Which of the following is/are true about security breaches according to the passage?
Directions: Read the following passage and answer the given question.
Security breaches and the compromise of sensitive information are very real concerns for any organisation today. Studies have shown that though the likelihood of the attack from insiders may be very low as compared to external threats, the magnitude of the impact is at least 10 times more than that of the total impact an external attacker can cause. This is because an insider attack is committed by people who know the organisation’s most sensitive secrets and vulnerabilities and have access to its systems. In most cases, breaches by insiders are committed by individuals who have no intention of doing anything wrong.
Data Security Council of India (DSCI) and Price waterhouse Coopers (PwC) have jointly conducted a study to understand the challenges and risks associated with insider threats. The study has been conducted to understand the security posture of the Indian IT/BPO industry from an insider threat perspective and the perceptions of the client organisations on the same.
Surprisingly, not even a single incident was attributed to the senior management of the organisation. This was in contrast to our findings from secondary research, where senior management was found to be involved in a number of such incidents.
The survey revealed that an insider can be motivated to commit a crime due to a number of reasons, viz. information gain, personal financial gain, a new job, unsatisfactory appraisal or unmet professional expectations, an urge to prove oneself, antagonism towards the management etc. As per 89% of the service provider organisations, behavioural motivation to break existing norms is the primary motive that leads to insider threat. This might be due to the predominant youth mix in the IT/BPO industry.
On the other hand, 75% of the respondents in the client organisations believe that personal financial gain is the prime motive for insiders at service provider organisations to carry out illicit activities.
Dissatisfaction with organisation policies was rated as the second most probable reason that leads to insider threat as 44% service provider organisations highlighted this as a concern. However, in contrast, 25% of client organisations believe this to be a reason for insider threat at service provider organisations.
It is encouraging to note that not even a single respondent in service provider organisations considers competition as a driving force for insider threat. This observation is supported by client organisations.
Interestingly, most of the factors such as dissatisfaction with organisational policy, dissatisfaction with immediate supervisor, feeling of entitlement, urge to prove oneself, breaking existing norms and unmet expectations, that lead to insider threats can be controlled. This means that by understanding such (controllable) motivational factors, an organisation can tune its policies to contain insider incidents.