Insiders the biggest data security threat
Organisations are ignoring the fact that their biggest threat to data security is from within - and around the mainframe.


Insiders pose the biggest threat to data security, according to a new report published today.
The research, based on a poll of 3,596 IT professionals in the US, UK, France and Germany carried out by the Ponemon Institute, found data breaches by hackers ranked a distant fifth in terms of security threats.
Negligence on the part of insiders was seen by far and away as the most dangerous, where US respondents said 75 percent of all breaches were the fault of insiders compared to hackers, who were responsible for just one per cent. The UK came in a close second with 63 per cent of breaches blamed on those from inside the organisation.
Overall, 63 per cent of respondent said their organisations suffered data breaches caused by negligent insiders and 37 per cent had been caused by malicious insiders.
More than half (55 per cent) of UK IT practitioners reported that their organisation had experienced one or more data breaches involving the loss or theft of information about individuals such as consumer data, customer information, employee records.
But it was when looking at where data breaches occurred that the study uncovered some concerning statistics. It found that 41 per cent of all data breaches occurred in a mainframe environment, as opposed to the removable and mobile media so many of the data breaches that come to public attention are attributed to.
The study said this was most worrying because more than 80 per cent of the world's corporate and governmental data resides on mainframes according to the Computer and Communications Industry Association (CCIA), .
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Atul Bhovan, senior technical consultant at the research sponsor, Compuware told IT PRO that the deterrent just isn't there to stop people waking out of the building with sensitive and confidential data.
"Monitoring is critical as it will provide often absent visibility of who is accessing data and what they are doing with it and serve as an important deterrent against unauthorised data removal or carelessness," he said.
Bhovan added that the biggest enemy in data security is complacency, where all offline data should be encrypted, for instance, but is not. "Many companies lack the experience and guidance to implement a full-proof technology solution to combat data loss," he said. "Companies need to look at how security solutions can be used within their own business to protect information."
A 25-year veteran enterprise technology expert, Miya Knights applies her deep understanding of technology gained through her journalism career to both her role as a consultant and as director at Retail Technology Magazine, which she helped shape over the past 17 years. Miya was educated at Oxford University, earning a master’s degree in English.
Her role as a journalist has seen her write for many of the leading technology publishers in the UK such as ITPro, TechWeekEurope, CIO UK, Computer Weekly, and also a number of national newspapers including The Times, Independent, and Financial Times.
-
Why keeping track of AI assistants can be a tricky business
Column Making the most of AI assistants means understanding what they can do – and what the workforce wants from them
By Stephen Pritchard
-
Nvidia braces for a $5.5 billion hit as tariffs reach the semiconductor industry
News The chipmaker says its H20 chips need a special license as its share price plummets
By Bobby Hellard
-
Tech leaders worry AI innovation is outpacing governance
News Business execs have warned the current rate of AI innovation is outpacing governance practices.
By Emma Woollacott
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro
-
SEC data breach rules branded “worryingly vague” by industry body
News The new rules announced last week leave many questions unanswered, according to security industry experts
By Ross Kelly
-
The gratitude gap
Whitepaper 2023 State of Recognition
By ITPro
-
Meta sues ‘data scraping for hire’ service that collected info on 600k users
News Meta says tackling data scraping will require a “collective effort” from platforms and policymakers
By Ross Kelly
-
Building a data governance strategy in 2023
In-depth Data governance will continue to expand as attitudes change and businesses look to optimise the value of their data
By Keri Allan
-
FCC plans strict overhaul of 15-year-old US data breach regulations
News Telcos could no longer be able to use negligence as a defence for data breaches as the FCC also seeks to hasten public notification of breaches
By Rory Bathgate
-
UK follows EU in securing data deal with South Korea
News The deal will foster cross-border collaboration between businesses by reducing administrative and financial frictions
By Zach Marzouk