home.social

#insiderrisk — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #insiderrisk, aggregated by home.social.

fetched live
  1. Insider threat programs have always been a Fortune 500 luxury. Above Security is changing that—agentic AI investigators, zero config, five-minute deploy. My RSAC Vendor Spotlight:

    paradigmtechnica.com/2026/04/2 #InsiderRisk #AgenticAI

  2. How much do insider security risks cost your company? A new report claims on average it costs firms an astonishing $19.5 million per year! And the figure is going up... because of AI.

    Read more in my article on the Fortra blog: fortra.com/blog/your-staff-are

    #artificialintelligence #insiderrisk #cybersecurity #ai

  3. How much do insider security risks cost your company? A new report claims on average it costs firms an astonishing $19.5 million per year! And the figure is going up... because of AI.

    Read more in my article on the Fortra blog: fortra.com/blog/your-staff-are

    #artificialintelligence #insiderrisk #cybersecurity #ai

  4. Weekly cyber roundup: insiders, incentives, and supply-chain weaknesses are driving breaches more than exploits.

    Arrests are rising - but human risk remains.

    Source: technadu.com/weekly-cybersecur
    Thoughts?

    #InfoSec #InsiderRisk #CyberNews

  5. Coupang’s post-breach response includes large-scale customer compensation and cooperation with law enforcement, following exposure of customer data earlier this year.

    The case highlights challenges around insider access, breach detection delays, and post-incident remediation. While authorities state that only limited data was retained, the scale of initial access underscores the importance of access controls and monitoring.

    Would welcome practitioner insights on mitigation strategies and breach response best practices.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for security-focused coverage.

    #InfoSec #DataBreach #IncidentResponse #InsiderRisk #DataProtection #CyberDefense #PrivacyEngineering

  6. When insider incidents can hit even the most security-focused companies, it forces every organization to reconsider how much “trust” is built into their workflows. Effective insider-threat defense now requires continuous monitoring, tighter access governance, and stronger guardrails around employee privileges—because the risk isn’t theoretical anymore.

    Explore how these attacks unfold and what you can do to reduce exposure on our blog: lmgsecurity.com/betrayed-from-

    Or listen to the podcast: chatcyberside.com/e/when-secur

    #InsiderThreat #Cybersecurity #ZeroTrust #AccessManagement #SecurityOperations #RiskManagement #InsiderRisk

  7. DOJ filings allege that an NSA contractor misused a government workstation for harmful activity involving minors. Monitoring tools reportedly detected the behavior. The contractor’s employment ended after his arrest, and he remains innocent until proven guilty.

    The case prompts renewed discussion on insider-risk models, endpoint monitoring, and oversight in high-trust environments.

    💬 Thoughts on strengthening insider-risk controls without over-surveilling legitimate analysts?

    Source: forbes.com/sites/the-wiretap/2

    Follow @technadu for responsible cybersecurity coverage.

    #CyberSecurity #InsiderRisk #DOJ #NSA #ThreatManagement #InfoSec #Monitoring #TechNadu

  8. 🎉 Epieos arrives in #SiliconValley!

    🇺🇸 This week, Sylvain Hajri, CEO of Epieos, was at eBay’s historic headquarters for the #P3 2025 event organized by Silicon Valley Security Group.

    👮‍♂️ The event gathered #security experts from leading Silicon Valley #companies, as well as renowned #lawenforcement agencies such as:

    🔹 Federal Bureau of Investigation
    🔹 U.S. Department of Homeland Security
    🔹 Northern California Regional Intelligence Center - NCRIC/High Intensity Drug Trafficking Area -HIDTA

    ✅ P3 was a great opportunity for Epieos, and all participating partners, to address #InsiderRisk and #OrganizedRetailCrime (ORC), critical threats that pose significant challenges for organizations around the world.

    🤝 We would like to thank all attendees, partners, and organizers for making this a high-quality event.

    Stay tuned for our latest news and updates by following 👉 Epieos.

  9. Thrilled to announce that Diana Makienko, Head of EMEA Service Management at SWIFT, and Lucile Renhas, Insider Risk Consultant at Signpost Six, will be speaking at #WICCON2024!

