Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Oxford study warns of the risk of internal cyber-attacks
  • USA - English


News provided by

University of Oxford

Aug 28, 2014, 08:00 ET

Share this article

Share toX

Share this article

Share toX

Oxford, Oxfordshire (PRWEB UK) 28 August 2014 -- For immediate release: 28 August 2014

Press release

The Danger From Within

Oxford study warns of the increasing risk of internal cyber-attacks

Saïd Business School, University of Oxford

In a new Harvard Business Review article, Professor David Upton of Saïd Business School, and Professor Sadie Creese of Oxford’s Global Cyber Security Capacity Centre warn that internal cyber attacks against companies, are an increasing threat that costs tens of billions of dollars a year worldwide, can destroy companies, and sink the careers of many senior executives. Their study found that while many organisations are intensifying their defences against external attack, these widely used safeguards are often ineffective against attacks involving insiders. Such attacks from insiders, be they from employees, suppliers, or other companies legitimately connected to a company’s computer system, pose a more pernicious threat than external attacks.

Cyber attacks on corporations are on the increase. The 2013 cyber attack on Target, where Russian thieves compromised point of sale information, left the company with a potential loss of $420 million, and affected 70 million customers, made headline news. What is less well known however is that this attack came through an unwitting vendor who had authorised access to Target’s computers, and as such was an insider in their ecosystem.

Over the past two years Professor Upton and Professor Creese have led an international research project whose goal is to provide a significant step change on insider threat prevention and detection so companies can be better protected. The study found that many managers were ignorant of the threat of insider attacks and the risks it posed from fraud, sabotage, intellectual property theft, and corporate terrorism. The key to reducing their vulnerability, they say, is to adopt the same approach companies applied to improve quality and safety at the end of the last decade. They recommend removing the reliance on the IT team and making it everyone’s responsibility to ensure critical assets are protected, proposing five steps that managers should implement immediately to reduce the risks:

1. Adopt a robust insider policy

Introduce a clear and concise policy to address what people must or must not do to deter insiders who introduce risk through carelessness, negligence or mistakes. The rules must apply to all levels of the organisation and employees should be given tools to help them adhere to the policy (such as on-screen warning messages). The policy should regularly be reinforced with information sessions and internal communications campaigns.

2. Raise awareness

Be open about likely threats so staff can detect them, and customise training to take into account the kinds of attacks they might encounter, such as phishing: phony emails which trick staff into sharing personal details or access codes, or downloading malware when a link is clicked. Encourage employees to report unusual or prohibited technologies or behaviour - such as the use of portable hard drives or asking for confidential data files.

3. Look out for threats when hiring

Adopt screening processes and interview techniques designed to weed out potential threats before they become privileged members of staff. Examples include criminal background checks, looking for misrepresentations on resumes, and techniques that assess a candidate’s moral compass. During the interview process managers should also assess cyber-safety awareness.

4. Employ rigorous subcontracting processes

Organisations must ensure that suppliers or distributors don’t put them at risk or create a back door to their systems. It’s therefore imperative that managers seek out partners and suppliers that have the same risk appetite and culture, and audit them regularly to ensure practices are maintained; if necessary screen their employees for criminal records, check candidates employment histories, and monitor access to its data and applications for unauthorised activity.

5. Monitor employees

The researchers recommend using readily available security software to monitor employee activities, such as accessing websites, yielding important information that will help detect danger. Regular risk assessments will identify the source of any threat, vulnerable employees and networks, and the possible consequences if a risk becomes a reality.

‘We have burglar alarms installed to prevent people breaking into our houses,’ said Professor Upton. ‘But it’s the people we let through the door that are the problem. It’s the same for organisations. The principles used to defend against external threats just don’t work with insiders. In recent years businesses have been letting more people into their houses – be it through the use of cloud services, Google drives, employees bringing their own devices to work, or through the proliferation of social media and use of big data. Though these people may have a legitimate access to an organisation’s cyber-assets, the scope for them to exploit this or be exploited is hugely increased.’
‘We found wide-scale global ignorance of the nature of the threat organisations face from internal attack, leaving corporate assets vulnerable, jobs and bonuses insecure, and reputations at risk,’ said Professor Creese. ‘We are now expanding the initial survey of 35 companies to 5,000 which will enable us to develop models to detect threats more accurately, faster and earlier than current solutions, and to help us develop education and awareness materials to help transfer knowledge and management skills to stakeholders.’

Further information about the research can be found here: http://www.cs.ox.ac.uk/projects/CITD/

For further information or to speak with David Upton or Sadie Creese please contact the press office:

Clare Fisher, Head of Public Relations, Saïd Business School
Mobile: +44 (0) 7912 771090; Tel: 01865 288968
Email: clare.fisher(at)sbs.ox(dot)ac.uk

Josie Powell, Press Officer, Saïd Business School
Mobile +44 (0)7711 387215, Tel: +44 (0) 1865 288403
Email: josie.powell(at)sbs.ox(dot)ac.uk

Notes to editors

About the study

Sponsored by the Centre for the Protection of National Infrastructure (CPNI), the study was conducted by an interdisciplinary 16-member team combining computer security specialists, management academics, scientific visualisation experts, psychologists and criminologists. The team included six professors and five researchers across three universities (Oxford, the University of Leicester, and Cardiff University).

About David Upton
http://www.sbs.ox.ac.uk/community/people/david-upton

About Sadie Creese
http://www.oxfordmartin.ox.ac.uk/cybersecurity/people/467

About Saïd Business School

Saïd Business School at the University of Oxford blends the best of new and old. We are a vibrant and innovative business school, but yet deeply embedded in an 800 year old world-class university. We create programmes and ideas that have global impact. We educate people for successful business careers, and as a community seek to tackle world-scale problems. We deliver cutting-edge programmes and ground-breaking research that transform individuals, organisations, business practice, and society. We seek to be a world-class business school community, embedded in a world-class University, tackling world-scale problems.

In the Financial Times European Business School ranking (Dec 2013) Saïd is ranked 12th. It is ranked 14th worldwide in the FT’s combined ranking of Executive Education programmes (May 2014) and 23rd in the world in the FT ranking of MBA programmes (Jan 2014). The MBA is ranked 5th in Businessweek’s full time MBA ranking outside the USA (Nov 2012) and is ranked 5th among the top non-US Business Schools by Forbes magazine (Sep 2013). The Executive MBA is ranked 23rd worldwide in the FT’s ranking of EMBAs (Oct 2013). The Oxford MSc in Financial Economics is ranked 7th in the world in the FT ranking of Masters in Finance programmes (Jun 2014). In the UK university league tables it is ranked first of all UK universities for undergraduate business and management in The Guardian (Jun 2013) and has ranked first in nine of the last ten years in The Times (Sept 2013). For more information, see http://www.sbs.ox.ac.uk/

About the Global Cyber Security Capacity Centre
http://www.oxfordmartin.ox.ac.uk/institutes/cybersecurity

ENDS

Clare Fisher, University of Oxford, +44 1865288879, [email protected]

Modal title

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.