started · updated
CISA releases guide to mitigate insider threats in critical infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an Insider Threat Mitigation Guide to help critical infrastructure owners and operators defend against cyberattacks, data theft, and sabotage.
The guide provides a framework for organizations to establish or enhance mitigation programs, offering best practices and case studies to address evolving technological threats. CISA highlighted the severe economic consequences of insider activity by citing a 2011 case where an American energy technology company lost over $1 billion in shareholder equity and nearly 700 jobs after an employee stole proprietary source code for a foreign competitor.
Scott Breor, acting executive assistant director for infrastructure security, stated that organizations must establish programs to protect key assets, prevent violence, reduce losses, and safeguard sensitive data.
Entities
CISA · Cybersecurity and Infrastructure Security Agency · Scott Breor