h digitalfootprint web 728x90

Audit: Employees largely responsible for security breaches

/wp-content/uploads/2022/11/BR_web_311x311.jpeg

Though many companies fear the harm an unknown hacker could cause to their internal computer systems, a recent survey found that the more likely threat is closer to home.

Ames-based Palisade Systems Inc. conducted a year-to-date audit of reported data theft incidents recorded by privacyrights.org. According to the audit, employees represent the largest and costliest threat to organizations that store, send or access consumers’ personally identifiable information, such as Social Security numbers, bank account numbers and health-care records.

From June 21, 2005, through May 31, 2006, privacyrights.org recorded 126 data breaches, 83 of which were caused by trusted sources such as employees or consultants who had authorization to access sensitive data.

Still, the majority of data breaches were found to be accidental. Of the 126 breaches, 43 were caused by hackers. Of the 83 internal breaches, nine were considered malicious, 69 were accidental and five were ruled undetermined.

The audit revealed that none of the organizations that discovered unauthorized use or access of sensitive data had deployed new content monitoring and blocking technology capable of blocking sensitive data before it is sent outside the network.

Palisade Systems, a provider of content security and data protection products, is one of fewer than 10 vendors that produce the new content monitoring and blocking technology.

Unlike previous technologies that are limited to only monitoring structured data such as Social Security numbers through pattern or data matching, the company’s PacketSure product, which is used by more than 500 organizations, uses an artificial intelligence feature that systematically looks for sensitive data even when the data are purposely disguised or scrambled by an employee.

“PacketSure does an excellent job at enforcing both an organization’s network security policy and protecting their clients’ confidential information,” said President and CEO Kurt Shedenhelm. “If PacketSure had been deployed by the organizations that had data breaches over the past year, we would have seen a dramatic reduction in the amount of data thefts and breaches caused by trusted sources like employees and consultants.”