The risks from ex-employees is greater than from hackers

103 Views

TalkTalk today formally went into administration shortly before the announcement of a rescue bid by BT, but the collapse of the country’s fourth largest broadband provider has raised serious concerns about national security. TalkTalk is said to provide telecoms services to the Ministry of Defence and other government bodies. Any business going through this kind of uncertainty should ask who still has access to key systems, and what are they doing with it.

There are a wide range of controls companies can put in place to mitigate the risks of data breaches from employees. However, history shows us that it is at times of volatility and change with increased stress and pressures on the workforce that lead to accidental, or more deliberate, breaches in security.

The risk is well documented. In 2014 an internal auditor at Morrisons, bearing a grudge after a disciplinary, leaked the payroll details of almost 100,000 colleagues. He was jailed for eight years and the case went to the Supreme Court in 2020.

In the US, an IT administrator fired from a medical centre in 2017 got back into its network four days later using administrator credentials, deleting user accounts and a file server and locking staff out of patient records.

Staff who are worried about their future, facing redundancy or preparing to leave the business, may still have access to sensitive systems, customer data, and intellectual property. Organisations facing financial problems, restructuring, or insolvency are particularly vulnerable to malicious insider activity and data breaches caused by such disengaged employees.

In such circumstances, these are the top five actions companies should take to mitigate insider threats:

    1. Create a clear response plan for staff breaches: When an employee breaks a security protocol or triggers an alert, the business should have a defined process for investigating the incident, limiting any damage, and involving governance, legal, or HR teams where appropriate.
    2. Use behaviour analytics to spot unusual activity: Behaviour analytics can identify when employees access unfamiliar systems, work in unexpected ways, or display activity that differs from their normal patterns.
    3. Build a security-aware workplace culture: Employees form a vital human firewall, so regular training should help them recognise phishing attempts, handle sensitive data safely, report concerns promptly, and understand the risks of entering company information into public AI tools.
    4. Monitor how sensitive data is being moved: Businesses need visibility of downloads, USB transfers, personal email use, and uploads to cloud storage.
    5. Control access throughout the employee lifecycle: Apply the principle of least privilege so people can access only the systems they need and use a robust joiners, movers, and leavers process to remove every account promptly when someone changes role or leaves.

As ever, prevention is better than cure. Companies need to treat this kind of risk as a board-level responsibility, ensuring sophisticated, AI-powered analytics software is in place to detect suspicious employee behaviour.

This is not about Big Brother; it is about taking sensible, practical steps to protect vital company assets from a well-known, if uncomfortable, source of threat.”

To find out more about Cybit please visit https://cybit.com/.