    🔐 Don’t miss their talk, "Inside Job: Tackling Insider Risk from All Angles"

    Secure your spot now: wiccon.nl/tickets-2024
    #CyberSecurity #InsiderRisk #WomenInTech

  10. Did you know that 25% of all data breaches are caused by trusted insiders? This case study, based on a true story of corporate espionage, shows how you can reduce insider risk with #Microsoft #Purview:

    Reduce Insider Risk | Microsoft Purview
    info.microsoft.com/ww-thankyou

    #InsiderRisk #MicrosoftPurview

  11. Did you know that 25% of all data breaches are caused by trusted insiders? This case study, based on a true story of corporate espionage, shows how you can reduce insider risk with #Microsoft #Purview:

    Reduce Insider Risk | Microsoft Purview
    info.microsoft.com/ww-thankyou

    #InsiderRisk #MicrosoftPurview

  12. Loose and Work In Progress Thoughts Related to #insiderrisk #insiderthreats in the context of #infosec / #cybersecurity / #risk :

    Insider Threats are not solely an effect of remote work, but the advent of remote work compounds them. There is no turning back to in-office only work, so how can organizations protect themselves from Insider Threats in what has become a larger attack surface?

    Collaboration Tools: A fragmented landscape including multiple cloud tools and services including Google Drive, iCloud, Box, Dropbox, and OneDrive. The problem is not the spirit of collaboration or the tools. It’s the approach to managing sensitive data and having visibility of it. Traditional Information security relies on blocking access. While sometimes effective, locked-down employees are not productive employees. Organizations need collaboration tools to stay ahead, and they also need them to maintain employee satisfaction in a highly competitive labor market.

    The nature of work for digital creatives has fundamentally changed. There is no predictable time intervals when all workers are online or supposed to be online. This makes traditional approaches of static behavior matching obsolete. The rise of cloud collaboration technologies expands the risk surface and makes “expected” behavior more ambiguous than ever. Complete visibility into behavior is now needed across platforms but continues to be centered around the behaviors triggered by an endpoint or workstation.

    Traditional Approaches
    - Blocking: This leads to exceptions and is intrusive for a collaborative culture.
    - Static Ringfencing of Data and Digital Assets is no longer Possible
    - Constant re-org
    - Distributed nature
    - Complexity and Dynamism of Required Access Controls
    - Classification: Can’t keep up with the dynamism of an organization. Requires significant up-front effort for initial classification and ongoing overhead to maintain the state.

    If you are directly or tangentially working on these problems would love to connect and learn more from your experiences in the space.

  13. Loose and Work In Progress Thoughts Related to #insiderrisk #insiderthreats in the context of #infosec / #cybersecurity / #risk :

    Insider Threats are not solely an effect of remote work, but the advent of remote work compounds them. There is no turning back to in-office only work, so how can organizations protect themselves from Insider Threats in what has become a larger attack surface?

    Collaboration Tools: A fragmented landscape including multiple cloud tools and services including Google Drive, iCloud, Box, Dropbox, and OneDrive. The problem is not the spirit of collaboration or the tools. It’s the approach to managing sensitive data and having visibility of it. Traditional Information security relies on blocking access. While sometimes effective, locked-down employees are not productive employees. Organizations need collaboration tools to stay ahead, and they also need them to maintain employee satisfaction in a highly competitive labor market.

    The nature of work for digital creatives has fundamentally changed. There is no predictable time intervals when all workers are online or supposed to be online. This makes traditional approaches of static behavior matching obsolete. The rise of cloud collaboration technologies expands the risk surface and makes “expected” behavior more ambiguous than ever. Complete visibility into behavior is now needed across platforms but continues to be centered around the behaviors triggered by an endpoint or workstation.

    Traditional Approaches
    - Blocking: This leads to exceptions and is intrusive for a collaborative culture.
    - Static Ringfencing of Data and Digital Assets is no longer Possible
    - Constant re-org
    - Distributed nature
    - Complexity and Dynamism of Required Access Controls
    - Classification: Can’t keep up with the dynamism of an organization. Requires significant up-front effort for initial classification and ongoing overhead to maintain the state.

    If you are directly or tangentially working on these problems would love to connect and learn more from your experiences in the space.