DOL Is Now Concerned About Internal Breaches: Should You Be Concerned?

The U.S. Department of Labor (DOL) recently updated its cybersecurity guidance to cover all Employee Retirement Income Security Act (ERISA) employee benefit plans. https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/compliance-assistance-release-2024-01

One concern is disgruntled employees. Disgruntled employees pose a significant cybersecurity risk as they may misuse their access to company systems. According to the Verizon 2022 Data Breach Investigations Report, internal threats account for 20 percent of security threats.

Common motivations from internal threats (which would include employees and former employees) include revenge, financial gain, or dissatisfaction with the organization. https://www.plansponsor.com/insider-threats-are-disgruntled-employees-a-cybersecurity-risk/ (Oct. 01, 2024).

Commentary

The DOL's concern is that a disgruntled employee would abuse their access to take personal identifiers from ERISA plan participants.

However, other risks include employees accessing employee records, including health, payroll, and financial records.

Quoting from the above cited source:

… certain employees, such as those in human resources, information technology or treasury, may have access to plan information or other personally identifiable information.

Executive, managers, and anyone with access to employee records also pose a potential risk.

Steps organizations can take to prevent internal threats are regular audits and employing advanced monitoring tools to detect suspicious activities early.

Additional steps to consider include:

  • Limit access
  • Control access
  • Monitor employee behavior
  • Cut-off credentials prior to a termination or layoff
  • Foster a positive work environment
Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Trinity Malware Has Healthcare And Feds On The Edge

A new ransomware emerges, targeting healthcare organizations. We provide the information you need.

Re-Evaluating Hot Pursuits: When Are They Necessary?

Data regarding hot pursuits is leading to questions about effectiveness. How do you balance community safety and driving accidents? We examine.

Are Your Employees Following Your Return-To-Work Policies? You Make The Call

A survey claims many employees are ignoring return-to-work policies. What about yours? You make the call and join the conversation.

Common Pulse Exam Leads To $300 Million In Damages For Sexual Abuse

Patients sue a hospital and a doctor for sexual abuse. His defense is that he performed a common pulse exam. We discuss the risk.

Rash Of Executive Kidnappings Leads To Government Intervention

Reports indicate a series of kidnappings targeting foreign executives in the Philippines. Facts suggest one group that follows a deadly pattern. We explore and provide prevention steps.