An insider threat is defined as a security threat that develops from inside
the organization being attacked by an employee of the organization. The
inside threat could come from present and former employees, board
members, or anyone who at any time had access to proprietary or
confidential information from within the organization.
Tesla reported and file a lawsuit against an employee that was angry
about being reassigned to a new position. The employee then altered
production software code that would export massive amounts of
proprietary and production data to third parties outside the company. He
then installed the coded software onto three other employees' computers,
which would ensure the exploit would still export data after his
termination and implement the other employees as co-conspirators.
"
The employee created fake usernames and passwords to carry out his
miss deeds. Tesla could restrict the editing and creation of usernames to
HR or Security to prevent this from reoccurring, also they could silo the
production software to only software engineers and continuously monitor
changes made to the software and by whom.