Ask the Expert

For many companies, the focus on cybersecurity is external hackers and external breaches. How important is it for banks to monitor internal risks, too, and what are some ways you’ve heard of their doing so?

As appeared in the Cleveland Fed Digest's Ask the Expert

As technology continues to enable insider threats—concentrating access to sensitive information and critical processes such as customer information databases, an entity’s proprietary information, and more—monitoring insider risk is extremely important. If appropriate controls are not in place, it’s easy for individuals to move information outside of a company. Cyber criminals understand the value of insider knowledge and attempt to collude with or take advantage of insiders—or are insiders themselves. Information technology professionals account for half of all insider issues.

Companies mitigate these risks by training employees to identify phishing and by taking other precautions such as employing the “least privilege concept,” whereby employees have access to only the information they need to do their jobs. Employee behavioral analysis is newer. It utilizes specialized software to look for patterns in how employees are conducting work, for example, where they are working and/or whether they’re moving abnormal volumes of files. Similarly, data loss prevention strategies include software that monitors email to help detect and prevent employees’ sharing confidential information.

