Researcher says internal security breaches pose a bigger threat than hackers

August 3, 2009

(PhysOrg.com) -- Periodic news accounts about computer hacking and deployment of worms and viruses strike fear in companies that now conduct much of their business online. But an Iowa State University information security researcher says their real fear should be corporate espionage.

"What our studies -- and many others by my colleagues in the field of information security -- have suggested is that internal computer fraud is a more significant issue than external hacking," said Qing Hu, a professor and chair of logistics, operations and management information systems at Iowa State. "External hacking gets headlines, but internal fraud -- employees actually altering data or stealing secrets and sending them to other companies -- is more prevalent than it is reported.

"The unfortunate thing is that companies don't want to report these types of things," he said. "It's only when you talk to individual companies that the manager will sometimes admit, 'Yes, we do have to discipline certain employees because they access commercial secrets that they weren't supposed to, and we had to fire some people because they sold some of our commercial secrets -- from product designs to marketing plans to pricing information -- to other companies.'"

Hu has spoken with such managers for research he's conducted on corporate information security management and user behavior toward protective technologies. Those studies -- which were part of a sponsored research program by the U.S. Department of Defense from 2005-07 -- were published within the last two years in information system journals. They took a different approach to addressing the security problem.

"When I look at a security issue, I do not focus on the technology," said Hu, who is a Microsoft Certified Systems Engineer and Solution Developer. "Information security technology is abundant -- hardware, software, etc. -- and organizations have invested millions of dollars purchasing that technology and installing it on their systems. But still, we hear horror stories about T.J. Maxx's system being broken into, 45 million credit card numbers being stolen, or something happening to this company or that company. So why do those things keep happening while we have invested so much money in terms of buying the security hardware and software?"

Hu contends it's because company employees aren't often educated well enough on information security policies and procedures. His research specifically examined how individual factors and an organization's culture affect its information security management effectiveness.

"The purpose of doing this research is first, to provide a better understanding of human behavior in organizations in the context of information security," Hu said. "Second, it's to provide some practical guidelines to businesses that say, 'OK, if you consider security to be a big issue, not only do you need to install the most sophisticated software and hardware, you also need to educate and set up those programs for employees -- and then enforce them.' So you have to have those processes in place to encourage good behavior and inhibit the potential bad behavior."

Hu is currently working with colleagues in the U.S., China and Finland on multiple research projects based on criminology theories and large-scale international surveys. The studies are designed to identify the individual factors -- such as moral beliefs and self-control -- that may affect a person's propensity to commit information security-related crimes.

"We want to understand why certain employees are more inclined to do bad things, while others are not," he said. "In the criminology research, there is a spectrum of theories and perspectives that explain why certain people are so inclined to commit crime, while others can inhibit that urge. So what I want to do in the immediate future is to explain that as it pertains to information security."

He hopes to have results from those surveys within the year. Hu also plans to collaborate with researchers from Iowa State's criminology and criminal justice program on future studies.

Provided by Iowa State University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3.5 /5 (2 votes)


August 3, 2009 all stories

Comments: 0

3.5 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Managing computer fraud
    created May 23, 2008 | popularity not rated yet | comments 0
  • Cisco CEO to use 'holistic' security
    created Feb 17, 2006 | popularity not rated yet | comments 0
  • New research seeks to enhance quality and security of wireless telemedicine
    created Sep 17, 2007 | popularity not rated yet | comments 0
  • Wake-up call to business: Tighten up on information security
    created Jun 30, 2008 | popularity not rated yet | comments 0
  • Cyber attacks, losses on rise worldwide
    created Sep 13, 2005 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Sixth sense technology
    created 19 hours ago
  • kindle e-reader and scientific papers
    created Nov 24, 2009
  • Help with a camera choice
    created Nov 18, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • Changing the language options on your phone.
    created Nov 03, 2009
  • More from Physics Forums - Computing & Technology

Other News

McKinnon, accused of hacking into US military and NASA computers, faces extradition to the United States

UFO-obsessed Briton loses bid to block US extradition

Technology / Other

created 1hour ago | popularity not rated yet | comments 0

A Briton accused of hacking into US military and NASA computers faces extradition to the United States after the British government Thursday rejected last-ditch requests to block the move.


Building real security with virtual worlds

Technology / Computer Sciences

created 5 hours ago | popularity 3 / 5 (2) | comments 0

(PhysOrg.com) -- Advances in computerized modeling and prediction of group behavior, together with improvements in video game graphics, are making possible virtual worlds in which defense analysts can explore and predict ...


A worman works on a computer

Half of Euro online travel purchases legally unsafe: EU

Technology / Internet

created 2 hours ago | popularity not rated yet | comments 0

More than half of all people who buy flights, hotel rooms and hire cars online risk being left without compensation if companies fail under outdated law, the EU said Thursday.


Roku adds more 'channels' of video and other digital content

Technology / Telecom

created 5 hours ago | popularity not rated yet | comments 0

Owners of Roku's digital video player will soon have a bunch more channels to choose from.


Should I buy a PC or Mac?

Technology / Software

created 22 hours ago | popularity 3.7 / 5 (7) | comments 13

Q. Our 6-year-old PC computer is dying a slow death and we are considering moving to a new iMac but have a few concerns. First, of all, we have several Word documents on our disk drive now that we want to keep and add to ...