Insider threats – detection and mitigation challenges
Detecting an insider threat is like finding a needle in a haystack. The data generated about all the employees working for an organization is enormous. This data could be about the activities they perform and activities that are permitted or not permitted. Also, there could be situations where an activity is suspicious for one employee but legitimate for another. Scanning through all this data to find insider threats is no easy task. But the UBA app helps you meet this challenge. The other two significant challenges that crop up while working on insider threats are as follows:
- Consolidating multiple identities of the same employee
We know that in an organization, we have hundreds of assets that may require a user to create multiple identities. For example, a user, Bob, may have an intranet ID, an ID for accessing Linux servers in a lab, a cloud account for accessing AWS, another cloud account for accessing...