At a glance
Malicious insiders are people who intentionally harm a business. They can be current or former employees, contractors, or partners who already have legitimate access to systems and data. They may be motivated by revenge, pressure from others, personal beliefs, ego or money.
These insiders can steal or destroy data, install malware, or damage systems and websites. To reduce risk, limit access, inform security, watch for unusual activity, and act quickly if something seems wrong.
What is a malicious insider
A malicious insider can be past or current employees, contractors or other professionals working within your business. They’re often people who have legitimate access to systems and data but use that access to cause deliberate harm.
Malicious insiders can:
- destroy or steal data
- sabotage systems
- steal or sell business trade secrets or intellectual property
- upload or install malware
- damage your business’s brand and reputation through website or social media accounts
- steal removable storage devices (such as USB sticks)
- connect unapproved devices (such as smartphones and tablets) to your network
- transfer sensitive or stolen data to their personal account.
Malicious insiders intentionally work against a company or its people. Their actions are not accidental. There are many reasons an insider can be or become malicious. They may:
- want revenge against a company or person
- have been forced or blackmailed into causing harm
- want to spread specific ideas or opinions
- be motivated by financial gain.
Warning signs of a malicious insider
There are warning signs a staff member may be a malicious insider. They could be:
- accessing information they don’t need
- downloading or copying large amounts of data
- breaking or avoiding security rules
- logging in at unusual times or from unusual locations
- hiding their actions or avoiding questions
- sending sensitive information outside the organisation
- behaving differently to normal
- using their unapproved personal devices or accounts for work.
How to prevent malicious insiders
It’s hard to recover from an insider attack. That’s why prevention is important. Follow our advice to reduce your business’s risk.
Restrict access and permissions
Only give staff access to sensitive information that they need to do their job. Review their access when they change roles. Only use administrator and other privileged accounts when required, not for day-to-day work.
Information and Communication Technology (ICT) staff often have high-level access. They can sometimes bypass security controls and tracking systems. In the Australian Government, these roles are called ’positions of trust‘ and need a security clearance. If your business has ICT staff with this level of access, make sure they’re trustworthy and act with integrity.
Use unique logins
Staff should have their own unique logins for systems. Avoid sharing logins unless there isn’t another option. If sharing is necessary, put controls in place to manage and monitor it.
Deactivate old or unused accounts
Remove or disable network and system access when it’s not needed. This includes when staff leave a business or move to a different role. Any shared passwords the staff member knows should also be changed. For example:
- shared office Wi-Fi password
- alarm codes
- bank account passwords
- remote access details
- shared email accounts
- administrative or privileged user accounts.
Keep a checklist of all systems staff members can access. This makes auditing access and passwords easier to check and action.
Monitor system activity
Many business systems track and record what staff do on a network. Check what your systems can record, especially for high-risk tasks like approving payments. Without unique logins, these records are less useful because you can’t tell who did what.
When buying new software or cloud services, make sure they include good security controls for important actions. Audits can work well if you review audit logs regularly and follow up on anything unusual. Let staff know that systems are monitored so they’re less likely to break the rules.
Keep regular backups
Malicious insiders may find a way to destroy your data, information and systems. You should always keep regular backups of them. Backups should be accessed by trusted staff only. Refer to our small business cyber security handbook for advice about backups.
Use multi-factor authentication and strong passwords
Having a strong password and using multi-factor authentication (MFA) can prevent insiders from accessing other people’s accounts to perform malicious actions. Even if they get hold of a colleague's user ID, having MFA in place can make it more difficult for them.
Refer to our small business cyber security handbook for more advice on passwords and MFA.
Control outbound emails and files
Insiders may try to send data to themselves or upload it online. To reduce this risk, you should:
- use email security tools to detect and block emails containing sensitive information, restricted attachments or flagged words and phrases
- restrict the use of personal email and unapproved cloud services.
Control removable storage devices
One easy way for a malicious insider to steal data is by using a removable device, such as a USB stick. If possible, control who can connect these devices to your network and what devices are allowed.
You can also block other unapproved devices which could be used to store data, such as:
- smartphones
- tablets
- other Bluetooth, Wi-Fi or mobile data devices.
Do pre-employment and background checks
Checking job candidates before you hire them is an important first step. Do pre-employment background checks and make sure the information they provide is correct. Let new staff know that these checks will happen and give them a way to correct any mistakes.
Tips for background checks include:
- confirming their identity using an officially recognised form of identification, such as an Australian state or territory driver licence or an Australian passport
- getting a police check through the relevant state and territory authority if required
- checking referees and previous workplaces.
You can pay a specialist background check provider to carry out these checks. It’s also a good idea to review background checks from time to time to make sure nothing has changed.
Build a positive workplace culture
A positive workplace culture can help reduce insider threats. When a workplace is honest and open, it’s harder for people to act dishonestly. Staff who feel happy, valued and challenged are less likely to harm the organisation.
Working together also helps prevent insider threats. It reduces the chance of people acting alone and lowers opportunities to misuse access.
Supporting staff wellbeing is important. It helps you notice early warning signs if someone’s situation changes in a way that could put them, or the organisation, at risk.
Educate staff on cyber security
Businesses should focus on building cyber security education among staff. Writing down processes and training staff helps everyone understand what’s expected and how the organisation works. Teaching staff about the business and the risks it faces is an important part of this.
Staff should know the importance of:
- choosing and remembering a strong password
- not sharing their password or login details with others
- being responsible for activity that happens under their account or login
- locking their computer or devices when they leave their desk.
Report any illegal activity
Illegal activity by a malicious insider is when someone in a business uses their access to break the law or harm the organisation. It’s important to report any illegal activity to the police as this protects your organisation, your staff and the wider community.
Recovering from an insider attack depends on what they have done. If they damaged your website, installed malware, or disrupted your systems, you may be able to fix these problems using technical solutions.
However, if data has been stolen, it can be hard to recover. If you have systems like unique logins and activity tracking, you or the police may be able to find out who was responsible – but this won’t bring the data back.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.