Insider Threat in Cyber Security: What the Organizational Psychology Literature on Counterproductive Work Behavior Can and Cannot (Yet) Tell Us
Reeshad Sam Dalal, Aiva K. Gorab · 2016
Data from surveys and case studies of cyber security attacks-such as the one in the foregoing example-demonstrate that insider attacks pose a major risk in both government and private industry (Greitzer & Hohimer, 2011). According to a U.S. Department of Defense, Office of the Inspector General (1997) report, 87 percent of all identified intruders into Department of Defense information systems were internal to the organization (i.e., employees or other individuals with access to the organization, such as contractors). In a similar vein, in his 2014 Worldwide Threat Assessment report to the Senate Select Committee on Intelligence, the Director of National Intelligence, James Clapper (2014), stated that “[t]rusted insiders with the intent to do harm. …will continue to pose a critical threat” (p. 3). Based on yearly Cybersecurity Watch Survey responses from government and private sector firms, CSO Magazine (2011-14) reported that although insider attacks made up a minority (22 percent to 49 percent) of all cyber attacks overall, the insider attacks were often more damaging than attacks from external sources. In general, the deleterious impact of insider threat is grave and includes (but is not limited to) the following: damage to organizational or national reputation, financial loss, disruption of operations, decrease in competitive edge, and harm to individuals. Better understanding of the insider threat phenomenon is hindered by the failure to detect (let alone solve) many insider attacks as well as targeted firms’ attempts to underreport insider attacks and handle them internally in an attempt to reduce negative reputational impact to the organization (Sarkar, 2010, p. 115; Shaw, Ruby & Post, 1998).