Businesses Increasingly at Risk From Insider Threats

執筆者
Nathan Eddy
Nathan Eddy
Published: Nov 13, 2015
Updated: Feb 2, 2021
2 minute read
skyhigh and it security
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

On average, organizations experience 5.1 incidents each month in which an unauthorized third party exploits stolen account credentials to gain access to corporate data stored in a cloud service, according to a report from Skyhigh Networks.

The study, derived from analysis of actual cloud usage across more than 23 million employees, found 89.6 percent of organizations experience at least one insider threat each month, which is up from 85 percent for the same quarter last year.

In addition, 55.6 percent of organizations experience unusual behavior by privileged users, such as administrators accessing data they should not, each month.

“While small businesses may consider themselves too small to be targets, almost all businesses have documents that are considered sensitive – like customer data or business information they want to keep from competitors,” Kamal Shah, senior vice president of products and marketing at Skyhigh, told eWEEK. “Small businesses are much less likely to have a chief information security officer or other form of IT security leadership. They’re also less likely to have a plan of action in place to respond to a data breach.”

Shah says the first step is education, and he explained security education functions best when it is a seamless part of the user experience, which he called just- in- time training.

“For example, if IT blocks access to a service or uploads to a specific high risk service, be transparent about why that behavior violated security policy,” he said. “Most employees want to do the right thing when it comes to information security, so security education should provide them with the resources to make smart choices regarding data security.”

The study also found 28.1 percent of employees have uploaded a file containing sensitive data to the cloud and the average organization shares documents with 849 external domains through these services.

Of all documents stored in file sharing services, 37.2 percent are shared with someone other than the document’s owner, 71.6 percent of shared documents are shared internally with select users, and 12.9 percent of shared documents are shared with all employees within an organization.

“The most concerning finding is that insider threats, exploited accounts, and data exfiltration collectively account for over 16 security incidents per month at the average organization,” Shah said. “Similarly, the high percentage of organizations that have suffered from such an incident – nearly 90 percent for insider threat alone – shows that these issues are widespread across companies and industries. Companies may not be equipped to differentiate malicious usage from employees’ normal behavior as they get their work done.”

Nathan Eddy

Nathan Eddy

Content Writer

A graduate of Northwestern University's Medill School of Journalism, Nathan was perviously the editor of gaming industry newsletter FierceGameBiz and has written for various consumer and tech publications including Popular Mechanics, Popular Science, CRN, and The Times of London. Currently based in Berlin, he released his first documentary film, The Absent Column, in 2013.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。