In a number of recent newsletters we’ve looked at spear-phishing and how it can make your employees, customers, clients and users into unwitting dupes of the crackers and malfeasants who are trying to steal the “family jewels” of your organization. Just ask the folks at RSA (who insist that they are the “security division” of EMC).
BACKGROUND: Is it time for RSA to open up about SecurID hack?
The only effective means of stopping these kinds of attacks is education — teaching your people, and teaching them over and over again if necessary, what due diligence they must take when looking at emails, statuses, tweets and the like. And, of course, moving on those who can’t learn.
But a recent SailPoint Market Pulse Survey examined the current state of employee compliance with corporate policy related to private, sensitive data to help identify weak links in IT risk mitigation programs and uncovered a far different risk.
The survey, conducted by Harris Interactive on behalf of SailPoint, interviewed 3,484 employees in the United States, Great Britain and Australia and found that an alarming number are exposing their companies to internal sabotage and theft.
22% of U.S. employees, 29% of Australian employees and almost half of British (48%) employees who have access to their employer’s or client’s private data indicated they would feel comfortable doing something with that data, regardless if that access was intentional or accidental. Further, 10% of American, 12% of Australian and 27% of British employees with access admitted they would forward electronic files to a non-employee, and 9% of Americans, 8% of Australians and 24% of Britons of these same group admitted they would copy electronic data and files to take with them when they leave a company.
These aren’t people who have been duped, these are people who knowingly violate company policies and — in some cases — criminal laws without compunction.
Fortunately, SailPoint has an answer (you knew they would, didn’t you). It’s the new discipline called Identity Governance, which they define as methods that can serve to get your organization compliant, keep it compliant, and then streamline the overall process for managing user access along every point of a user’s life cycle.
Certainly the results of this survey serve SailPoint’s purpose — but the results scared me, and they should scare you.
The SailPoint survey also asked about mobile devices and found that 15% of American, 29% of British and 18% of Australian employees use their mobile devices to access their company’s private Intranet or portals. Next issue we’ll look at another scary survey about mobile access.




