A survey of 200 federal IT managers and decision makers showed data breaches due to careless and untrained insiders is the top cybersecurity concern, but that is not reflected in their spending. External threats still get the lion’s share of investment.
The perceived threat from careless or untrained insiders — employees or contractors with access — was a major cause of concern for 53 percent of respondents to a survey conducted by SolarWinds and Market Connections. The figure is up from 42 percent at the same time last year and the leading threat identified in the 2015 survey.
Threats from the “general hacking community” (46 percent) and foreign governments (38 percent) weren’t far behind.
Survey Results: Federal Cybersecurity Report
“Pointing to hackers, terrorists or foreign governments as the top threats to our government’s security seems obvious, especially given the hype that surrounds huge corporate hacks and acts of terrorism,” said Chris LaPoint, group vice president of product management at SolarWinds. “Even intentional insider security breaches such as Edward Snowden’s raise valid concerns and demand prevention investment. But who could imagine that their own colleagues could accidentally cause security breaches with comparable impact to those executed with malicious intent?”
Interestingly, the threat posed by malicious insiders was only a concern for 23 percent of those polled, less than half or those worried about accidental insider leaks.
“Data loss can easily become data stolen,” LaPoint said. “And agencies that ignore these accidental insider threats may well be doing so to their own detriment.”
“We have positioned ourselves relatively strongly against external threats but it is the accidental or malicious insider threat which has caused us more problems,” a director of operations for the Defense Contract Management Agency said. “People do what they want to do and there are so many people — particularly younger — who view security as interference and also have some skills to successfully work around security protocols.”

Chart shows concern over a specific threat does not necessarily lead to more spending to combat that threat.
Photo Credit: SolarWinds
Budget constraints were cited as the most significant obstacle to cybersecurity at 29 percent. However, that number is down from 40 percent at the same time last year.
(The complexity of an agency’s network environment and competing priorities were the next biggest obstacles, at 17 percent and 13 percent, respectively.)
While concern over budgets dropped some, investments in malicious and accidental insider threats continue to lag behind spending on external threats. According to the survey, nearly half of agencies maintained the same investment level for insider threat mitigation over the last two years.
During that same time, 69 percent said their agency somewhat or significantly increased spending on external threats.
“Contrasting the prevalence of insider IT security threats against a general lack of threat prevention resources and inconsistently enforced security policies, federal IT pros absolutely must gain visibility into insider actions to keep their agencies protected,” LaPoint said.
Despite concerns and budget pressures, an overwhelming percentage of respondents said they were “somewhat” or “very” confident in their agency’s security policy, including external threats and malicious and accidental insider issues.

Despite concerns, most respondents reported confidence in their agency’s security policy.
Photo Credit: SolarWinds




