Story image

Singapore, Aus employees admit to snooping around corporate networks

24 Oct 17

Employees in Singapore, Australia and across the globe are increasingly snooping their employer’s networks to deliberately seek information they are not permitted to access – and almost half of employees admit to doing so.

A new report from One Identity revealed that 94% of Singapore respondents said that employees in their organization try to access information that is not necessary for their day-to-day work, and 16% said it happens frequently.

When the employees themselves were asked, 47% of Singapore employees admit to looking for or accessing information about their company’s performance - information that is not required to do their job.

In Australia, 83% of respondents say their employees try to seek information and 65% of employees admit they have searched for or accessed information they did not need.

“Even though the majority of threats Australian organisations face due to their own employees tend to not be of malicious intent, the research shows a large amount of intrusive examining of information from employees when the data is outside of their responsibility. In reality, it could be that bit of intrusive meddling that puts organisations in a dilemma,” comments Richard Cookes, country manager ANZ, One Identity.

“Without proper authority of access permissions and rights, employees have a free-for-all to move about the business and access sensitive information such as financial performance data, confidential customer documents, or an executive’s personal files. If that valuable information ends up in the wrong hands, corporate data loss, customer data exposure or compliance violations are possible risks facing organisations that could result in irreversible damage to the business’s reputation or financial standing. The concern this should highlight is that organisations are very open to social engineering attacks where someone might join a company legitimately to attack it from within verses an external frontal assault. This makes protection of privileged access systems and applications from within even more important.”

IT executives are the most likely culprits by level: Globally, 71% of executives admit to seeking information, compared to 56% of non-manager-level IT security team members. Only 17% of non-manager team members admit to seeking information.

Smaller companies are also prone to bigger snoops: 38% of IT security professionals at companies with 500-2000 employees admit to snooping. At larger organisations, 29% of respondents admit to the deed.

“The alarming results of our study prove that employees in Singapore have a free reign to access sensitive information including financial performance data, confidential customer documentation, or even CEO’s personal files. Meddling with confidential information, even if it is non-malicious in intent, could lead to a serious damage to the business’s reputation and financial standing,” comments Lennie Tan, VP & GM of One Identity, Asia Pacific & Japan.

Globally, those who work for technology companies are more likely to search for information (44%), compared to 36% in financial services and 21% in healthcare.

“Businesses across the Asia Pacific region need to realize that potential cyber threats are not only coming from the outside of their organization,” Tan concludes.

How your enterprise backup solution could fail
Even the best-trained employees are prone to error, and unfortunately, sometimes those errors affect enterprise backups.
Xinja can now officially call itself a bank
The ‘neo’bank that is focused on being a digital disruptor to traditional financial institutions has received a restricted banking license from APRA.
Exclusive: Three access management learnings from 2018
There was a renewed global response to data security in 2018, placing pressure on organisations to assume more responsibility for the data they hold.
How businesses will pivot AI strategies to align with human-centric goals
AI will not only allow businesses to reduce costs but will also provide ROI to the staff working with the technology. 
HubSpot announces fund for 'customer first' startups
HubSpot is pouring US$30 million (NZ$40 million) into a new fund to support startups that demonstrate ‘customer first’ approach of not only growing bigger, but growing better.
Mac malware on WatchGuard’s top ten list for first time
The report is based on data from active WatchGuard Firebox unified threat management appliances and covers the major malware campaigns.
Using blockchain to drive transparency across the supply chain
"With blockchain, it’s likely we’ll see an increase in trust between organisations that work together through the supply chain."
Why businesses are struggling to reach digital maturity
Approximately 65% of respondents identified that they have yet to reach 'expert' status in their digital transformation maturity.