Show notes
Title - Overcoming Resistance for Insider Threat Change
Intro
Welcome back! This is
episode 40 of The Insider Threat podcast, for the week of July 2nd, 2018.
July 4th and Canada Day
World Cup - I picked Germany. My 9 year old will probably win.
Infosec Trivia Question
It’s time for your
Infosec Trivia Question, where Google is king and the prize is
nonexistent!
The question last episode
was “In 1996, the term ‘phishing’ was introduced in a Usenet group that was focused on America Online. What was the name of this group?”
The answer was
“AOHell”.
There is speculation that the reason phishing starts with “ph” instead of “f” is due to the earlier spelling of phone phreaking, which uses the same spelling substitution. America Online at the time was one-stop-shop for early social engineering exploits.
Congratulations to:
Swen from Lac Au Saumon, Patrick from Virginia, Lola from Santa Fe Springs, and Brodie from Quebec for
getting the correct answer.
Here’s your question
for this episode: “In July of 1953, the first mass-produced computer was announced by IBM. This computer ended up becoming the dominant computer of the decade. What was the model of this computer?”
Send your response to
InfosecAnswer@gmail.com. Be sure to include your first name, location, and the
hashtag “10-digit-memory”.
Discussion Topic for
the Episode
This episode’s discussion
topic is resistance to insider threat program changes and how to overcome them
- Trying to be a hero, but you are running into roadblocks by either management or employees
- Management
– Funding
– Process change
- Employees
– Perceived prod impacts
– Feeling of no trust
- Solution
– Include senior management at the beginning. You can’t ask them to change production processes suddenly and without warning.
– Have open dialog with employees. Explain to them why things are important. That is a very important part of your program, anyway.
News
Tesla
Link - https://www.infosecurity-magazine.com/news/teslas-tough-lesson-on-malicious/
- According to a supposed email from Elon Musk to Tesla employees, someone committed sabotage against the company that included the use of false usernames to make changes to the code used in the Tesla Manufacturing Operation System, as well as “exporting large amounts of highly sensitive Tesla data to unknown third parties.”
- This all supposedly happened because an employee didn’t get the promotion he was going for.
- While this will certainly be used by vendors to sell User and Entity Behavior Analytics, Identity and Access Management, and similar products, we have to remind ourselves that malicious insider threat only really accounts for less than 10% of insider threat incidents.
- I agree though, that those types of tools would go a long way in twarting these types of attacks.
Exactis
Link - http://www.dailymail.co.uk/sciencetech/article-5900071/Marketing-firm-Exactis-leaks-340-million-files-containing-private-data.html
- Whether it is 230 million or 340 million people whose data was left unprotected (sometimes I think they just spit ball these numbers), it is still a very big deal.
- This is bigger than Equifax, and includes home addresses, phone numbers, email addresses and other sensitive information for named individuals. They also record their hobbies, interests and habits, as well as the number, age, and gender of any children they have.
- The data is now secured and the FBI is investigating.
- There is currently no way to see if your data was included or if anyone downloaded a copy.
Links to both of these stories are in the show notes.
Closing Thought
Our closing thought for this episode comes from Elon Musk. He said, “When something is important enough, you do it even if the odds are not in your favor.”
Outro
Thank you for listening to this episode of The Insider Threat podcast. Please remember to subscribe and review in your favorite podcast app, and also share with everyone you know! Those reviews are key to building this out and improving for later episodes, so please feel free to leave suggestions.
You can contact me on twitter @stevehigdon or send an email to steve@theinsiderthreatpodcast.com. Go to our website, www.theinsiderthreatpodcast.com, to find the show notes for this and every other episode, as well as links to the topics we’ve covered. You can also go to the website to find a link to the Patreon page and subscribe to the newsletter to get up-to-date information on current episodes and news for the show. Call and leave a voicemail at (443) 292-2287 to have a conversation, get a comment added to the show, or even ask a question.
Thanks again and I’ll see you folks next time!
Contact information:
Call in number: (443)
292-2287
Email - steve@theinsiderthreatpodcast.com
Blog - http://www.stephenhigdon.com
Twitter - https://twitter.com/stevehigdon
LinkedIn - https://www.linkedin.com/in/stevehigdon-infosec/
Notes
*Title - Overcoming Resistance for Insider Threat Change
*
In this episode we
cover some common issues with implementing insider threat programs and how to deal with them, Tesla and Exactis (should you be worried?) and more. Don’t touch that dial!
