Insider threat actors can be motivated by different factors. I try to summarize possible motivations in the following table, and it is not a complete list.
Also the attackers can gain access to a workstation of an employee through mechanism like phishing, and if there are controls to prevent insider threats, the damage that could be done by this attacker can be minimized.
Threat Agent | motivated by | Possible Motivations | ||
Insider | Government | Patriotism, Blackmail, Financial gain, Legal gain, Psychological manipulation | ||
Insider | Criminal Organization | Blackmail, Financial gain, Psychological manipulation | ||
Insider | Criminal Organization - Criminal Community | Blackmail, Financial gain, reputation on sharing with community | ||
Insider | Criminal Organization - Hacktivist groups | supporting a ideological cause, reputation on sharing with community, guilt/remorse | ||
Insider | Criminal Organization - Terrorists | supporting a ideological cause, reputation in a like-minded community, | ||
Insider | Competitor | Financial gain | ||
Insider | Hacker | Financial gain, Blackmail | ||
Insider | family/friend | Financial gain, helping family/friend from difficult situation | ||
Insider | own-self | revenge, remorse/guilt, financial reward, patriotism, ideological cause, fame | ||
Criminal Organization | Government | Financial gain, blackmail, patriotism | ||
Criminal Organization | Competitor | Financial gain | ||
Hacktivist | Government | Manipulation of facts |
No comments:
Post a Comment