Cyberattacks are relentless and increasing. I don’t even know if that’s even necessary to say anymore; you’d need to be living under a rock not to have heard about at least one breach over the past few years.
It would appear that we are helpless to prevent, much less counter, attacks when they occur. While pondering this dilemma, I’ve observed some facts and trends I feel are worthy of consideration.
Insider threat practitioners are constantly challenged to identify and counter these attacks. In order to succeed, we must develop programs that have what I refer to as the “three As”:
- Advocacy by senior executives.
- Authority invested in a single organization.
- Agility to cross any and all internal boundaries to identify and counter threats wherever they are found to exist.
Today I would like to address being
agile
when countering threats.
Plan effectively and change decisively
German military strategist Helmuth von Moltke the Elder famously stated, “No battle plan survives contact with the enemy.” The actual quote is a bit more military, but the vernacular version of it works here. The fact that this sentiment is seen, in various forms, throughout history is testament to its veracity — even the most comprehensive plans will go awry when they meet with any resistance or opposition.
Famous Chinese military strategist Sun Tzu went a step further when confronting this problem when he wrote, “Those who are victorious plan effectively and change decisively.” In essence, he is saying that planning and agility have equal importance in war. And, let’s face it, we’re at war with the people who would steal or sabotage our data.
The first step in planning for any contingency is defining the threat and the target. In our world, most of us have begun this process by defining what an insider threat actually is. The same is true for our colleagues who deal more directly with external threats — they’ve spent time defining words like “hacker” and “threat-actor.”
This is a great start, but too many of us fail to realize that the only people who care about our definitions are us. Attackers don’t care one bit what we call them. When a hacker (external threat) gains access to our systems and data, don’t they then become an insider by our very own definitions? If we fail to react to a situation because our definitions are in the way, we will inevitably fail to successfully respond to threats to our systems and information.
In other words, if we assiduously stick to a non-agile plan, we will not survive.
Get out of your own way
Cementing definitions and plans, then creating a rigid bureaucracy to support them, is the same thing as purchasing a “tool” to solve cyber problems. Tools provide information, but they do so without context. Bureaucracy creates a framework that can very easily become bloated and an obstruction where agility and alacrity are necessary.
Look at what happened to the Office of Personnel Management. OPM calls it a cyber intrusion, others call it a breach, while others call it a hack. What is significant to me is that the culprits were
inside
OPM’s network for at least a year.
There were many failures, including lack of encryption, poor IT security, poor leadership, lack of budget … the list goes on. Since the attackers were on the inside for so long, was this also an insider threat? The short answer is, “It doesn’t matter.” The culprits don’t care what we call it, because they got what they wanted and OPM proved that it was incapable of following Sun Tzu’s enjoinder to be agile when battle was joined.
Definitions and planning must begin with agility because where the threats go, so must any organization be ready to counter. As protectors of our organizations’ information, we must be ready and empowered to cross any boundary, process, function or internal organization without hesitation or blockage. We must be as agile as the foe or we will not survive. We must create an organization that is able to sort through any relevant data, putting it into perspective of defending and countering threats to the target.
Creating agility within structure
Agility is not intended to be a boundless concept, but it must be sufficient to allow the insider threat team to properly respond to threats to the organization. At the risk of sounding immodest, I’d like to quote from a white paper I wrote with my colleague, Mr. Kevin Frank, titled A Holistic Approach to Countering Insider Threats:
[U]nless the insider threat team has agility to combat the ever-changing threat environment, it will not succeed. The organization must be flexible in identifying and following threats wherever they reside. By creating an agile environment, organizations can be creative in combating ever-changing and persistent threats.
To achieve this agility, an organization must create supporting policies and grant authority to one organization that can cross any internal boundaries required to counter discovered threats. Adversaries don’t respect internal policies or organizational charts, so the insider threat program must be similarly unconstrained. When a threat moves across the organization in search of its targets of interest, so the insider threat team must be able to quickly and responsibly follow to take appropriate action.
Combined with the right technology, policies and procedures, agility at an institutional level gives organizations a real chance at effectively responding to threats to their critical information assets. With the added support and advocacy of the organization’s senior leadership, a truly holistic and agile program is a very real possibility. A successfully implemented
agile
insider threat program, I would say, is an essential component given today’s alarmingly risky reality.
Keith Lowry is Nuix’s senior vice president for business threat intelligence and analysis. He served as chief of staff to the deputy undersecretary of Defense for human intelligence, counterintelligence and security at the Pentagon, and as an information security consultant in the private sector.




