Insider threat actors can be motivated by different factors. I try to summarize possible motivations in the following table, and it is not a complete list.
Also the attackers can gain access to a workstation of an employee through mechanism like phishing, and if there are controls to prevent insider threats, the damage that could be done by this attacker can be minimized.
| Threat Agent | motivated by | Possible Motivations | ||
| Insider | Government | Patriotism, Blackmail, Financial gain, Legal gain, Psychological manipulation | ||
| Insider | Criminal Organization | Blackmail, Financial gain, Psychological manipulation | ||
| Insider | Criminal Organization - Criminal Community | Blackmail, Financial gain, reputation on sharing with community | ||
| Insider | Criminal Organization - Hacktivist groups | supporting a ideological cause, reputation on sharing with community, guilt/remorse | ||
| Insider | Criminal Organization - Terrorists | supporting a ideological cause, reputation in a like-minded community, | ||
| Insider | Competitor | Financial gain | ||
| Insider | Hacker | Financial gain, Blackmail | ||
| Insider | family/friend | Financial gain, helping family/friend from difficult situation | ||
| Insider | own-self | revenge, remorse/guilt, financial reward, patriotism, ideological cause, fame | ||
| Criminal Organization | Government | Financial gain, blackmail, patriotism | ||
| Criminal Organization | Competitor | Financial gain | ||
| Hacktivist | Government | Manipulation of facts |
No comments:
Post a Comment