1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:04,260
we are going to dive into the world of insider threats.

3
00:00:04,260 --> 00:00:06,120
Insider threats pose a unique

4
00:00:06,120 --> 00:00:08,220
and they are often overlooked.

5
00:00:08,220 --> 00:00:10,290
They refer to the cybersecurity threats

6
00:00:10,290 --> 00:00:13,170
that originate from within an organization.

7
00:00:13,170 --> 00:00:15,420
These insider threats can come from current

8
00:00:15,420 --> 00:00:17,910
or former employees, contractors,

9
00:00:17,910 --> 00:00:20,640
or business associates who have legitimate access

10
00:00:20,640 --> 00:00:23,280
to the organization's systems data.

11
00:00:23,280 --> 00:00:24,810
Unlike external threats,

12
00:00:24,810 --> 00:00:26,910
insider threats have an intimate knowledge

13
00:00:26,910 --> 00:00:28,920
of the organization's infrastructure,

14
00:00:28,920 --> 00:00:31,110
which makes them potentially more damaging

15
00:00:31,110 --> 00:00:32,610
than an external attacker.

16
00:00:32,610 --> 00:00:35,220
For example, if a threat actor is trying to break

17
00:00:35,220 --> 00:00:36,510
into an office building,

18
00:00:36,510 --> 00:00:38,790
but they have never been inside the building before,

19
00:00:38,790 --> 00:00:40,470
it's going to be pretty difficult

20
00:00:40,470 --> 00:00:42,600
since they have no pre-existing knowledge

21
00:00:42,600 --> 00:00:44,430
of the building's security features,

22
00:00:44,430 --> 00:00:46,050
or even the building's layout.

23
00:00:46,050 --> 00:00:47,040
On the other hand,

24
00:00:47,040 --> 00:00:49,890
if you have a disgruntled employee who wants to gain access

25
00:00:49,890 --> 00:00:52,770
to the building, it's pretty easy for them to do so.

26
00:00:52,770 --> 00:00:55,470
They already have an access badge, or access code,

27
00:00:55,470 --> 00:00:57,480
since they work in the building every day

28
00:00:57,480 --> 00:00:59,490
and they know the layout of the building

29
00:00:59,490 --> 00:01:01,320
because they work there every day

30
00:01:01,320 --> 00:01:04,410
and they know the security processes and procedures.

31
00:01:04,410 --> 00:01:06,810
Well, the same thing happens in the digital world

32
00:01:06,810 --> 00:01:10,410
and our trusted insiders can easily become a problem for us

33
00:01:10,410 --> 00:01:12,690
if they switch sides and become an insider threat

34
00:01:12,690 --> 00:01:15,750
to our organizations and our networks.

35
00:01:15,750 --> 00:01:18,750
Insider threats have varying levels of capabilities,

36
00:01:18,750 --> 00:01:22,230
and these are largely determined by the individual's role

37
00:01:22,230 --> 00:01:25,890
and level of access within the targeted organization.

38
00:01:25,890 --> 00:01:26,760
For example,

39
00:01:26,760 --> 00:01:29,550
if an individual has extensive access privileges

40
00:01:29,550 --> 00:01:32,460
because they work as a system administrator for the company,

41
00:01:32,460 --> 00:01:35,010
they could potentially cause significant damage.

42
00:01:35,010 --> 00:01:36,030
On the other hand,

43
00:01:36,030 --> 00:01:38,730
if the individual only has limited access rights

44
00:01:38,730 --> 00:01:39,563
to the system,

45
00:01:39,563 --> 00:01:42,120
they may not be able to cause widespread damage

46
00:01:42,120 --> 00:01:43,860
to the organization's network,

47
00:01:43,860 --> 00:01:45,480
but another factor in determining

48
00:01:45,480 --> 00:01:47,040
the individual's capabilities

49
00:01:47,040 --> 00:01:48,870
is their own level of knowledge.

