28.3k views
1 vote
insiders who are uneducated on potential security threats or simply bypasses general security procedures to meet workplace efficiency are what category of insider threat?

User Wyj
by
7.9k points

1 Answer

0 votes

Final answer:

Insiders who are not properly educated on security threats or who bypass security procedures for efficiency contribute to inadvertent inside threats, as described by the insider-outsider model. Such negligence can lead to significant security breaches, as evidenced in case studies of financial institutions and high-profile retail breaches like the one experienced by Target in 2013.

Step-by-step explanation:

Insiders who are uneducated on potential security threats or those who bypass general security procedures to meet workplace efficiency fall into a specific category of insider threat connected to the insider-outsider model. This model posits that insiders are employees with knowledge of, and access to, the organization's procedures, while outsiders are generally either new hires or external entities. When insiders neglect security measures or lack security awareness, they inadvertently pose a threat to the organization because they have the means to bypass security measures due to their need for workplace efficiency, yet their actions can lead to vulnerabilities and potential breaches.

An example that illustrates the consequences of such unintentional insider threats is the case of a banking institution in Brazil studied by Bruno & Abrahão (2012), where the volume of decisions made by operators led to a higher rate of false positives in security breach detections. Similarly, security personnel at Target in 2013 received signals of a breach but failed to interpret them correctly, leading to a significant data breach detected later by the FBI. These scenarios underscore the importance of insider threat awareness and training to prevent such occurrences.

User Yuanyuan
by
7.9k points