event/conference management software - using insider threat … · 2019-09-10 · using insider...

42
Using Insider Threat Profiles To Create More Effective Early Warning Systems

Upload: others

Post on 14-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Using Insider Threat Profiles To Create

More Effective Early Warning Systems

Page 2: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

“When someone shows you who they are, believe them the first time”.- Maya Angelou

“You don’t need a weatherman to know which way the wind blows”.- Bob Dylan

Page 3: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

The job is not getting easier

Page 4: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Snowden

Nicholson

Manning

Ames

HanssenMontes

Mallory

Lonetree

Pollard

Walker

Madoff

Martin

Regan

Hasan

McVeigh

Alexis

Khazee

Justice

Claiborne

Underwood

Beliveau

Mo

LiewAwwad Robert

Just to name a few…

Cho

Ivins Ramos

El-Batouty

Lubitz

Page 5: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Security Failure

Page 6: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Action

PredispositionCritical Event

GrievanceIdeation

Planning & Preparation

The Insider Threat Kill Chain

Page 7: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

The Power of Human Assessment

Page 8: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Self - DestructionSelf - Healing

Predisposition

Personality

Page 9: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Precipitating events = emotional change

Page 10: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Focused, Tailored, and Profile-Based Early Warning System

Page 11: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Focused

Page 12: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Tailored

Page 13: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Profile-based

Page 14: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

The Framework13 Steps to a Better Early Warning System

Using a Whole Person, Whole Threat Approach

Page 15: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

EnvironmentWithin Your Control

PersonalitySomewhat Outside Your Control

Precipitating EventsOutside Your Control

Tripwires

Early Warning…”and the wisdom to know the difference”

Page 16: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Determine your early warning program goals

Page 17: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Advertise your program

Page 18: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

:

Create an empowered stakeholder team

Page 19: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Identify your critical materials, products,data and processes:

Page 20: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Identify everyone who has access to your critical items:Identify everyone who has accessto your critical items

Page 21: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Determine the early warning capability of your partners

Page 22: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Determine your leading vulnerabilities

Page 23: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Determine theInsider Profiles Most Relevant to Your Situation

Page 24: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Understand your insider profiles

Page 25: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Identify your ‘sensors’

Page 26: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Increase the awareness, appreciation and use of profiles and tripwires

Page 27: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Determine how you will respond:

Page 28: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Seek continuous program improvement

Page 29: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

InsiderAttackProfiles

SabotageIP/Data Theft

FraudUnintentional

Workplace Violence

Page 30: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Sabotage

Angry, vengeful, vindictive, disengaged, destructive.

Confrontation with management Poor performance reviewFailed promotion effortWorkplace embarrassment Demotion or termination

Testing of security proceduresMisconfiguring products to cause failure

“Accidentally” breaking a critical machineDefacing company website pages

Contaminating a clean roomAltering enterprise software

Page 31: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Comparative Analysis – Applying the WPV Offender Model to Intentional Adulteration

Class Description Potential Motivations

1Criminal Intent, Outsider

Behavioral Health Patient Social Media Fame Seeker Copycat Extortion Economic motivation

2Customer/Client/Truck Driver

My load isn’t ready, you are costing me money

3Current/Former Employee or Contractor

I am upset with a coworker and adulterate to create problems for that person *I am upset with the company and adulterate as retribution and to harm the brand *Youthful stupidityI am not paid enough *

4 Domestic I am upset with a coworker and adulterate to create problems for that person

5 Ideological Radicalized Insider

* - Supported by actual incident in this briefing

Page 32: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

The Food Industry as a Case Example

Page 33: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Recent Intentional Adulteration Incidents Which May Have Been Prevented with Trip Wires

Page 34: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

IP/Data Theft

Entitled, narcissistic, anti-social, controlling.

Negative financial event Failed promotion effort

Poor performance reviewUnmet career aspirations

Resignation Termination

“Borrowing” office items for home useBringing in unauthorized equipmentAttempting privilege escalationConducing questionable downloadsViolating cyber security policyWorking out of profile hoursUnusual data transfers Stealing inventory

Page 35: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

IP/Data Theft Case Study

Page 36: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Living beyond one's meansFacing debt collectionViolating enterprise policyUsing an enterprise server inappropriately Influencing use of a personally known supplierReporting minor fraudulent expensesUsing controlled, non-public information for insider tradingMaintaining unusually close association with a vendorDemonstrating excessive control over financial dutiesExhibiting shrewd or unscrupulous behavior

Insider Fraud Significant additional expenses Negative personal financial event

Unmet career aspirations

Egotistic, entitled, privileged, self-important

Page 37: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Insider Fraud Case Study

Page 38: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Flighty, unfocused, disorganized, scatter-brained, stressed, strained

Unintentional Insider Threat

New personal or professional

distraction

Personal cell phone/computer overuseUnwittingly providing sensitive infoInappropriately discussing sensitive mattersLeaving out sensitive documents or devicesPosting confidential details to social mediaConsistent failure to meet deadlines

Page 39: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Unintentional InsiderCase Study

Page 40: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Aggressive, detached, confrontational, controlling, unremorseful, and strained

Workplace violenceNegative family or relationship event

Emotional outburstsRefusing to work with othersFailure to communicateFailure to work in groupsDifficulty taking criticism Violating boundariesThreatening violencePhysical altercationsReflections of extremist beliefs

Page 41: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Workplace Violence Case StudyPhoto Courtesy of Long Beach Police Department

Page 42: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance

Val LeTellierASIS Defense & Intelligence [email protected]

David NiccoliniTorchStone Global

[email protected]

Frank PisciottaBusiness Protection Specialists

[email protected] Food Defense &

Agriculture Security Council

James SummersASIS Food Defense & Agriculture Security [email protected]

Jeff SiebenASIS IT [email protected]