
Editor’s note: Wired for Safety is a column on cybersecurity and other tech issues. Duane Dunston is an assistant professor of cybersecurity and networking at Champlain College. He received his bachelor’s and master’s of science from Pfeiffer University. From 2001 to 2011 he worked in cybersecurity for NOAA. He is a doctoral student at Northeastern University with a concentration in Curriculum, Teaching, Learning, and Leadership. His other activities include “You Have A Voice,” a project to develop an electronic screening assessment to identify human trafficking victims.
[I] hope that you are having a safe online Cybersecurity Awareness Month.
We’ve had some comments and some questions this week that have helped spark some topics. The question and comments about privacy of data on computer systems brings up to a type of cybercrime that is not often discussed: the insider threat — In other words, the security of people with access to information.
I do not believe we can expect privacy when our data is on electronic systems or our activities are monitored by devices. That is because even with the best secure systems, people are still involved and can access the data. Even organizations that spend millions of dollars on security cannot guarantee the people accessing the data will keep it confidential — Edward Snowden and Reality Winner. The insider threat poses the greatest risk to any cybersecurity best practices. People are involved with maintaining the confidentiality, integrity and availability of data. The motivations for insider threat breaches vary and it is a topic of cybersecurity that does not receive much attention, except with large data breaches. Organizations can prepare and analyze the threat using the Insider Threat guide provide by Carnegie Mellon.
Why don’t you hear about insider threats with small businesses?
• The cost of litigation may exceed what was stolen. Small business owners may not have the financial resources to prosecute the accused so firing them is the easiest solution and it may not be reported to authorities.
• People who work in small businesses often create strong relationships. If the trust is broken due to theft, the impact on the perpetrator and his or her family may factor into the decision to not report it.
• The business may face public scrutiny depending on its reputation or the status of its finances and operation. If a business is on the verge of closing, for instance, but wants to continue to try to make the business work, or can’t because of the impact on personal and professional life, it may decide to conceal the incident.
These types of decisions may help the business that was impacted, but does not help the ex-employees or their future employers, such as the case of an former University of Vermont employee who was dismissed from one job for allegedly stealing $3,000 and ended up stealing $185,000 from UVM.
Vermont is not a stranger to insider threats. VPR had a segment on the embezzlement that occurs here in Vermont. Hardwick Electric Co. had over $1 million embezzled by an employee. Owners engaged in these activities are even more difficult to detect and usually steal a larger sum of money. While the argument is with the numbers and the study, the central issue is that the impacts can be substantial regardless of how much money was stolen. The Milton youth football team is a small program, so for it $9,000 or $10,000 is a lot of money to lose.
It is worth paying for an independent auditor to review financials for organizations. They look not only for fraud, but also for efficiency. They may recommend ways money could be better spent or ways to eliminate unnecessary expenditures, such as paying for services and resources that are not being utilized. A bookkeeper may keep paying the bills because no one reported to them a given service was no longer used. An independent auditor could review warehouse and product inventories. Theft is not always cash money or wire transfers of money, but can also be products and goods, which do cost money. Again, the auditor could help uncover overstocked products or purchasing of products and services that are not needed for inventory.
Here is a document by the FBI that discusses warning signs for insider threats. I do not own a business, though I can identify with the difficulty in having one’s own employees audited, especially those who have been around for years. It may be good business to do it, despite the possibility it may uncover illegal activity.
