The insider threat : a problem wrapped in perplexity

Renaud, Karen (2024) The insider threat : a problem wrapped in perplexity. FutureScot.

[thumbnail of Renaud-FutureScot-2024-The-insider-threat-a-problem-wrapped]
Preview
Text. Filename: Renaud-FutureScot-2024-The-insider-threat-a-problem-wrapped.pdf
Final Published Version
License: Strathprints license 1.0

Download (3MB)| Preview

Abstract

The insider threat is a real problem for modern organisations. The human is undeniably a lot harder to secure than technical parts of the socio-technical system. The traditional approach is to formulate policies, disseminate them during awareness drives, and mandating compliance. When someone makes a mistake like clicking on a phishing message, they are sent for retraining. This approach relies on two assumptions: (1) knowing=doing, and (2) compliance will reduce the insider threat.