THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Luca Fioravanti, Senior Vice President, Group Head of Corporate Security and Resilience, UniCreditThe new working environments have dramatically changed compared to what they were just a few years ago. The fast development of new communication technologies, the need for an organisation to expand their business in new markets to remain competitive and generate profits for their shareholders, and the need for organisations to attract talents globally, introduced new challenges. Those challenges have further increased from the post-COVID-19 pandemic, with employees all around the world preferring remote working to the traditional workplace.
As a result, the attack surface has extended and organization and the insider threat is a raising issue.
In addition, the recent conflict between Russia and Ukraine has seen an increase in nation-state-sponsored attacks, not only using criminal organizations, and offering hacking tools as a service but also leveraging on insiders.
Large organisations, in all industry sectors, nowadays have access to an unprecedented amount of data, which often is the most valuable company’s asset. To be effective and efficient in their business propositions, organisations extensively use third parties, which are now considered strategic partners, and more often offshore offices and processes, to exploit labour arbitrage, in developing countries.
The insider threat is an emerging issue and it comes in many forms, such as data breaches, fraud, sabotage and even terrorist attacks, employees and more in general every authorised individual with access right to a company’s resources can create enormous dam-ages in terms of financial losses, service interruption, reputational damage and even physical harm to the workforce.
“Large organisations, in all industry sectors, nowadays have access to an unprecedented amount of data, which often is the most valuable company’s asset.”
Nowadays, with the evolution of advanced data analytics, artificial intelligence, machine learning and big data, sophisticated mathematical models can be developed to identify and monitor employees’ behaviours to identify anomaly patterns that could represent a threat to the organisation. However, organisations must be mindful of employees’ right to privacy, considering that the boundaries between personal life and work life are often blurred and not well demarked.
Mutual trust between employer and employees is the key to implementing an effective and balanced secure environment, being transparent about the control environment and demonstrating a fair and balanced approach will lead the employees to follow and obey the security policies, while if the control environment is too oppressive the workforce may be distracted and distressed and leave in fear.
The legal aspect is very critical for global organisations which want to implement and roll out employee monitoring programmes across all locations where they have employees or contractors accessing their network and utilising the company’s assets.
Organisations must be aware that the legal considerations for employee monitoring will vary from organisation to organisation and specific issues will arise depending on the nature of the organisation undertaking monitoring and the risks it is trying to mitigate.