Home / News, Views and Opinion / Risks from ex-employees greater than from hackers, says cyber chief

Risks from ex-employees greater than from hackers, says cyber chief

The danger of data loss is greatest in times of business uncertainty and sets out what should be done after jobs are lost. Ben Large reports

TalkTalk today formally went into administration shortly before the announcement of a rescue bid by BT, but the collapse of the country’s fourth largest broadband provider has raised serious concerns about national security. TalkTalk is said to provide telecoms services to the Ministry of Defence and other government bodies.

Any business going through this kind of uncertainty should ask who still has access to key systems, and what are they doing with it.

“There are a wide range of controls companies can put in place to mitigate the risks of data breaches from employees,” says Large.

“However, history shows us that it is at times of volatility and change with increased stress and pressures on the workforce that lead to accidental, or more deliberate, breaches in security.”

The risk is well documented. In 2014 an internal auditor at Morrisons, bearing a grudge after a disciplinary, leaked the payroll details of almost 100,000 colleagues. He was jailed for eight years and the case went to the Supreme Court in 2020.

In the US, an IT administrator fired from a medical centre in 2017 got back into its network four days later using administrator credentials, deleting user accounts and a file server and locking staff out of patient records.

Ben Large added: “Staff who are worried about their future, facing redundancy or preparing to leave the business, may still have access to sensitive systems, customer data, and intellectual property.

“Organisations facing financial problems, restructuring, or insolvency are particularly vulnerable to malicious insider activity and data breaches caused by such disengaged employees.”

In such circumstances, Large outlines the top five actions companies should take to mitigate insider threats:

  1. Create a clear response plan for staff breaches: When an employee breaks a security protocol or triggers an alert, the business should have a defined process for investigating the incident, limiting any damage, and involving governance, legal, or HR teams where appropriate.
  2. Use behaviour analytics to spot unusual activity: Behaviour analytics can identify when employees access unfamiliar systems, work in unexpected ways, or display activity that differs from their normal patterns.
  3. Build a security-aware workplace culture: Employees form a vital human firewall, so regular training should help them recognise phishing attempts, handle sensitive data safely, report concerns promptly, and understand the risks of entering company information into public AI tools.
  4. Monitor how sensitive data is being moved: Businesses need visibility of downloads, USB transfers, personal email use, and uploads to cloud storage.
  5. Control access throughout the employee lifecycle: Apply the principle of least privilege so people can access only the systems they need and use a robust joiners, movers, and leavers process to remove every account promptly when someone changes role or leaves.
Ben Large, Head of Cyber Security, Cybit

Ben Large concluded: “As ever, prevention is better than cure. Companies need to treat this kind of risk as a board-level responsibility, ensuring sophisticated, AI-powered analytics software is in place to detect suspicious employee behaviour.

“This is not about Big Brother; it is about taking sensible, practical steps to protect vital company assets from a well-known, if uncomfortable, source of threat.”

Ben Large is Head of Cyber Security at technology solutions provider Cybit.

Check Also

Why smarter machine control can unlock efficiency gains beyond hardware upgrades

Increasingly, manufacturers must improve productivity while minimising operating costs and energy consumption. Therefore, many focus …

Contactless communication solution for development of safer, more reliable batteries

Dukosi announces the availability of DK-NFLNK contactless communication solution for development of safer, more reliable …

CCUS continues to attract bulk of investments from energy sector

Carbon capture, utilisation and storage (CCUS) adoption remains uneven across sectors, with current capacity concentrated …