Friday, 21 September 2012

one down

A short follow up to the blog about Jessica Harper http://geraintw.blogspot.co.uk/2012/08/insider-threat.html who was convicted of £2.4m fraud against Lloyds Bank who she worked for as head of anti-fraud.

She has now been sentenced to 5 years in jail for the committing fraud and has so-far repaid £709,000, Harper had told investigating officers she deserved the money because she was rising at 5.30am and returning home at 8pm. In mitigation, Carol Hawley, defending Harper, said her client had a long history of charity fundraising.

It is one corrupt banker down, but how many other insiders are they siphoning off data and funds from their employers. Combating the insider threat can be done by the use of controls

Technical controls focus on data and computer activities, while nontechnical controls focus on human motivations and behaviour. Nontechnical controls are critical because many insider attacks do not depend on technology.

  • Job rotation,
  • segregation of duties, 
  • mandatory vacations, 
  • regular audits/reviews, 
  • periodic employee background checks

Technical solutions

  • Data loss protection (DLP) systems
  • Fraud detection tools 
  • Security information and event management (SIEM) solutions


No comments:

Post a Comment