50
00:01:48,870 --> 00:01:51,240
For example, a skilled attacker who has

51
00:01:51,240 --> 00:01:54,000
a regular user account on the organization's system

52
00:01:54,000 --> 00:01:56,430
because they're working as an unpaid earn intern

53
00:01:56,430 --> 00:01:59,340
or receptionist who causes much or more damage

54
00:01:59,340 --> 00:02:00,300
than an unskilled,

55
00:02:00,300 --> 00:02:03,360
entry-level system administrator on the same system,

56
00:02:03,360 --> 00:02:05,010
even though the system administrator

57
00:02:05,010 --> 00:02:08,160
has higher levels of access by default.

58
00:02:08,160 --> 00:02:09,780
When it comes to insider threats,

59
00:02:09,780 --> 00:02:11,790
you should be aware that insider threats

60
00:02:11,790 --> 00:02:13,560
can take various forms,

61
00:02:13,560 --> 00:02:15,720
including data theft, sabotage,

62
00:02:15,720 --> 00:02:18,240
or the misuse of access privileges.

63
00:02:18,240 --> 00:02:21,690
Insider threats can also help to facilitate external attack,

64
00:02:21,690 --> 00:02:24,150
such as installing malware or creating backdoors

65
00:02:24,150 --> 00:02:27,540
in organization systems based on their motive and intent.

66
00:02:27,540 --> 00:02:31,320
Each insider threat is driven by different motivations.

67
00:02:31,320 --> 00:02:34,080
Some are driven by financial gain and they want to profit

68
00:02:34,080 --> 00:02:37,200
from the sale of sensitive organizational data to others.

69
00:02:37,200 --> 00:02:39,660
Some other threats may be motivated by revenge

70
00:02:39,660 --> 00:02:41,730
and are aiming to harm the organization

71
00:02:41,730 --> 00:02:44,040
due to some kind of perceived wrong levied

72
00:02:44,040 --> 00:02:45,300
against the insider.

73
00:02:45,300 --> 00:02:48,210
For example, a recently fired employee might attempt

74
00:02:48,210 --> 00:02:50,670
to take some of the company's sensitive information

75
00:02:50,670 --> 00:02:52,410
with them on their last day,

76
00:02:52,410 --> 00:02:53,820
and they could publicly leak it

77
00:02:53,820 --> 00:02:57,060
or send it to the organization's other competitors.

78
00:02:57,060 --> 00:02:59,910
In some cases, insider threats may be unintentional

79
00:02:59,910 --> 00:03:02,130
or simply the result of carelessness

80
00:03:02,130 --> 00:03:05,520
or a lack of awareness of cybersecurity best practices

81
00:03:05,520 --> 00:03:08,040
by one of the organization's users.

82
00:03:08,040 --> 00:03:10,050
A common example of this type of insider threat

83
00:03:10,050 --> 00:03:12,810
would be an untrained employee clicking on a link

84
00:03:12,810 --> 00:03:13,980
in a phishing email

85
00:03:13,980 --> 00:03:16,530
and it accidentally allowed access to the workstation

86
00:03:16,530 --> 00:03:17,400
and an turn,

87
00:03:17,400 --> 00:03:19,860
it could potentially compromise the company's network.

88
00:03:19,860 --> 00:03:22,500
One of the most infamous examples of an insider threat

89
00:03:22,500 --> 00:03:25,080
is the infamous case of Edward Snowden,

90
00:03:25,080 --> 00:03:28,050
a former contractor for the US National Security Agency,

91
00:03:28,050 --> 00:03:29,250
or the NSA.

92
00:03:29,250 --> 00:03:31,770
Now, some people believe he was a whistleblower

93
00:03:31,770 --> 00:03:33,690
and a privacy advocate,

94
00:03:33,690 --> 00:03:35,640
but from the perspective of his employer,

95
00:03:35,640 --> 00:03:37,770
the NSA and the US government,

96
00:03:37,770 --> 00:03:40,230
he has been classified as an insider threat.

97
00:03:40,230 --> 00:03:43,830
Back in 2013, Edward Snowden leaked a vast amount

98
00:03:43,830 --> 00:03:46,260
of classified information to the media

99
00:03:46,260 --> 00:03:50,010
to reveal extensive global surveillance programs run

100
00:03:50,010 --> 00:03:54,330
by the National Security Agency that he disagreed with.

