PDF p.32
In progress
Internal Threat Actors
Summary
PDF p.32Internal threat actors, or insiders, are individuals within an organization who have been granted access to its systems. These threats can be malicious or unintentional, and they include employees, contractors, guests, and former insiders.
In plain words
Supplementary — not from your PDFInsiders already have access: employees, contractors, guests, even former staff whose accounts weren't removed. Some are malicious, but many cause harm by accident, such as weak passwords or 'shadow IT' nobody approved.
Detailed explanation
PDF p.32-
Internal Threats
- Definition: Arise from actors identified by the organization and granted access.
-
Types
- Permanent Privileges: Employees.
- Temporary Privileges: Contractors, guests.
- Former Insiders: Ex-employees with residual permissions or grievances.
-
Motivations
- Revenge: Disgruntled employees or ex-employees.
- Financial Gain: Opportunistic or targeted attacks.
-
Examples
- Structured Attack: Planned campaign to modify invoices and divert funds.
- Opportunistic Attack: Guessing passwords on accessible files.
-
Whistleblowers
- Definition: Individuals with ethical motivations for releasing confidential information.
- Protection: Cannot be threatened or labeled punitively for protected disclosures.
-
Unintentional Threats
- Causes: Lack of awareness, carelessness (e.g., poor password management).
- Shadow IT: Unauthorized hardware/software introduced by users, creating unmonitored attack surfaces.
Important terms
taken from the text above- Internal Threats
- Arise from actors identified by the organization and granted access.
- Permanent Privileges
- Employees.
- Temporary Privileges
- Contractors, guests.
- Former Insiders
- Ex-employees with residual permissions or grievances.
- Revenge
- Disgruntled employees or ex-employees.
- Financial Gain
- Opportunistic or targeted attacks.
- Structured Attack
- Planned campaign to modify invoices and divert funds.
- Opportunistic Attack
- Guessing passwords on accessible files.
- Whistleblowers
- Individuals with ethical motivations for releasing confidential information.
- Causes
- Lack of awareness, carelessness (e.g., poor password management).
- Shadow IT
- Unauthorized hardware/software introduced by users, creating unmonitored attack surfaces.
Examples & real-world scenarios
Supplementary — not from your PDF- Malicious: an employee planning to change invoice bank details.
- Unintentional: someone uploading work files to a personal cloud drive.
- Former insider: an ex-contractor whose VPN account still works.
Scenario
Marketing starts using an unapproved online file-sharing tool to swap large files with an agency. Nobody in IT monitors it. It's shadow IT, an unintentional insider threat that widens the attack surface.
Common mistakes
Supplementary — not from your PDF- Thinking insider threats are always malicious.
- Forgetting offboarding. Leftover accounts turn former staff into insiders.
Practical skills
Supplementary — not from your PDF- Suggest controls for each insider type: access reviews, training, offboarding, DLP.
What I should remember
Key Points PDF p.32-
Internal Threats
- Access: Granted by the organization.
- Types: Employees, contractors, guests, former insiders.
-
Motivations
- Revenge: Grievances.
- Financial Gain: Opportunistic or targeted.
- Examples: Structured (planned) vs. opportunistic (unplanned) attacks.
-
Whistleblowers
- Ethical Motivation: Releasing information for ethical reasons.
- Protection: Against retaliatory actions.
-
Unintentional Threats
- Causes: Awareness, carelessness.
- Shadow IT: Unauthorized IT resources.