Chief security officers say it's very difficult to protect business-technology systems from trusted employees. "If someone on the inside is brazen enough, there's not much you can do. You've got to trust people," says a security officer at a major financial-services firm.
"Companies aren't spending enough, or doing enough, to protect their systems," says Mark Rasch, former head of the Justice Department's computer crimes unit and senior VP and chief security counsel for security vendor Solutionary Inc. "It's still mostly just talk. The bad news is it's going to take a catastrophic event" to get companies to take security seriously, and Rasch believes that such an event "is going to happen."
And it may be caused by insiders, those who know a company's systems and weaknesses and can inflict serious damage. It takes solid technology, tough policies, and tight control over systems changes to protect a company's electronic assets from malicious employees, security experts say.
"It's a matter of strong change control," says Peter Tippett, vice chairman and chief technologist for security-services company TruSecure Corp. "When it comes to administrators with access to servers, you have to have them watch each other. It should take two administrators present for any changes to the system." All server changes need to be logged to separate systems that the administrators can't access and change, Tippett says. "You start doing that, and they'll know they'll get caught. It's a deterrent."
That advice looks good on paper, says the chief security officer at a consumer-goods manufacturer in New Jersey. "I barely have the staff to keep up on maintenance and patches," he says. "I can't afford to have two administrators at every server for every update."
Still, it might be cheaper than dealing with the damage caused by a disgruntled staffer or former employee. While no company can totally protect its systems, especially from insiders, aggressive policies can cut the risk. "It will still happen from time to time," Tippett says. "But you can greatly reduce the likelihood."More Software Insights
White Papers
Webcasts
Reports
Security and business-technology managers view attacks over the Internet as their greatest threat. For the fifth year in a row, respondents to the Computer Security Institute/FBI Computer Crime and Security Survey cite the Internet as the most frequent point of attack: 74% cite the Internet, while 33% cite internal systems.

![]()
![]()
Duronio is accused of damaging files at UBS PaineWebber with a logic bomb.
![]()
Cirrus Logic seeking Digital IC Design Engr in Austin, TX
Hebrew SeniorLife seeking Senior Network Analyst in Boston, MA
Agilent seeking NPI Project Manager in Shanghai, CN
UC Berkeley seeking Helpdesk Team Lead in Berkeley, CA
Rohm and Haas seeking Product Portfolio Manager in Philadelphia, PA
For more great jobs, career-related news, features and services, please visit our Career Center.
SOA and Web Services - The Performance Paradox
Loosely-coupled service environments provide unique benefits to the organizations that utilize them, while at the same time, they introduce new challenges. See how IT teams - operations, application support, architects and developers - gain control over complex, composite applications upon which so much business depends. Read the white paper.
read more 
NOTE: Offer valid for U.S., U.S. possessions, & Canada only