Insider threats take centre stage

Issue 7 2023 Information Security


John Mc Loughlin.

J2 Software, a DTEX Systems partner, has emphasised the inadequacy of current cybersecurity budgets in addressing the core cause of data breaches; insider risks. A recent survey revealed that 58% of organisations believe their budgets allocated to manage insider risks are insufficient to effectively mitigate the increasing costs and frequency of security incidents instigated by individuals within the organisation.

DTEX Systems, in collaboration with the Ponemon Institute, unveiled the 2023 Cost of Insider Risks Global Report. This independent study disclosed a 40% rise over four years in the average annual cost of insider risks, now totalling $16,2 million. Concurrently, the average duration to contain an insider incident has surged to 86 days.

J2 Software CEO, John Mc Loughlin, says that in addition to scrutinising the financial implications of insider security incidents, this year’s study sheds light on how organisations are funding their insider risk programmes. “The research highlights that nearly half (46%) of organisations are planning to bolster their investment in insider risk programs in 2024. Moreover, an overwhelming 77% of organisations have either initiated or are in the process of implementing an insider risk programme.”

As defined by research analyst Gartner, insider risk management encompasses “the tools and capabilities to measure, detect and contain undesirable behaviour of trusted accounts within the organisation.”

Mc Loughlin adds, “Despite the rising costs associated with insider risks, a substantial 88% of organisations allocate less than 10% of their total IT security budget towards managing these internal threats. Organisations boast an IT security budget averaging $2437 per employee, with a mere 8,2% ($200 per employee) designated specifically for insider risk programs and policies.”

Symptom management

DTEX Systems CTO, Rajan Koo emphasised that these findings underscore a diversion of budgets towards reactive ‘symptom management’ despite mounting evidence that the root cause lies within the human factor, represented by insider risks.

“The findings illuminate that insiders, manifesting as insider risks, are the primary cause of data breaches, including those stemming from social engineering. This highlights a pervasive misunderstanding of the various forms of insider risks and the failure to proactively safeguard customer data and intellectual property,” he added.

The 2023 Cost of Insider Risks Global Report offers a comprehensive analysis to comprehend the financial ramifications of insider risks, stemming from either negligent or inadvertent employees, outsmarted employees (including insider incidents linked to credential theft), or malicious insiders.

Dr Larry Ponemon, Chairman and Founder of the Ponemon Institute, commented, “Our goal in conducting this research is to create awareness of the significant costs incurred when employees are negligent, outsmarted or malicious in the handling of an organisation’s sensitive data.”

“We believe this study is unique because it analyses the costs based on the type of insider, the time it takes to contain the incident and the technologies that are most effective in reducing the costs. Such information is beneficial in creating a strategy to deal more effectively with the insider risk while reducing the costs.”

Key findings of the 2023 Cost of Insider Risks Global Report include:

• The average annual cost of an insider risk has risen 40% over four years to $16,2 million, up from $15,4 million in 2022.

• The average number of days to contain an insider incident in 2023 has increased to 86 days. The longer it takes to respond, the higher the cost ($18,33 million for incidents that take more than 91 days to contain).

• Organisations are spending less than 10% of their IT security budget on insider risk management. Organisations had an average IT security budget of $2437 per employee, yet only 8,2% (equivalent to $200 per employee) was allocated specifically to insider risk management programs and policies.

• Most insider risk budget is spent after an insider incident has occurred. Only 10% of insider risk management budget (averaging $63 383 per incident) was spent on pre-incident activities: $33 596 on monitoring and surveillance, and $29 787 on ex-post analysis (this includes activities to minimise potential future insider incidents and steps taken to communicate recommendations with key stakeholders). The remaining 90% (averaging $565 363 per incident) was spent on post-incident activity cost centres: $179 209 on containment, $125 221 on remediation, $117 504 on investigation, $113 635 on incident response, and $29 794 on escalation.

• Insider risk programme funding is set to increase. Despite the fact that most organisations allocate an average of 8,2% of their IT security budgets to insider risk programs, 58% view current spending as inadequate and 46% expect funding to increase in the next year. Seventy-seven percent of organisations have started or are planning to start an insider risk programme.

• Non-malicious insiders cause most insider incidents. 75% percent of respondents said the most likely cause of insider risk is non-malicious; a negligent or mistaken insider (55%), or an outsmarted insider who was exploited by an external attack or adversary (20%).

• More than half of non-insider attacks are caused by social engineering. Fifty-three percent of organisations said social engineering (including phishing, pretexting and business email compromise) was a leading cause of non-insider or external attacks.

• Financial services and service organisations have the highest average activity costs. The average activity cost for financial services is $20,68 million, and services (including accountancy, consultancy and professional services firms) are $19,09 million.

• Top-down support is the gold standard. Among organisations that have, or plan to have, a dedicated insider risk programme, 52% report that top-down support and championing of the programme (e.g., an insider risk steering committee) is a key feature. Fifty-one percent have a dedicated cross-functional team from legal, human resources, line of business and IT security.

• AI/ML is essential to insider risk management. One-third of organisations view artificial intelligence and machine learning as essential to the prevention, investigation, escalation, containment and remediation of insider incidents, while 31% view it as very important.

For more information, contact J2 Software, +27 11 794 1096, [email protected], www.j2.co.za




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.