5 things
Channel Brief: Mosyle Acquires Assetbots, AI Features Drive Canva Price Hike

Welcome to September, folks! Besides being the traditional back-to-school time of year (though I know many folks are already back in the classroom), September is also national insider threat awareness month (NITAM).If you aren't familiar, NITAM was first observed in 2019 in the U.S., but now includes international participants, too. According to the U.S. government, this "annual, month-long campaign brings together thousands of U.S. security professionals and policy makers from government and industry, located in 25 countries around the globe, to educate government and industry about the risks posed by insider threats and the role of insider threat programs."The Under Secretary of Defense for Intelligence & Security (USD(I&S)), the National Insider Threat Task Force, and the Defense Counterintelligence and Security Agency (DCSA) partner together with other stakeholder organizations to expand the impact and audience of the NITAM campaign each year. Organizations that participate in the campaign increase awareness and promote reporting of insider threats (InTs) across their workforces.Insider threats can come from a number of directions, including when employees leave an organization and aren't properly offboarded, said Larry O’Connor, CEO and founder, Other World Computing (OWC). “One of the most significant insider threats facing organizations today is the challenge of properly managing employee exits and access revocation. Even weeks or months after departure, it is all too common for exiting employees to still have lingering access to company systems and data. From there, malicious insiders can then steal sensitive data or sabotage critical systems rather easily by exploiting these oversights. And, as organizations have become more reliant on cloud services and remote work, unfortunately this risk has only grown," O'Connor said."Luckily, today we have robust identity and access management controls to mitigate these insider risks. This includes automating the process of disabling accounts across all apps and services when an employee leaves the company. Leveraging technologies like two-factor authentication and certificate-based authentication can also help prevent unauthorized access -- even if login credentials are compromised. Additionally, maintaining comprehensive, air-gapped backups of critical data is essential - this provides a secure fallback in case malicious insiders do manage to delete or encrypt production data," he said.These insider attacks can be costly, said Carl D’Halluin, CTO, Datadobi. “National Insider Threat Awareness Month is a crucial reminder not to underestimate the significance of risks from within -- regardless of whether they are malicious or a result of negligence," D'Halluin said. "For a clearer picture of just how significant, the 2023 Cost of Insider Risks Global Report by the Ponemon Institute revealed that in 2023, the average annual cost of an insider risk rose to $16.2 million per organization, while the average time to contain an incident extended to 86 days, compared to $15.4 million and 85 days in 2022."And they can come from unlikely sources you might not otherwise consider, including the humble PDF document format, said DeeDee Kato, vice president of corporate marketing, Foxit. “This year during National Insider Threats Awareness Month I think it’s time to shine a light on the importance of robust document security measures – especially, when it comes to the often-overlooked PDF," Kato said. "Whether you are a government agency, a business, a healthcare provider, a financial institution – it is a safe bet that highly sensitive information is contained within your PDF docs. ... During this National Insider Threats Awareness Month and all the months to come… remain relentless in your pursuit to prevent insider threats – leave no stone unturned, and scrutinize every potential risk, even those that may appear benign, like the seemingly harmless PDF.”As always, drop me a line at [email protected] if you have news to share or want to say hi!Grab your coffee. Here's what else you need to know today.AppDirect Thrive! September 17-19, Chicago, Illinois MSSP Alert Live, October 14-16, Austin, Texas Canalys North America Forum, October 22-24, Miami, Florida Kaseya Dattocon, October 28-30, 2024, Fontainebleau, Miami Beach, Florida Ingram Micro One, November 6-8, Gaylord Resort, Washington DC IT Nation Connect, November 6-8, Orlando, Florida OpenText World, November 19-21, The Venetian Resort, Las Vegas, Nevada
You can skip this ad in 5 seconds