Intro
Welcome back! This is
episode 40 of The Insider Threat podcast, for the week of July 2nd, 2018.
July 4th and Canada Day
World Cup - I picked Germany. My 9 year old will probably win.
Infosec Trivia Question
It’s time for your
Infosec Trivia Question, where Google is king and the prize is
nonexistent!
The question last episode
was “In 1996, the term ‘phishing’ was introduced in a Usenet group that was focused on America Online. What was the name of this group?”
The answer was
“AOHell”.
There is speculation that the reason phishing starts with “ph” instead of “f” is due to the earlier spelling of phone phreaking, which uses the same spelling substitution. America Online at the time was one-stop-shop for early social engineering exploits.
Congratulations to:
Swen from Lac Au Saumon, Patrick from Virginia, Lola from Santa Fe Springs, and Brodie from Quebec for
getting the correct answer.
Here’s your question
for this episode: “In July of 1953, the first mass-produced computer was announced by IBM. This computer ended up becoming the dominant computer of the decade. What was the model of this computer?”
Send your response to
InfosecAnswer@gmail.com. Be sure to include your first name, location, and the
hashtag “10-digit-memory”.
Discussion Topic for
the Episode
This episode’s discussion
topic is resistance to insider threat program changes and how to overcome them
- Trying to be a hero, but you are running into roadblocks by either management or employees
- Management
– Funding
– Process change
- Employees
– Perceived prod impacts
– Feeling of no trust
- Solution
– Include senior management at the beginning. You can’t ask them to change production processes suddenly and without warning.
– Have open dialog with employees. Explain to them why things are important. That is a very important part of your program, anyway.
News
Tesla
Link - https://www.infosecurity-magazine.com/news/teslas-tough-lesson-on-malicious/
- According to a supposed email from Elon Musk to Tesla employees, someone committed sabotage against the company that included the use of false usernames to make changes to the code used in the Tesla Manufacturing Operation System, as well as “exporting large amounts of highly sensitive Tesla data to unknown third parties.”
- This all supposedly happened because an employee didn’t get the promotion he was going for.
- While this will certainly be used by vendors to sell User and Entity Behavior Analytics, Identity and Access Management, and similar products, we have to remind ourselves that malicious insider threat only really accounts for less than 10% of insider threat incidents.
- I agree though, that those types of tools would go a long way in twarting these types of attacks.
Exactis
Link - http://www.dailymail.co.uk/sciencetech/article-5900071/Marketing-firm-Exactis-leaks-340-million-files-containing-private-data.html
- Whether it is 230 million or 340 million people whose data was left unprotected (sometimes I think they just spit ball these numbers), it is still a very big deal.
- This is bigger than Equifax, and includes home addresses, phone numbers, email addresses and other sensitive information for named individuals. They also record their hobbies, interests and habits, as well as the number, age, and gender of any children they have.
- The data is now secured and the FBI is investigating.
- There is currently no way to see if your data was included or if anyone downloaded a copy.
Links to both of these stories are in the show notes.
Closing Thought
Our closing thought for this episode comes from Elon Musk. He said, “When something is important enough, you do it even if the odds are not in your favor.”
Outro
Thank you for listening to this episode of The Insider Threat podcast. Please remember to subscribe and review in your favorite podcast app, and also share with everyone you know! Those reviews are key to building this out and improving for later episodes, so please feel free to leave suggestions.
You can contact me on twitter @stevehigdon or send an email to steve@theinsiderthreatpodcast.com. Go to our website, www.theinsiderthreatpodcast.com, to find the show notes for this and every other episode, as well as links to the topics we’ve covered. You can also go to the website to find a link to the Patreon page and subscribe to the newsletter to get up-to-date information on current episodes and news for the show. Call and leave a voicemail at (443) 292-2287 to have a conversation, get a comment added to the show, or even ask a question.
Thanks again and I’ll see you folks next time!
Contact information:
Call in number: (443)
292-2287
Email - steve@theinsiderthreatpodcast.com
Blog - http://www.stephenhigdon.com
Twitter - https://twitter.com/stevehigdon
LinkedIn - https://www.linkedin.com/in/stevehigdon-infosec/