CERT
search  



Insider Threat Blog


Recently in Guidance Category

The Common Sense Guide to Mitigating Insider Threats Expanded

Hi, this is George Silowash of the CERT Insider Threat Center. I am happy to announce the release of the Common Sense Guide to Mitigating Insider Threats, 4th Edition. This edition introduces four new best practices for preventing and detecting insider threats and a number of new features.


Continue reading The Common Sense Guide to Mitigating Insider Threats Expanded

"Spotlight On: Insider Threat from Trusted Business Partners" Article Revised and Released

Hello, this is Todd Lewellen of the CERT Insider Threat Center. We are excited to announce that a revised version of our Spotlight On: Insider Threat from Trusted Business Partners article has been released. It has been almost three years since the first version of this article was published. During that time, our collection of insider threat case data has grown significantly. Specifically, we have collected 30 additional cases involving trusted business partners (TBPs) alone, which increased our sample population from 45 to 75 cases. Some of these case examples have been included in the new revision of the article.


Continue reading "Spotlight On: Insider Threat from Trusted Business Partners" Article Revised and Released

Insider Threats Related to Cloud Computing--Installment 10: Conclusion

Hi, this is Bill Claycomb and Alex Nicoll with the final installment of a series on cloud-related insider threats. In this post, we present our conclusion on the current state of cloud-related insider threats and our vision for the future.


Continue reading Insider Threats Related to Cloud Computing--Installment 10: Conclusion

The Insider Threat Awareness Virtual Roundtable Webinar

Hi, this is Dawn Cappelli, Director of the CERT Insider Threat Center. Last week I had the pleasure of participating in The Insider Threat Awareness Virtual Roundtable webinar, which was sponsored by the DHS Office of Infrastructure Protection. The webinar was moderated by Jon Richeson from DHS, and I was joined by the Supervisory Special Agent from the Insider Threat Investigations Unit of the FBI.


Continue reading The Insider Threat Awareness Virtual Roundtable Webinar

Insider Threats Related to Cloud Computing--Installment 9: Two More Proposed Directions for Future Research

Hi, this is Bill Claycomb and Alex Nicoll with installment 9 of a 10-part series on cloud-related insider threats. In this post, we discuss in detail two final areas of future research for cloud-related insider threats: normal user behavior analysis and policy integration.


Continue reading Insider Threats Related to Cloud Computing--Installment 9: Two More Proposed Directions for Future Research

Insider Threats Related to Cloud Computing--Installment 8: Three More Proposed Directions for Future Research in Detail

Hi, this is Bill Claycomb and Alex Nicoll with installment 8 of a 10-part series on cloud-related insider threats. In this post, we discuss three more areas of future research for cloud-related insider threats: identifying cloud-based indicators of insider threats, virtualization and hypervisors, and awareness and reporting.


Continue reading Insider Threats Related to Cloud Computing--Installment 8: Three More Proposed Directions for Future Research in Detail

CERT Insider Threat Center in the News

Hi, this is Dawn Cappelli of the CERT Insider Threat Center. We always feel proud when we see others recognize our hard work and, better yet, communicate the results of our work to others. SC Magazine, FedTech, Information Week, eWeek, and GovInfoSecurity have all published articles about the work that the CERT Insider Threat Center has done. We’ve collected excerpts from each here with a link to the complete article so you can take a look.


Continue reading CERT Insider Threat Center in the News

Study on Insider Cyber Fraud in Financial Services Released

Hi, this is Randy Trzeciak of the CERT Insider Threat Center. Recently, we completed a study that revealed insights into the type of insiders who commit insider financial cyber fraud, how they do it, and what they steal. The study, funded by the U.S. Department of Homeland Security (DHS) Science and Technology Directorate, involved 80 real cases of insider cyber fraud in the financial services sector. We conducted the study working with the U.S. Secret Service, the U.S. Department of the Treasury, and project partners from the U.S. financial services sector.


Continue reading Study on Insider Cyber Fraud in Financial Services Released

Insider Threats Related to Cloud Computing--Installment 6: Securing Against Other Cloud-Related Insiders

Hi, this is Bill Claycomb and Alex Nicoll with installment 6 of a 10-part series on cloud-related insider threats. In this post, we discuss how to secure against two other types of cloud-related insider threats: cloud exploits and those using the cloud against you.


Continue reading Insider Threats Related to Cloud Computing--Installment 6: Securing Against Other Cloud-Related Insiders

Insider Threats Related to Cloud Computing--Installment 5: Securing Against Cloud-Related Insiders

Hi, this is Bill Claycomb and Alex Nicoll with installment 5 of a 10-part series on cloud-related insider threats. In this post, we discuss how to secure against one type of cloud-related insider threat: rogue administrators.


Continue reading Insider Threats Related to Cloud Computing--Installment 5: Securing Against Cloud-Related Insiders