The Risk Isn’t Always Outside the Building.

When we talk about security risk, we spend a lot of time thinking about external threats. But some of the more difficult cases I’ve dealt with involved people who already had access to the operation.

Employees know how things work. They know the routines, the processes and, sometimes, where the weaknesses are.

The difficult part is that these can also be people who are trusted. Maybe they’ve been with the company for years. Maybe they’re well-liked or considered a great employee. Over time, it becomes easy for normal controls to loosen because nobody sees a reason to question them.

One thing I’ve learned is that trust is not a control.

That doesn’t mean you shouldn’t trust your employees. It means your processes shouldn’t depend on trust to work. Good controls protect the company and the employee. They create accountability, reduce opportunity and make expectations clear.

When I look at a process, I’m less interested in whether we trust the people involved and more interested in what would happen if someone decided to take advantage of it.

Could they? If the answer is yes, that’s the problem I want to fix.

Consider This

Look at one process in your organization that relies heavily on trust and ask: If someone decided to take advantage of this process, could they?

If the answer is yes, the next question is whether you're relying on trust where you should be relying on a control.

Previous
Previous

The Security You Can’t See