Introduction to the Special Issue on Insider Threats
Digital Threats Research and Practice · 2021
Introduction to the Special Issue on Insider ThreatsOne of humanity's most perplexing and persistent security risks is the threat of harm from those we trust.Various descriptions and definitions of this insider threat have been offered.The US Cybersecurity & Infrastructure Security Agency (CISA) defines insider threat as "the threat that an insider will use his or her authorized access, wittingly or unwittingly, to do harm to the Department's mission, resources, personnel, facilities, information, equipment, networks, or systems."The CERT National Insider Threat Center defines it as "the potential for an individual who has or had authorized access to an organization's assets to use their access, either maliciously or unintentionally, to act in a way that could negatively affect the organization."The various definitions differ slightly in specifying who an insider is, what actions are of concern, and why the individual took those actions.To some extent, the functional definition of insider threat may be unique to a particular context, such as with respect to the organization's mission, or focusing on a particular type of crime.Simply stated, we can describe the insider threat most generally as "the risk of misuse of trust to cause harm."This removes qualifications about who is the insider and what trust was violated through what means.Encompassed within this broad definition is the current or former employee, trusted business partner, or even a piece of poorly written or exploited software or a malfunctioning server; this description also acknowledges the insider threat risk posed by a regular customer with access to a company web portal.Most importantly, this definition of insider threat focuses on trust in people and in systems and includes impacts such as physical damage to assets, reputational harm, financial loss, and injuries to people.As Zimmer, Burkert and Federrath point out in their article, "Insiders Dissected-New Foundations and a Systematisation of the Research on Insiders," in order to establish a rigorous, functional definition of insider threat, it is necessary to more clearly specify the nature of insiders.Their article addresses this need by systematically breaking down the concept of insider, with a careful discussion of defining characteristics of insiders and the relationships among these constructs.The resultant taxonomy of insiders represents a major contribution that may be applied to further inform not only the definition of insider threat used in research and practice, but also to inform and facilitate a more systematic representation of insiders in current insider threat knowledge bases, taxonomies, and ontologies.Research on detection, deterrence, and mitigation of insider threat risk generally falls into several focus areas.The first area focuses on the "who" and "what."That is, identifying the entities that have access to an organization, and what assets they have access to.A second area focuses more on the question of "why?"This includes social and behavioral science research that explores the motivations and underlying psychological aspects of insiders.A third focus area considers "how" insiders attack, including the mechanisms, capabilities, and pathways insiders might utilize in an effort to cause harm, and how an organization can mitigate and minimize those opportunities.While each focus area is interesting on its own, very exciting results emerge when the three areas overlap.For example, consider the differences in how a behavioral scientist and a computer scientist might approach the insider threat problem.With the behavioral scientist's interest on individual