<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Risk Report &#187; computer abuse and fraud act</title>
	<atom:link href="https://privacyriskreport.com/tag/computer-abuse-and-fraud-act/feed/" rel="self" type="application/rss+xml" />
	<link>https://privacyriskreport.com</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2023 16:49:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat</title>
		<link>https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat</link>
		<comments>https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/#comments</comments>
		<pubDate>Wed, 14 Oct 2015 20:18:31 +0000</pubDate>
		<dc:creator><![CDATA[Todd Rowe]]></dc:creator>
				<category><![CDATA[Protecting Against the Risk]]></category>
		<category><![CDATA[computer abuse and fraud act]]></category>
		<category><![CDATA[corporate]]></category>
		<category><![CDATA[coverage]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cyberliability]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[insurance]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[litigation]]></category>
		<category><![CDATA[malicious insider]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">https://privacyriskreport.com/?p=406</guid>
		<description><![CDATA[<div class="e-mailit_top_toolbox">
<div class="e-mailit_toolbox square size32 " data-emailit-url='https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/' data-emailit-title='New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat'>
<div class="e-mailit_btn_Facebook"></div>
<div class="e-mailit_btn_Twitter"></div>
<div class="e-mailit_btn_Send_via_Email"></div>
<div class="e-mailit_btn_Pinterest"></div>
<div class="e-mailit_btn_LinkedIn"></div>
<div class="e-mailit_btn_EMAILiT"></div>
</div>
</div>
<p>While large cyber attacks and data breaches may get the headlines, a recent study prepared by the Ponemon Institute and Hewlett-Packard and a recent criminal conviction of a Los Angeles Times reporter that disclosed corporate passwords on a hacker website serve... <a class="more-link" href="https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/">Continue Reading &#8594;</a>
<div class="e-mailit_bottom_toolbox">
<div class="e-mailit_toolbox square size32 " data-emailit-url='https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/' data-emailit-title='New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat'>
<div class="e-mailit_btn_Facebook"></div>
<div class="e-mailit_btn_Twitter"></div>
<div class="e-mailit_btn_Send_via_Email"></div>
<div class="e-mailit_btn_Pinterest"></div>
<div class="e-mailit_btn_LinkedIn"></div>
<div class="e-mailit_btn_EMAILiT"></div>
</div>
</div>
<p>The post <a rel="nofollow" href="https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/">New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat</a> appeared first on <a rel="nofollow" href="https://privacyriskreport.com">Privacy Risk Report</a>.</p>
]]></description>
				<content:encoded><![CDATA[<div class="e-mailit_top_toolbox"><div class="e-mailit_toolbox square size32 " data-emailit-url='https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/' data-emailit-title='New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat'>
<div class="e-mailit_btn_Facebook"></div>
<div class="e-mailit_btn_Twitter"></div>
<div class="e-mailit_btn_Send_via_Email"></div>
<div class="e-mailit_btn_Pinterest"></div>
<div class="e-mailit_btn_LinkedIn"></div>
<div class="e-mailit_btn_EMAILiT"></div></div>
</div><p>While large cyber attacks and data breaches may get the headlines, a recent study prepared by the Ponemon Institute and Hewlett-Packard and a recent criminal conviction of a <em>Los Angeles Times</em> reporter that disclosed corporate passwords on a hacker website serve as <a href="https://privacyriskreport.com/insureds-employees-are-often-overlooked-when-insurers-assess-cyber-coverage/" target="_blank">additional reminders</a> that “malicious insiders” still pose the largest security threat to an organization.</p>
<p><strong>Ponemon Institute/Hewlett-Packard Study: Malicious Insiders Can Cause the Most Serious Cyber Incidents</strong></p>
<p>The Ponemon Institute and Hewlett-Packard (HP) published the study, &#8220;<a href="http://www8.hp.com/us/en/software-solutions/ponemon-cyber-security-report/" target="_blank">2015 Cost of Cyber Crime Study: Global</a>,&#8221; which provides insight into the increasing frequency and costs of cyber attacks against governments and businesses around the world. Specifically, the study examines the “economic impact of cyber attacks and observes cost trends over time” and relies on data taken from 252 organizations in seven countries. Most importantly, the study finds that the most costly cyber crimes are caused by &#8220;malicious insiders,&#8221; people from within an organization.</p>