101
00:03:54,330 --> 00:03:56,400
His intimate knowledge of these systems

102
00:03:56,400 --> 00:03:58,560
and his access privileges allowed him

103
00:03:58,560 --> 00:04:02,490
to gather a ton of data without the NSA ever detecting it,

104
00:04:02,490 --> 00:04:05,520
and then Snowden was able to leak this information

105
00:04:05,520 --> 00:04:08,580
to bring light to different surveillance programs used

106
00:04:08,580 --> 00:04:09,810
by the NSA.

107
00:04:09,810 --> 00:04:12,000
This really does show how much damage

108
00:04:12,000 --> 00:04:14,670
a trusted insider like Snowden can do

109
00:04:14,670 --> 00:04:17,070
since they already have legitimate access

110
00:04:17,070 --> 00:04:21,029
to the organization, its network, and its data.

111
00:04:21,029 --> 00:04:22,680
After the cleanup of the incident,

112
00:04:22,680 --> 00:04:25,650
the Director of National Intelligence, James Clapper,

113
00:04:25,650 --> 00:04:28,980
described the Snowden disclosures as the most massive

114
00:04:28,980 --> 00:04:32,070
and most damaging theft of intelligence information

115
00:04:32,070 --> 00:04:34,320
in the history of the United States.

116
00:04:34,320 --> 00:04:37,170
It is hard to provide a cost estimate for this incident

117
00:04:37,170 --> 00:04:40,260
since much of the impact revolved around national security,

118
00:04:40,260 --> 00:04:43,380
intelligence capabilities, and diplomatic relations,

119
00:04:43,380 --> 00:04:45,330
but some estimates put the cost

120
00:04:45,330 --> 00:04:48,480
into the billions of dollars, lost capabilities,

121
00:04:48,480 --> 00:04:52,560
and technological advantages against the enemies of the US.

122
00:04:52,560 --> 00:04:54,720
Another example of an insider threat

123
00:04:54,720 --> 00:04:56,880
is the Twitter attack of 2020.

124
00:04:56,880 --> 00:04:57,840
Back in the year,

125
00:04:57,840 --> 00:05:00,450
Twitter fell victim to an attacker who collaborated

126
00:05:00,450 --> 00:05:01,830
with two insider threats

127
00:05:01,830 --> 00:05:03,780
to achieve the goals of this attack.

128
00:05:03,780 --> 00:05:05,730
The young attacker managed to gain access

129
00:05:05,730 --> 00:05:07,920
to several high profile Twitter accounts,

130
00:05:07,920 --> 00:05:10,620
including those of Elon Musk, Barack Obama,

131
00:05:10,620 --> 00:05:13,320
Joe Biden, Bill Gates, among others.

132
00:05:13,320 --> 00:05:15,750
The attacker used this unauthorized access

133
00:05:15,750 --> 00:05:19,680
to launch a Bitcoin scam by attempting to mislead followers

134
00:05:19,680 --> 00:05:21,930
of these influential Twitter accounts.

135
00:05:21,930 --> 00:05:25,470
The attack was a stark reminder of the risks associated

136
00:05:25,470 --> 00:05:28,350
with insider threats and highlights the importance

137
00:05:28,350 --> 00:05:31,260
of robust internal cybersecurity controls,

138
00:05:31,260 --> 00:05:33,240
even in tech savvy organizations

139
00:05:33,240 --> 00:05:36,390
like the formal social media giant, Twitter.

140
00:05:36,390 --> 00:05:38,580
So remember, an insider threat refers

141
00:05:38,580 --> 00:05:40,920
to the potential risk posed by individuals

142
00:05:40,920 --> 00:05:42,930
within an organization who have access

143
00:05:42,930 --> 00:05:45,180
to sensitive information and systems

144
00:05:45,180 --> 00:05:47,160
and who may misuse this access

145
00:05:47,160 --> 00:05:49,710
for malicious or unintended purposes.

146
00:05:49,710 --> 00:05:50,550
To mitigate the risk

147
00:05:50,550 --> 00:05:52,620
of an insider threat being successful,

148
00:05:52,620 --> 00:05:56,160
organizations should implement a zero trust architecture,

149
00:05:56,160 --> 00:05:59,730
employ robust access controls, conduct regular audits,

150
00:05:59,730 --> 00:06:03,963
and provide effective employee security awareness programs.

