Hostile or malicious insider activity is one of the malicious activities that attracted me to
research today. Malicious insider activity are the threats that is called within the house.
According to the CERT National Insider Threat Center, a malicious insider threat is a threat
that occurred by a current or former employee, contractor, or business partner who has
legitimate access to organization’s network system, and intentionally misused that access
without caring confidentiality, integrity or availability of the organization’s information or
informational systems. Such type of insider behavior not only threatens organization
resources but also place survival of the organization to risk.
&
To illustrate an example, I would like to choose cyber sabotage as one of the malicious
insider threats. According to Tesla CEO Elon Musk, one of Tesla employee conducted
extensive and damaging sabotage in their operation. The employee made direct code changes
to the Tesla Operating System under false username exploiting huge amounts of highly
sensitive Tesla data to unknown third parties. The incident was the employee denied a raise
and intentionally access the restricted database that was kept without anyone noticing and
found that many peers had 20% higher salaries than the employee. The employee copied that
database and posted it in the company’s website. This behavior disclosed the privacy of many
employees, built less trust on customers, and hampered the reputation of the company.&
&
After this malicious insider activity, Mr. Musk realized that the first concern was cyber
security. The main reason of happening this activity was insider security breaches were seen
more costly than those from outsiders. Both administrative and technical controls such as
developing and refining policy, training and awareness programs and technical monitoring
systems are important countermeasures that can address the malicious activity. Strong hiring
practices that include thorough screening through multiple interviews and pre-employment
testing might avoid high risk individuals which might be one additional preventive
countermeasure.
&
In this article, study was done on dark triad that included three social adverse personality
traits namely, Machiavellianism, narcissism, and psychopathy to figure out whether these
traits had relationship to malicious insider threats or not. The conclusion was the relationship
between dark trait personality traits and intention committed insider cyber sabotage.
Educating managers on the dark traits might help to identify high risk individuals which is
one of the important administrative countermeasures for organization to address this type of
activity.
Source
Michelle Maasberg.2020.The Dark Triad and Insider Threats in Cyber Security..p. 64-
70.http://libdatab.strayer.edu/login?url=https://search.ebscohost.com/login.aspx?
direct=true&db=bth&AN=147083011&site=eds-live&scope=site.