"Insider threats" are typically the one group that any security firm can actually do anything about in an active manner. Every other threat group comes at you, not the other way around.
"Insider threats" are typically the one group that any security firm can actually do anything about in an active manner. Every other threat group comes at you, not the other way around.
That's the whole point behind phishing attacks against corporate employees. Back in the day of windows auto-playing CDs and USB files, dropping random official looking drives around the parking lot was a thing: https://www.wired.com/2011/06/the-dropped-drive-hack/
Then you get into data exfiltration by employees who were bribed, etc.
Having paid attention to cyber security over the past decade, this tracks.
Frankly, the thought of "Actively Coming At" infosec threats is personally appalling.
Feelings aside, you couldn't "actively" "come at" APT actors from the future with unknown techniques, and the way to "actively come at", so to speak, entire categories of "cyber threats" would be to fund detailed white box security testing on your IoT devices or VoIP handsets, for example.
Much cheaper to oppress your workforce. At least that will shorten the checklist. Worst case scenario, you can catch the next wave of offshoring if you push it too far and they unionize.
https://learn.microsoft.com/en-us/purview/insider-risk-manag...