

The emergence of techniques such as spear phishing, where targeted phishing emails are aimed at specific individuals within an organization, shows how cybercriminals leverage personal information to increase a phishing attack's credibility. If a cybercriminal can find the home address, full name, or marital status of an individual within a corporate network, crafting a convincing phishing email becomes far easier. By leveraging executive personal information to gain the trust of individuals high in the corporate hierarchy, a practice known as "whaling," cybercriminals can quickly initiate devastating cyberattacks.

In 2016, a whaling attack on the social media company Snapchat, where a cybercriminal impersonated its CEO to gain an executive's trust, resulted in a massive leak of employee payroll information. Similarly, the CEO of FACC, an Austrian Aerospace Company, was fired after he lost nearly $60 million by falling victim to a whaling attack.

Worryingly, the personal information that threat actors use to facilitate these kinds of attacks is easily accessible. Whether as a result of a data breach or, more frequently, through publicly accessible information collated by data brokers and people search websites, employee personal information is often readily available.

With most US companies concerned about the cybersecurity impact of employee social media use, employees themselves can also be serial offenders when creating personal information security gaps.

 

The Personal Information Security Solution Landscape

In response to the growing threat that personal information presents, the market for information protection solutions is rapidly expanding, with an expected compound annual growth rate (CAGR) of 13% annually over the next 6 years.

However, many organizations are eager to offer more protection to employees as part of a corporate benefits package but are unclear about how that protection actually works. To help clarify this issue, it's useful to think of information security solutions as belonging to one of three main categories.

 

1.Credit monitoring

By scanning changes to an individual's credit file at the three major credit monitoring agencies — Equifax, TransUnion, and Experian — credit monitoring services allow individuals to keep an eye on their credit score in one place.

While anyone can check their credit score by themselves, paid credit monitoring services automate the process and make it easier for individuals to keep track of changes.

For employees, the advantage of credit monitoring as a workplace benefit is the capability to watch out for abrupt changes to their credit scores, which indicate that they are the victim of fraud.

 

2.Identity theft protection

Like credit monitoring services, identity theft protection solutions are best thought of as insurance policies for personal information. However, these kinds of products offered by providers such as Identity Guard, Norton, and OneRep, go a step beyond just looking at an individual's credit score.

As well as conducting credit checks, identity theft protection takes a more comprehensive look at things like court records, loan applications, and utility orders to see whether an individual's personal information is being fraudulently used.

With identity theft impacting record numbers of Americans, identity theft protection is now a popular elective benefit.

 

3.Privacy protection

Credit monitoring and identity theft protection services provide insurance that employees will be notified if their information is misused, but they do little to increase cybersecurity for enterprises.

By the time an employee sees real benefit from these kinds of services, their data has already been exposed, and new cybersecurity risks to their employer created. The reactive nature of credit and identity protection also means that while individuals can notice and remediate fraud faster and easier, the problem of personal data exposure remains outstanding.

Like the service offered by DeleteMe, privacy protection solutions work to solve the root of the problem of personal data exposure. By looking for and removing unnecessary exposure of an individual's personal and professional data, proactive privacy protection drastically reduces the likelihood of fraud occurring in the first place.

For enterprises, this kind of solution also bolsters cybersecurity by minimizing employee personal information leakage and, in turn, taking valuable ammunition away from threat actors.

 

Developing a Proactive Approach to Personal Information Privacy in Your Organization

While every type of solution has its place, true protection for employee personal information results from a layered approach.

At the most basic level, employees need practical training in how to minimize their personal information footprint both at work and at home. As well as emphasizing the potential security risks of an insecure approach to personal information, effective training should also show employees the benefits (i.e., reduced spam and greater personal safety) that privacy brings.

However, training alone is rarely effective. While regular training is crucial, security awareness training programs that teach employees how to spot social engineering scams are usually forgotten in a few months and need to be continually reinforced to remain effective.

On top of training, employee personal information should also be protected by proactive personal information retrieval and removal service. Ultimately, the best way to protect employees and enterprises from the kind of fraud that leverages personal information is to cut the supply of personal data off at the source.

Credit monitoring and identity protection services can form the third layer of a proactive approach. While these services do little to increase enterprise security, they can help reassure employees that they will find out if their data is misused before the problem gets out of hand.

 

Final Thoughts

Even though it doesn't appear on a corporate balance sheet, employee personal information is a valuable corporate asset. With over 90% of organizations regularly experiencing targeted phishing attacks, minimizing employee data exposure needs to be a critical part of every enterprise's security posture.

 

However, rather than offering employees solutions that only work after the fact, organizations need to create a layered, proactive solution that delivers real security value. Employee privacy is too important to remain a personal matter.

KEYWORDS: cyber security fraud Identity Authentication information security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Rob shavell headshot square

Rob Shavell is CEO and co-founder of Abine. Prior to Abine, Rob was VP Product at Identity Force, an identity theft provider, and co-founder of consumer group travel portals, "TravelTogether.com.” He was also an associate at Softbank Capital Partners (Boston) and Softbank / Mobius Venture Capital (Silicon Valley). Shavell has a BA from Cornell University where he began his studies in the school of Architecture. You can find Shavell at LinkedIn: https://www.linkedin.com/in/rob-shavell-494749/ and Twitter: https://twitter.com/robshavell, @RobShavell

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Enterprise Services
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Keyboard

Marks & Spencer Hackers Tricked IT Workers Into Resetting Passwords

Person working on laptop

Governance in the Age of Citizen Developers and AI

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

September 29, 2025

Global Security Exchange (GSX)

 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • data privacy

    How a culture of privacy can help protect your business from ransomware

    See More
  • Increase in Cybercrime Demands Fresh Attention to Employee Onboarding and Training

    When It Comes to Employee Security Awareness Training - Should You be Phishing or Teaching?

    See More
  • growing program

    Security at scale: Growing a security program regardless of headcount, size or budget

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Physical-Security-and-Envir.gif

    Physical Security and Environmental Protection

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!