Combatting the Insider Threat

Combatting the Insider Threat

Combatting the Insider Threat

Additionally, DHS should continue to bolster systems that detect the behavioral red flags preceding a malicious cyberattack. Agencies can share information about anomalous behaviors with employees, as employees who work alongside an insider may be in the best position to recognize unusual behavior. DHS currently recognizes a more systematic approach: behavioral methodologies that establish normal use trends (i.e., baselines) of employee cyber activity and evaluate new cyber activity against these trends. When cyber activity deviates from the baseline, this system identifies employees who may be in the process of going rogue.

According to a majority of Federal information technology (IT) professionals, accidental insiders are the greatest IT security threat to their agencies. Lax environments and poor data protection protocols enable employees to accidentally open doors to otherwise secure cyber systems. Online training can emphasize the potential for social media activity to unintentionally leak information, and in-person training helps employees integrate cybersecurity measures into the context of DHS’s larger culture of vigilance. Performing regular audits and effectively managing new-hire background investigations can also reduce the risk of potential accidental insider threats.

Given the dual identity – malicious and accidental – of the insider threat, successfully combatting this risk demands a nuanced approach that balances the need to enhance cybersecurity with the need to promote information sharing and efficiency among Government personnel.

Insider threats are a serious cybersecurity risk to the Federal Government. According to Verizon’s 2013 Data Breach Investigations Report, insider threats, which can be malicious or accidental, comprise at least 14% of confirmed data breaches. Each type of insider threat requires a unique solution.

Malicious insiders intentionally abuse their privileged access to execute cyberattacks. Currently, the  Department of Homeland Security (DHS) restricts employee and contractor access only to the sensitive data required for their roles to limit avenues for malicious insiders. Still, the Government must continue to enhance systems that monitor, review, and roll back unnecessary access. These ongoing reviews should prioritize manager-level personnel, who, according to the 2015 Insider Threat Spotlight Report, are the highest risk cohort due to the large volumes of sensitive data they can access.

Contributors

Aaron Bishop |

Aaron Bishop is a Senior Associate at Arc Aspicio. A transplant from the environmental consulting sector, Aaron focuses on the intersection of organizational design and human potential. He graduated Magna Cum Laude from the College of William and Mary with a B.S. in English and Environmental Policy.

Confessions of a Chief Strategy Officer

Confessions of a Chief Strategy Officer

I’ll admit it, I was a little smug. After more than 20 years in the consulting business helping clients develop, implement, and integrate their strategies, I thought… “how hard could it be to do the same things for my own company – a company of consultants?” I had the commitment of my leadership, a group of talented people, and a plan and resources to grow the company. We had energy and we had a great process and tools to successful. What could go wrong?

Exploring Trends in Strategic Workforce Planning (Attract, Engage, and Retain)

Exploring Trends in Strategic Workforce Planning (Attract, Engage, and Retain)

Federal agencies have been undergoing significant transformation, requiring effective workforce strategies that can assist them in facing increasing challenges. As government leaders look for and implement initiatives to improve performance, Strategic Workforce Planning, (SWP) has become instrumental in assisting organizations to focus on their most important resource: their people

#Innovate Your Heart Out: We See an Innovation Day in Your Future

#Innovate Your Heart Out: We See an Innovation Day in Your Future

Innovation is difficult to harness for organizations of all sizes (Government and private sector alike). Replicating a process to encourage and produce innovation is even more challenging. Innovating in a structured space and time seems counter-intuitive, and begs the question: can thinking outside the box be a structured activity? Arc Aspicio recently held an Innovation Day to answer this question.

A Unified Brand Helps Serve a Complex Mission

A Unified Brand Helps Serve a Complex Mission

The Department of Homeland Security (DHS), created in 2003, undertook the most significant reorganization of federal agencies since the Cold War. It brought together federal, state, local, tribal, and territorial agencies with a focus on securing the U.S. from threats in a collaborative way. DHS pulls together five complex mission areas: preventing terrorism and enhancing security; managing our borders; administering immigration laws; securing cyberspace; and ensuring disaster resilience.

Towards Preparedness and an Emergency Management Workforce of the Future

Towards Preparedness and an Emergency Management Workforce of the Future

Grit and determination. This is what the Federal Emergency Management Agency (FEMA) workforce is known for. After what is arguably the most challenging year in its history, the FEMA leadership called on the agency to enable the workforce through four elements: build, empower, sustain, and train. A key factor in creating a scalable, sustainable disaster response workforce is to foster a proactive culture, one focused on preparedness. A proactive mindset can create an environment that asks the “what if” questions that lead to more prepared response efforts.

Achieving Strategy Breakthroughs by Enabling the Operational Workforce

Achieving Strategy Breakthroughs by Enabling the Operational Workforce

Are you developing a strategy but are unsure where to start, what to rely on, and who to engage when driving a business, organization, or agency forward? Start by enabling the operational workforce. The workforce includes those who are executing daily tasks and operations of the many programs within an organization. Enabling the workforce gives them authority, allowing them to access their full potential to achieve desired results, and helps the Government develop, communicate, and implement strategy.

Greater Washington Innovation Awards Selects Arc Aspicio as Nominee in Professional Services Category

Greater Washington Innovation Awards Selects Arc Aspicio as Nominee in Professional Services Category

Arlington VA, March 14, 2018 — The Greater Washington Innovation Awards chose Arc Aspicio to participate in their showcase as a nominee for the Professional Services Innovator of the Year Award. This prestigious event gave Arc Aspicio employees the opportunity to present their innovative methods for solving the Federal Government’s most complex challenges.