Visibility is key to tackling insider threat and data breaches

There’s a lot of weight given to external threats that cause data breaches and not enough to the insider threats which is a very real…

Share this article:

Visibility is key to tackling insider threat and data breaches

Sudhakar Ramakrishna, CEO of Pulse Secure

There’s a lot of weight given to external threats that cause data breaches and not enough to the insider threats which is a very real issue. Whether it’s a disgruntled employee, a malicious employee, an opportunistic employee, or even an employee under pressure from a criminal organisation, the data breach will have the same consequences for the organisation – fines to pay and a bad reputation to overcome.

One of the reasons cyber breaches dominate the headlines is because the hackers release what they’ve stolen onto the black market or hacker groups release statements about their achievements. In short, they get the column inches because we know it’s happened. With insider threats, whether they are malicious or not, we often simply don’t ever find out about them. As a result, they don’t get talked about as much and they’re perceived, wrongly, as a lesser or at least a less frequently successful threat but insider threats are very real – you only have to look at the recent Mossack Fonseca breach to understand the risk.

Visibility is key to tackling insider threat and data breaches
Sudhakar Ramakrishna, CEO of Pulse Secure
So how can organisations protect against insider threats?
The first thing that organisations need to understand is that it’s not just full time employees that can get access to the network – it’s also contractors and guests. It’s completely normal for a visitor to request and expect access to your Wi-Fi network while contractors will have even more access. Any one of these can represent an insider threat. The second thing organisations should consider is what these people are accessing on the network and from where. BYOD and remote working is now the norm within most businesses so organisations have to secure their data while allowing access to it from various different locations and from an array of devices with different operating systems.
Then, organisations need to implement policies and technology solutions that clearly define and regulate network access for employees, contractors and guests whilst taking into consideration where and what devices they may be logging in from – a Network Access Control (NAC) solution is what’s required.

Organisations should be looking for NAC solutions that can detect the user, role, device, location, time, network and application and enforce very granular access policies and of course, trigger an alarm if any unusual behaviour is detected. A solution that can take all these factors into account can ultimately red flag an insider threat in action and prevent the unauthorised network, application, or data access before the insider’s device connects to the enterprise network via VPN or Wi-Fi. Not only does this protect the corporate network from the insider threat, it also protects the network from infected devices even if they were not infected maliciously. It also ensures only authorised workers have access to the different enterprise resources they need to complete their job. And of course solutions that capture who was logged in to what part of the network and what they’ve tried to access is incredibly useful intelligence to have during and after a breach.

NAC solutions also need to be compliant, easy-to-use and to easy-to-deploy, scalable and adaptable, and ideally be vendor agnostic.

Choosing a NAC solution that adheres to the toughest government standards with FIPS 140-2 compliance and a Common Criteria assurance level of EAL3+ will future-proof your technology. It’s also important to find a solution that employees don’t find cumbersome or difficult to use; the result will be unhappy and unproductive workers. Scalability and adaptability should also be considerations because work styles evolve and new technologies are always emerging. Solutions that are vendor-agnostic will often be easier to deploy and manage in the short and long term as they will be compatible with existing systems and technologies.

Finally, a NAC solution with one central management console will give end-to-end visibility of who is accessing data, from which device and from what location. We are a long way off preventing every single data breach but this kind of visibility is exactly the type of help an IT security team needs to win the war and protect their organisation against data breaches.

[su_button url=”https://www.pulsesecure.net/” target=”blank” background=”#df2027″ color=”#ffffff” size=”10″ radius=”0″ icon=”icon: arrow-circle-right”]For more information on Pulse Secure click here[/su_button]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top