Cyberstudy
PDF p.32 In progress

Internal Threat Actors

Open PDF at p.32 17 flashcards

Summary

PDF p.32

Internal threat actors, or insiders, are individuals within an organization who have been granted access to its systems. These threats can be malicious or unintentional, and they include employees, contractors, guests, and former insiders.

In plain words

Supplementary — not from your PDF

Insiders already have access: employees, contractors, guests, even former staff whose accounts weren't removed. Some are malicious, but many cause harm by accident, such as weak passwords or 'shadow IT' nobody approved.

Detailed explanation

PDF p.32
  • Internal Threats
    • Definition: Arise from actors identified by the organization and granted access.
    • Types
      • Permanent Privileges: Employees.
      • Temporary Privileges: Contractors, guests.
    • Former Insiders: Ex-employees with residual permissions or grievances.
  • Motivations
    • Revenge: Disgruntled employees or ex-employees.
    • Financial Gain: Opportunistic or targeted attacks.
    • Examples
      • Structured Attack: Planned campaign to modify invoices and divert funds.
      • Opportunistic Attack: Guessing passwords on accessible files.
  • Whistleblowers
    • Definition: Individuals with ethical motivations for releasing confidential information.
    • Protection: Cannot be threatened or labeled punitively for protected disclosures.
  • Unintentional Threats
    • Causes: Lack of awareness, carelessness (e.g., poor password management).
    • Shadow IT: Unauthorized hardware/software introduced by users, creating unmonitored attack surfaces.

Important terms

taken from the text above
Internal Threats
Arise from actors identified by the organization and granted access.
Permanent Privileges
Employees.
Temporary Privileges
Contractors, guests.
Former Insiders
Ex-employees with residual permissions or grievances.
Revenge
Disgruntled employees or ex-employees.
Financial Gain
Opportunistic or targeted attacks.
Structured Attack
Planned campaign to modify invoices and divert funds.
Opportunistic Attack
Guessing passwords on accessible files.
Whistleblowers
Individuals with ethical motivations for releasing confidential information.
Causes
Lack of awareness, carelessness (e.g., poor password management).
Shadow IT
Unauthorized hardware/software introduced by users, creating unmonitored attack surfaces.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Malicious: an employee planning to change invoice bank details.
  • Unintentional: someone uploading work files to a personal cloud drive.
  • Former insider: an ex-contractor whose VPN account still works.

Scenario

Marketing starts using an unapproved online file-sharing tool to swap large files with an agency. Nobody in IT monitors it. It's shadow IT, an unintentional insider threat that widens the attack surface.

Common mistakes

Supplementary — not from your PDF
  • Thinking insider threats are always malicious.
  • Forgetting offboarding. Leftover accounts turn former staff into insiders.

Practical skills

Supplementary — not from your PDF
  • Suggest controls for each insider type: access reviews, training, offboarding, DLP.

What I should remember

Key Points PDF p.32
  • Internal Threats
    • Access: Granted by the organization.
    • Types: Employees, contractors, guests, former insiders.
  • Motivations
    • Revenge: Grievances.
    • Financial Gain: Opportunistic or targeted.
    • Examples: Structured (planned) vs. opportunistic (unplanned) attacks.
  • Whistleblowers
    • Ethical Motivation: Releasing information for ethical reasons.
    • Protection: Against retaliatory actions.
  • Unintentional Threats
    • Causes: Awareness, carelessness.
    • Shadow IT: Unauthorized IT resources.