In a quantum sphere that is increasingly going digital, the cybersecurity aspects pertaining to the data that law firms and in-house counsels deal with, has become more significant than ever before. Despite the prevalence of multifaceted security measures like complex passwords, firewalls, and multi-factor authentication, there still exists a quite significant vector of risk – the insider employee. Optiv defines insider risk as the potential for an employee or individual with legitimate access to negatively impact the organization’s people, data, or resources.
The 2023 Cost of Insider Risks Global Report by the Ponemon Institute notes that the costs associated with insider risk are at an all-time high. In 2023, the average annual expense of a data breach from an insider risk was reported as $16.2 million per company. On average, it took about three months to contain these data breaches.
While it might be unrealistic to expect eradication of insider risk altogether, it can be considerably minimized using technical and non-technical controls and focusing on employee engagement.
Understanding Insider Risk
In order to efficiently reduce insider risk, it is crucial to appreciate the differences between unintentional and intentional insider risk. Unintentional risk can occur when an employee or a closely associated individual unintentionally causes harm due to negligence or complacency. Such insiders can compromise data security due to careless acts such as loosing a laptop with unencrypted data, sharing a password, or clicking on links in a suspicious email. Unintentional data loss can occur when insiders neglect to follow proper security protocols. In 2023, these non-malicious insiders accounted for 75% of all insider risk incidents. Non-malicious Insider Risk.
Intentional or malicious insider risk incidents involve individuals who deliberately seek to cause financial or reputational harm to their organization. These incidents include espionage, intellectual property theft, unauthorized disclosure, sabotage, and workplace violence. The most significant is insider workplace violence, which the UK National Protective Security Authority defines as any action or threat of physical violence, harassment, sexual harassment, intimidation, bullying, or other threatening behavior by a coworker in the workplace. MITRE Insider Threat Research & Solutions covers these in detail. Though less frequent, the average cost of each intentional breach by an insider was over $700,000 in 2023 according to Ponemon.
Using Tech to Reduce Insider Risk
Organizations can adopt technical controls to mitigate insider threats. Detecting controls like auditing provides accountability and offers the ability to monitor unusual user behavior that may indicate attempts at data exfiltration or unwanted system modification. Preventative controls reduce the load on analysts and hinder known malicious behaviors. These include proper account provisioning and de-provisioning, observing least-privilege access management best practices, separating duties for critical system changes, and having strict remote access controls. If a malicious act is performed, corrective controls, such as data backups, can restore systems back to functioning.
Technical controls are eyed as an essential type of control that organizations can employ to alert an organization of the first signs of suspicious activity and used as evidence when a suspicious activity occurs. The Cybersecurity and Infrastructure Security Agency (CISA) suggest in particular that User Behavior Analytics (UBA) software can help identify these anomalies and alert analysts promptly of unusual user behavior. Insider Threat Mitigation Guide (cisa.gov) offers further insights on this approach, as does theCommon Sense Guide to Mitigating Insider Threats, Seventh Edition (cmu.edu).
Moreover, preventative controls can be a great ally in scrutinizing and alleviating insider threats by forfending malicious actions from taking place. While provisioning user accounts, least privilege permissions should be employed to ensure users only have access to systems and applications required for their specific job duties. Furthermore, a thorough and dependable user de-provisioning process should be put in place to ensure access to previous systems and account passwords are removed or changed once a user departs the organization. Logical controls requiring multiple users to authorize crucial system changes should also be incorporated. Common Sense Guide to Mitigating Insider Threats, Seventh Edition (cmu.edu).
The final line of defense, although mitigations may be in place to reduce risk, in the event of a threat actor inflicting damage to an organization’s systems, corrective controls like data backups and configuration backups, can revert systems to normal operations. It is advised that these backups and rollback plans should be tested regularly.
Non-Technical Solutions to Reduce Insider Risk
While technical controls are essential for safeguarding against insider threats, non-technical tactics also play a crucial role in mitigating such risks within legal firms and corporate legal departments. Such non-technical strategies can minimize insider risk by bolstering positive reinforcement and incentives and reducing negative environment factors.
Creating a positive work environment is deemed crucial in reducing insider risk. Fostering a culture of trust, transparency, and collaboration, cultivates a sense of loyalty and commitment among employees and spreads a feeling of shared responsibility for information security. Actually involving employees, strengthens their dedication to upholding ethical standards and protecting sensitive information.
Addressing employee grievances in a fair and transparent manner and providing channels for employees to voice their concerns can significantly reduce the risk of insider threats from internal dissatisfaction or disgruntlement. Hence, resolving conflicts, understanding issues is one critical part of nipping in the bud, the risk of insider threats.
Organizations should provide regular security awareness training to all employees, highlighting the value of protecting proprietary information. Regular communication reinforces the value of information security and keeps it top of mind for employees. Creating an environment where employees feel free to report suspicious activities or security concerns without fear of retaliation is key. SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations | CSRC (nist.gov) provides further elucidation on non-technical approaches.
Implementing robust background checks and vetting procedures during the hiring process should be standard practice for most organizations. Similarly, exit interviews and offboarding procedures offer a last chance to prevent data loss. Organizations should conduct thorough exit interviews and ask departing employees to sign, confirming no company files are being taken. Also, revoking promptly, all access to sensitive information is a part of the effective offboarding procedures. SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations | CSRC (nist.gov).
Conclusion
Both technical and non-technical measures are vital for reducing insider risk in the legal industry. Law firms and corporate legal departments can effectively safeguard sensitive information by having the right technical controls in place, fostering a positive work environment, addressing resentment and discontent and focusing on strengthening employee engagement.
Authors: Scott Busch & Ethan Powell with Joshua Smith