Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Protecting Intellectual Property From Insider Threat.

The Importance of Securing Sensitive Data

by The Gurus
November 1, 2019
in Featured, Opinions & Analysis
surveillance camera, Flag
Share on FacebookShare on Twitter

By Josh Lefkowitz, CEO, Flashpoint

The topic of intellectual property (IP) protection is getting the much-needed attention it deserves on the global stage. Due largely to the U.S. administration’s line on trade negotiations with China, the issue of counterfeit products and international IP theft by state-sponsored actors has risen to the fore. Recent estimates suggest economic espionage in the form of IP theft by Chinese actors costs the U.S. economy up to a staggering $600 billion. While the impact of the U.S. ultimatum to the Chinese government on IP theft has yet to be seen, this previously below-the-radar issue is now gaining long-overdue recognition.

Intellectual property – a critical business risk

A company’s IP is estimated to represent as much as 70% of its market value. Ideas and innovations are what make an organisation unique and competitive, yet businesses have often struggled to properly value their IP. A recent study found that, despite 80% of organisations citing cyber liability and IP theft as a serious business risk, only 16% of IP assets at risk of cybercrime are adequately insured. The report also found that 28% of organisations have experienced a material IP event in the past two years.

Unfortunately, the value of IP is often only understood once it has been stolen and commercialised. When copycat products start appearing, or unique features pop up in competitor designs, the loss becomes apparent. By that point, the damage has been done, and recourse is limited to patent infringement courts. So, what can businesses do to protect IP assets, quickly identify when theft has occurred, and reduce the risk of exploitation?

Motivations for insider IP theft

A key vulnerability for businesses defending their IP is company employees. When tracking the history of an IP breach, we often find that the door was unlocked by someone on the inside. With privileged access to critical systems and information, employees are trusted with corporate secrets that, for some, prove too much of a temptation. There are many scenarios:

Employees with a grievance against their employer bid to punish them by sharing sensitive information for personal profit. Another scenario might see an employee tempted by a high salary position with a competitor in return for stealing corporate secrets prior to leaving their current role. This is the alleged situation with Tesla and Xiaopeng Motors where a former Tesla employee is accused of stealing 300,000 files of the company’s self-driving source code from the car maker by using his personal iCloud account attached to the corporate network, before leaving to take up a role with the Chinese firm.

Employees don’t always deliberately reveal secrets; they can simply be targets of malicious activity themselves. They may be recruited by bad actors using an apparently legitimate front, such an invitation to an overseas academic conference, and manipulated into divulging trade secrets.

Compromised employees are vulnerable to threats of blackmail from actors who have either uncovered compromising information or have manipulated them into actions that they fear being made public. These employees steal company data to prevent their own secrets from being revealed.

Finally, we see bad actors take roles within target organisations with the sole aim of accessing and exfiltrating trade secrets.

Managing insider IP theft threat

Managing and mitigating the risk of IP theft is a complex, multi-layered activity that needs broad reach to be effective across the different kinds of insider threat. It’s also a multi-disciplinary undertaking that should incorporate HR and IT, but have visibility at board level, too.

User access management (UAM) is an important element that restricts employees to accessing only the data and systems that are relevant to their role. Combined with user behaviour analytics (UBA), this can pick up unexpected access attempts and spot a potential theft— perhaps by an unhappy or compromised employee—before it takes place.

From an HR perspective, policies about data access and management should be regularly reinforced and companies should also seriously consider controlling access to public data-sharing sites from within the corporate network. HR departments should be alert to the risks around employees leaving the company, working with IT to ensure that permissions are revoked and analysing activity prior to the exit date to identify any unusual data movements or actions. Bear in mind that many employees believe they have ownership of the projects and data that they’ve worked on, and the temptation to take it with them can be strong.

Organisations also need to be aware of high-risk dates on the corporate calendar. These include the development and launch of new products, when stolen IP is likely to command a premium price. Overseas visits by senior personnel should also trigger a higher level of vigilance, and staff should be advised how to protect their devices and be aware of being manipulated.

Swift detection to mitigate impact

Such is the market for stolen IP that, even in the most vigilant organisations, breaches happen. Detecting them as quickly as possible is critical in limiting their impact. A valid way to do this is by looking at the onward journey of stolen IP. If its theft has been motivated by greed, the IP may potentially be offered for sale to the underground community. Monitoring these illicit online communities for references to the organisation can help detect the theft. This practice, however, requires access to such communities and is not something the average IT team should be expected to undertake. Instead, companies should consider using business risk intelligence to underpin their insider threat programme.

A prior incident shows how this works: Flashpoint analysts identified a post on an elite cybercrime forum offering the sale of source code from unreleased software owned by a multinational technology company. Analysis subsequently determined the actor was a company employee. This intelligence enabled the company to safeguard the source code and terminate the rogue employee.

Attempted sales of stolen IP are not the only use case for business risk intelligence. It can also pick up chatter that indicates bad actors are planning to target a company or expose prospective employees’ links to undesirable organisations.

IP theft stifles innovation and legitimate competition, damaging companies and economies on an enormous scale. As companies begin to better recognise the value that IP represents, they need to gain greater insight into who is aiming to steal their IP and how. By combining this with a robust insider threat programme, companies can do a better job of protecting their most valuable assets.

ShareTweet
Previous Post

ASCO production halted by ransomware attack.

Next Post

UK Businesses Waste Two And A Half Months A Year Due To Poor Password Management.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol