{"id":47924,"date":"2021-03-24T11:57:45","date_gmt":"2021-03-24T10:57:45","guid":{"rendered":"https:\/\/www.microsoft.com\/en-gb\/industry\/blog\/?p=47924"},"modified":"2021-03-29T10:05:31","modified_gmt":"2021-03-29T09:05:31","slug":"3-ways-to-reduce-insider-risk","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-gb\/industry\/blog\/cross-industry\/2021\/03\/24\/3-ways-to-reduce-insider-risk\/","title":{"rendered":"3 ways to build a strong security culture to reduce insider risk"},"content":{"rendered":"

\"AdultWhen we think about data protection and cybersecurity, organisations traditionally have not considered the security culture of the organisation and the inherent insider risk. Instead, the focus is often aimed at external adversaries. However, insiders often have access to the most sensitive information. These risks can be inadvertent or malicious. Regardless of that, the requirement to have visibility and mitigate the risk as soon as possible has never been higher.<\/p>\n

According to the 2020 Ponemon study, The Cost of Insider Threats<\/a>, the average cost of an insider risk has increased 31 percent since 2018 to about \u00a38.2m per incident. Due to the rise of hybrid working, leaders and IT teams must have visibility over insider risks. Also, employees need to be educated and become security champions to reduce the risk of insider threats.<\/p>\n

Two years ago, a team of Microsoft engineers asked Microsoft\u2019s CISO: \u201cWhat keeps you up at night?\u201d To the surprise of many, the response was not the ever-growing sophistication of external threats. Instead, it was insider threats. Fast forward to March 2021 and Microsoft now has a comprehensive and fully functional UEBA solution. Insider Risk Management helps leaders identify insider risks and mitigate accordingly in Microsoft 365. In addition, it\u2019s important that leaders foster a security culture that empowers employees with the knowledge and the tools to stay secure, no matter where they are.<\/p>\n

What is an insider risk?<\/h2>\n

Firstly, let\u2019s discuss what an insider risk is. It can come in many forms; the scale is vastly widespread. Common insider threats can be:<\/p>\n