event/conference management software - using insider threat … · 2019-09-10 · using insider...
TRANSCRIPT
![Page 1: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/1.jpg)
Using Insider Threat Profiles To Create
More Effective Early Warning Systems
![Page 2: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/2.jpg)
“When someone shows you who they are, believe them the first time”.- Maya Angelou
“You don’t need a weatherman to know which way the wind blows”.- Bob Dylan
![Page 3: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/3.jpg)
The job is not getting easier
![Page 4: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/4.jpg)
Snowden
Nicholson
Manning
Ames
HanssenMontes
Mallory
Lonetree
Pollard
Walker
Madoff
Martin
Regan
Hasan
McVeigh
Alexis
Khazee
Justice
Claiborne
Underwood
Beliveau
Mo
LiewAwwad Robert
Just to name a few…
Cho
Ivins Ramos
El-Batouty
Lubitz
![Page 5: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/5.jpg)
Security Failure
![Page 6: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/6.jpg)
Action
PredispositionCritical Event
GrievanceIdeation
Planning & Preparation
The Insider Threat Kill Chain
![Page 7: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/7.jpg)
The Power of Human Assessment
![Page 8: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/8.jpg)
Self - DestructionSelf - Healing
Predisposition
Personality
![Page 9: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/9.jpg)
Precipitating events = emotional change
![Page 10: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/10.jpg)
Focused, Tailored, and Profile-Based Early Warning System
![Page 11: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/11.jpg)
Focused
![Page 12: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/12.jpg)
Tailored
![Page 13: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/13.jpg)
Profile-based
![Page 14: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/14.jpg)
The Framework13 Steps to a Better Early Warning System
Using a Whole Person, Whole Threat Approach
![Page 15: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/15.jpg)
EnvironmentWithin Your Control
PersonalitySomewhat Outside Your Control
Precipitating EventsOutside Your Control
Tripwires
Early Warning…”and the wisdom to know the difference”
![Page 16: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/16.jpg)
Determine your early warning program goals
![Page 17: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/17.jpg)
Advertise your program
![Page 18: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/18.jpg)
:
Create an empowered stakeholder team
![Page 19: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/19.jpg)
Identify your critical materials, products,data and processes:
![Page 20: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/20.jpg)
Identify everyone who has access to your critical items:Identify everyone who has accessto your critical items
![Page 21: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/21.jpg)
Determine the early warning capability of your partners
![Page 22: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/22.jpg)
Determine your leading vulnerabilities
![Page 23: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/23.jpg)
Determine theInsider Profiles Most Relevant to Your Situation
![Page 24: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/24.jpg)
Understand your insider profiles
![Page 25: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/25.jpg)
Identify your ‘sensors’
![Page 26: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/26.jpg)
Increase the awareness, appreciation and use of profiles and tripwires
![Page 27: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/27.jpg)
Determine how you will respond:
![Page 28: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/28.jpg)
Seek continuous program improvement
![Page 29: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/29.jpg)
InsiderAttackProfiles
SabotageIP/Data Theft
FraudUnintentional
Workplace Violence
![Page 30: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/30.jpg)
Sabotage
Angry, vengeful, vindictive, disengaged, destructive.
Confrontation with management Poor performance reviewFailed promotion effortWorkplace embarrassment Demotion or termination
Testing of security proceduresMisconfiguring products to cause failure
“Accidentally” breaking a critical machineDefacing company website pages
Contaminating a clean roomAltering enterprise software
![Page 31: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/31.jpg)
Comparative Analysis – Applying the WPV Offender Model to Intentional Adulteration
Class Description Potential Motivations
1Criminal Intent, Outsider
Behavioral Health Patient Social Media Fame Seeker Copycat Extortion Economic motivation
2Customer/Client/Truck Driver
My load isn’t ready, you are costing me money
3Current/Former Employee or Contractor
I am upset with a coworker and adulterate to create problems for that person *I am upset with the company and adulterate as retribution and to harm the brand *Youthful stupidityI am not paid enough *
4 Domestic I am upset with a coworker and adulterate to create problems for that person
5 Ideological Radicalized Insider
* - Supported by actual incident in this briefing
![Page 32: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/32.jpg)
The Food Industry as a Case Example
![Page 33: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/33.jpg)
Recent Intentional Adulteration Incidents Which May Have Been Prevented with Trip Wires
![Page 34: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/34.jpg)
IP/Data Theft
Entitled, narcissistic, anti-social, controlling.
Negative financial event Failed promotion effort
Poor performance reviewUnmet career aspirations
Resignation Termination
“Borrowing” office items for home useBringing in unauthorized equipmentAttempting privilege escalationConducing questionable downloadsViolating cyber security policyWorking out of profile hoursUnusual data transfers Stealing inventory
![Page 35: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/35.jpg)
IP/Data Theft Case Study
![Page 36: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/36.jpg)
Living beyond one's meansFacing debt collectionViolating enterprise policyUsing an enterprise server inappropriately Influencing use of a personally known supplierReporting minor fraudulent expensesUsing controlled, non-public information for insider tradingMaintaining unusually close association with a vendorDemonstrating excessive control over financial dutiesExhibiting shrewd or unscrupulous behavior
Insider Fraud Significant additional expenses Negative personal financial event
Unmet career aspirations
Egotistic, entitled, privileged, self-important
![Page 37: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/37.jpg)
Insider Fraud Case Study
![Page 38: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/38.jpg)
Flighty, unfocused, disorganized, scatter-brained, stressed, strained
Unintentional Insider Threat
New personal or professional
distraction
Personal cell phone/computer overuseUnwittingly providing sensitive infoInappropriately discussing sensitive mattersLeaving out sensitive documents or devicesPosting confidential details to social mediaConsistent failure to meet deadlines
![Page 39: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/39.jpg)
Unintentional InsiderCase Study
![Page 40: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/40.jpg)
Aggressive, detached, confrontational, controlling, unremorseful, and strained
Workplace violenceNegative family or relationship event
Emotional outburstsRefusing to work with othersFailure to communicateFailure to work in groupsDifficulty taking criticism Violating boundariesThreatening violencePhysical altercationsReflections of extremist beliefs
![Page 41: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/41.jpg)
Workplace Violence Case StudyPhoto Courtesy of Long Beach Police Department
![Page 42: Event/Conference Management Software - Using Insider Threat … · 2019-09-10 · Using Insider Threat Profiles To Create More Effective Early Warning Systems ... Critical Event Grievance](https://reader034.vdocuments.us/reader034/viewer/2022050110/5f47bce66ab37a6b58789415/html5/thumbnails/42.jpg)
Val LeTellierASIS Defense & Intelligence [email protected]
David NiccoliniTorchStone Global
Frank PisciottaBusiness Protection Specialists
[email protected] Food Defense &
Agriculture Security Council
James SummersASIS Food Defense & Agriculture Security [email protected]
Jeff SiebenASIS IT [email protected]