d Intellectual property (IP) theft is a growing problem for businesses
today as more and more data is stored electronically. There are many
individuals who are looking to steal this private information for
purposes such as corporate espionage, or attackers looking to sell this
information to our competitors. Attackers typically go after targets
known to possess confidential data and trade secrets, and in some
cases, security experts believe the perpetrators may even be working
for business rivals seeking to gain a competitive edge. (Cooper, 2017).
d d There are several methods an attacker will use to gain access
to this sensitive information. The most common is the use of
Advanced Persistent Threats or APTs. APTs refer to a category of
high-risk computer intrusion threats by threat actors that aggressively
pursue, and compromise chosen targets. The main goal of an APT is
data exfiltration. (Trend Micro, 2013). APTs are usually delivered using
social engineering tactics to deliver exploits through email
attachments. These exploits can lay dormant until the threat actor
decides to activate it which in turn can install malware into the
system. Once a threat actor penetrates the network and establishes
persistent control, they can easily transfer the gathered company data.
(Trend Micro, 2013). Intellectual property is also at risk from other
threats such as malicious insiders and unpatched systems.
d d Fortunately, there are many ways in which business and all of
us here at PBI can prevent sensitive information from falling into the
wrong hands due to these threats. I would recommend that PBI put in
place a data loss prevention policy that would discourage employees
from the unauthorized use or disclosure of sensitive information. This
policy should outline specific pieces of data and information that
should not be shared outside the company. It should also include stiff
penalties for violating the policy up to and including termination and
possible legal action.
d d There are also many technical processes that can be put in
place to regulate which employees are allowed access to certain types
of data. To accomplish this, data must first be classified according to
its sensitivity. Cooper suggests companies take an inventory of IP to
classify the relative importance of valuable assets. (Cooper, 2017).
Once IP is classified, we can implement separation of duties and least
privilege to regulate which employees can access which data.
d d The use of network monitoring tools is also an effective
approach to prevent IP loss from APTs and malicious insiders.
Network monitoring tools can gather and analyze network data to give
system administrators information related to network problems and
traffic anomalies. (Pecha, 2021). PBI can also implement an intrusion
detection and intrusion prevention device which can recognize threats
and either notify our cybersecurity professionals of a possible attack
or prevent it from even happening. It is also important that PBI keep
all network equipment and devices up to date with the latest patches
and fixes to prevent attacker from exploiting them.
d d It takes a coordinated team effort to prevent IP theft from
happening. Data must be classified, and users must only be granted
access to this data based on their job duties. Effective network
monitoring tools must also be used to help prevent threat actors from
utilizing APTs to gather sensitive company data. IP can be critical to
the well being of a company and as such must be protected at all
costs.
References:
Cooper, Charles. July 13, 2017. Cyberespionage: Your intellectual
property under threat.
d d https://www.csoonline.com/article/3200608/cyberespionage-
your-intellectual-property-under-threat.html
Trend Micro. 2013. Data Exfiltration: How Do Threat Actors Steal
Your Data.
d d http://about-threats.trendmicro.com/cloud-content/us/ent-
primers/pdf/how_do_threat_actors_steal_your_data.pdf