<p>For example, the study found cyber attacks committed by malicious insiders cost the responding organizations, on average, $144,542 to resolve. The costs related to malicious insiders exceeded costs related to denial of service attacks, phishing scams and stolen devices. Further, the study found the time required to resolve issues created by malicious insiders greatly exceeded the time to resolve issues related to other attacks. Specifically, time to resolve issues related to malicious insiders (54 days) exceeded web-based attacks (28 days) and denial of service attacks (19 days). While the threat created by malicious insiders has been understood for some time, this study puts these threats into context when measured against other cybersecurity threats.</p>
<p><strong>Matthew Keys’ Conviction Demonstrates Real World Dangers Associated with Malicious Insiders</strong></p>
<p>The findings in the Ponemon/HP Study related to the malicious insiders threat were further supported when earlier this month a former <em>Los Angeles Times</em> reporter <a href="http://motherboard.vice.com/read/former-reuters-journalist-matthew-keys-found-guilty-of-hacking-faces-25-years" target="_blank">was convicted</a> under the <a href="https://www.fas.org/sgp/crs/misc/97-1025.pdf" target="_blank">Computer Abuse and Fraud Act</a> (CFAA). Matthew Keys was convicted of posting confidential server passwords on a hacker website and urged hackers to “go [expletive] some [expletive] up” on websites maintained by his employer, the Tribune Company. Keys had access to the passwords during his employment. After Keys posted the passwords, a hacker gained access to the <em>Los Angeles Times</em> website and created a fake headline for a story.</p>
<p>While there may be <a href="http://fortune.com/2015/10/12/matthew-keys-hacking/" target="_blank">questions as to whether Keys was properly charged and convicted</a> under the CFAA, another important consideration is the fact that he does not fit the mold of a &#8220;traditional&#8221; hacker. During the criminal trial it became clear that Keys had nothing more than a basic working knowledge of computers and no experience as a “hacktivist.” Costs related to the investigation of the hacks, related vandalism, security issues repairs and lost employee productivity were estimated to be nearly $1 million.</p>
<p><strong>The Greatest Threat Comes from Inside an Organization</strong></p>
<p>The Ponemon/HP Study and Keys’ conviction demonstrate that while large-scale hacks from foreign countries make news, employees continually prove to be the greatest threat to cybersecurity. Monitoring the conduct of employees and former employees continues to be just as important as maintaining cutting-edge technology in order to safeguard data or other valuable information. Further, the difficult question related to the amount of damages Keys actually caused leads into an interesting issue related to cyber insurance.</p>
<p>For example, while Keys’ employer claimed it suffered $1 million in damages, this amount was called into question by Keys because many of the hours logged to fix the damage caused by leaked passwords were attributed to journalists and executives rather than technical staff. This dispute over what costs were justified and attributable to Keys’ conduct illustrates the importance that insurers and insureds have a complete understanding prior to a cyber incident of the costs and damages covered under cyber policies.</p>
<div class="e-mailit_bottom_toolbox"><div class="e-mailit_toolbox square size32 " data-emailit-url='https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/' data-emailit-title='New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat'>
<div class="e-mailit_btn_Facebook"></div>
<div class="e-mailit_btn_Twitter"></div>
<div class="e-mailit_btn_Send_via_Email"></div>
<div class="e-mailit_btn_Pinterest"></div>
<div class="e-mailit_btn_LinkedIn"></div>
<div class="e-mailit_btn_EMAILiT"></div></div>
</div><p>The post <a rel="nofollow" href="https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/">New Study and Recent Criminal Conviction Sheds Light on the &#8220;Malicious Insiders&#8221; Threat</a> appeared first on <a rel="nofollow" href="https://privacyriskreport.com">Privacy Risk Report</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://privacyriskreport.com/new-study-and-recent-criminal-conviction-sheds-light-on-the-malicious-insiders-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
