How much do insider security risks cost your company? A new report claims on average it costs firms an astonishing $19.5 million per year! And the figure is going up... because of AI.

Read more in my article on the Fortra blog: https://www.fortra.com/blog/your-staff-are-your-biggest-security-risk-ai-making-it-worse

#artificialintelligence #insiderrisk #cybersecurity #ai

When one engineer can walk out with thousands of pages of AI trade secrets, you don’t have a “user problem” — you have an insider‑threat problem. Insider‑threat programs must monitor behaviors & risk indicators. #InsiderThreat #InsiderRisk #AISecurity 🔗https://zurl.co/Avvtu

🔎 The Hidden Threat Inside Your Organization
Internal users can cause incidents by mistake or misuse. Limit risk with least-privilege access, monitoring, and security awareness.

#CyberSecurity #SecurityCulture #InsiderRisk #InfosecK2K

Weekly cyber roundup: insiders, incentives, and supply-chain weaknesses are driving breaches more than exploits.

Arrests are rising - but human risk remains.

Source: https://www.technadu.com/weekly-cybersecurity-news-highlighting-incentives-over-exploits-arrests-and-hacker-claims/617427/
Thoughts?

#InfoSec #InsiderRisk #CyberNews

ALPHV affiliates plead guilty — a brutal reminder that in cybercrime, the firefighters are sometimes the arsonists. Insiders, double games, and broken trust sit at the heart of ransomware. ⚖️🔥 #Ransomware #InsiderRisk

https://www.theregister.com/2025/12/31/alphv_ransomware_affiliates_plead_guilty/

Cybersecurity pros admit to moonlighting as ransomware scum

: Pair became ALPHV affiliates to prey on US-based clients

The Register

Coupang’s post-breach response includes large-scale customer compensation and cooperation with law enforcement, following exposure of customer data earlier this year.

The case highlights challenges around insider access, breach detection delays, and post-incident remediation. While authorities state that only limited data was retained, the scale of initial access underscores the importance of access controls and monitoring.

Would welcome practitioner insights on mitigation strategies and breach response best practices.

Source: https://www.bleepingcomputer.com/news/security/coupang-to-split-117-billion-among-337-million-data-breach-victims/

Follow @technadu for security-focused coverage.

#InfoSec #DataBreach #IncidentResponse #InsiderRisk #DataProtection #CyberDefense #PrivacyEngineering

When insider incidents can hit even the most security-focused companies, it forces every organization to reconsider how much “trust” is built into their workflows. Effective insider-threat defense now requires continuous monitoring, tighter access governance, and stronger guardrails around employee privileges—because the risk isn’t theoretical anymore.

Explore how these attacks unfold and what you can do to reduce exposure on our blog: https://www.lmgsecurity.com/betrayed-from-within-the-modern-insider-attack/

Or listen to the podcast: https://www.chatcyberside.com/e/when-security-fails-crowdstrike-insider-leaks-and-the-threat-within/

#InsiderThreat #Cybersecurity #ZeroTrust #AccessManagement #SecurityOperations #RiskManagement #InsiderRisk

DOJ filings allege that an NSA contractor misused a government workstation for harmful activity involving minors. Monitoring tools reportedly detected the behavior. The contractor’s employment ended after his arrest, and he remains innocent until proven guilty.

The case prompts renewed discussion on insider-risk models, endpoint monitoring, and oversight in high-trust environments.

💬 Thoughts on strengthening insider-risk controls without over-surveilling legitimate analysts?

Source: https://www.forbes.com/sites/the-wiretap/2025/11/26/nsa-contractor-groomed-teenage-girls-on-reddit-doj-alleges/

Follow @technadu for responsible cybersecurity coverage.

#CyberSecurity #InsiderRisk #DOJ #NSA #ThreatManagement #InfoSec #Monitoring #TechNadu

🎉 Epieos arrives in #SiliconValley!

🇺🇸 This week, Sylvain Hajri, CEO of Epieos, was at eBay’s historic headquarters for the #P3 2025 event organized by Silicon Valley Security Group.

👮‍♂️ The event gathered #security experts from leading Silicon Valley #companies, as well as renowned #lawenforcement agencies such as:

🔹 Federal Bureau of Investigation
🔹 U.S. Department of Homeland Security
🔹 Northern California Regional Intelligence Center - NCRIC/High Intensity Drug Trafficking Area -HIDTA

✅ P3 was a great opportunity for Epieos, and all participating partners, to address #InsiderRisk and #OrganizedRetailCrime (ORC), critical threats that pose significant challenges for organizations around the world.

🤝 We would like to thank all attendees, partners, and organizers for making this a high-quality event.

Stay tuned for our latest news and updates by following 👉 Epieos.