From HP to Verizon and Ashley Madison, data leaks are almost commonplace in today’s data-driven society. Alarmingly, according to a recent survey by Kroll, the average organizational cost of a breach hovers near the $6 million mark. What many companies are not aware of is that far too frequently, these infractions are made possible by individuals within the organization. In fact, according to the experts at DigitalGuardian, employees within the company pose a greater security risk than do attackers from outside the organization.

Any team members – from outsourced contractors to employees – engaging in seemingly harmless activities are opening the front door to major security issues. The Kroll survey showed that 31 percent of the time, employee negligence is the prime culprit for a data breach.

Lack of Training Makes Employees Unaware and Dangerous

According to a TechRadar survey, employees put corporate information at risk on a daily basis in numerous ways:

  • Eighty-four percent of survey respondents send sensitive information from their personal, unprotected email accounts.
  • More than 50 percent of employees said they use an open-cloud server such as DropBox or YouSendIt.
  • More than 30 percent admitted to having misplaced a USB or other external drive with sensitive information (and only 51 percent reported this loss to the IT team).

Careless workers can be a major security risk. One wrong click, and an entire company file can be shared, misplaced or even deleted, costing an organization millions in reparations.

Additionally, it is far too easy for an employee to be manipulated into unintentionally delivering sensitive information such as passwords, files or account numbers to a hacker waiting on the other end of a phishing scam or other malicious attacks.

Keeping Information Safe Post-Firing

Yet another problem exists for a company when letting employees go. For whatever reason, there are times when it is appropriate to fire an employee, but businesses have to be on guard about whom they let go and how. Heimdal Security released a harrowing statistic: Fifty-nine percent of former employees steal corporate data when they quit or are fired. Vindictive and out for revenge, many disgruntled employees will take company secrets with them and expose them to the public or sell them to the competition as a way to get back at their ex-employers for showing them the door.

Executive Positions Hold Higher Risks

Moving up the corporate chain introduces an entirely new and exponentially more dangerous threat: sensitive data leaks. Managers, vice presidents and C-level executives have access to critical data such as company earnings, legal transactions, business development plans and more. When data of that nature is leaked, the psychological and financial repercussions are catastrophic.

According to IBM’s most recent study, data breaches cost companies an average of $158 per record leaked! Highly sensitive data leaks result in company stocks dropping in value, potential company investments being canceled, competitors gaining a developmental edge and worse.

It’s no surprise, then, that in a recent Ovum report, 40 percent of IT professionals believe that privileged (or high-level) users were the greatest security threat to their own organizations.

Tracking to Prevent: Ways to Measure Risk Score

To deal with this growing problem, many organizations are opting for employee risk management systems, which monitor and analyze employee behavior for potential security risks. The systems can assign employees and/or contractors a risk score to help managers assess their security status across the organization.

Measuring employee risk could help assess the likelihood that an employee may leak sensitive data – accidentally or intentionally – by tracking their various activities, such as email behavior, file sharing, keyword logging, document printing, internet activity and cloud uploading. Monitoring metrics, plus a methodological approach in being active and aware within each department, empowers managers to assess employee security risk based on the number of risk-potential factors triggered.

Training for Safety: Managing High-Risk Team Members

If an employee or contractor is deemed high-risk due to negligent technology practices, the organization can then properly educate them on security best practices, such as 2FA, logging out of all user accounts upon work completion, implementing highly secure passwords and never downloading files from unidentified sources.

Should an employee receive a high risk score due to other factors, the company may then wish to restrict their access to vital information, upload security monitoring software on their computer and/or keep a closer watch on their data usage patterns.

Applying such tactics to reduce company risk can save a business millions of dollars as well as hours of unnecessary damage control and reputation management.