Persistent Insider Threats in Corporate Espionage
Companies and organizations face a multitude of different threats from insiders regarding the theft of intellectual property, trade secrets, and proprietary information. Expanding the thought process on how people evaluate and hunt insider threats is integral to stopping corporate espionage—whether a one-time event or a more insidious possibility.
Entrepreneurial Corporate Spies
When people think about the insider threats to critical information, they tend to focus much of their attention on the high-profile cases where an actor has stolen a large quantity of material and then sold it to a competitor, provided it to the media, or to hacktivists. However, the threat posed by a company’s information walking out the door, even a one-time theft of information as an employee leaves a company, is a serious problem.
While accurate figures on intellectual property theft are hard to obtain for obvious reasons, studies suggest that a significant percentage of employees take sensitive information with them when they leave a job, whether they resign or their employment is terminated. In some cases, the information taken by the employee is information they created and feel entitled to, despite any agreements they may have signed. In other cases, it is important/valuable information that another employee created.
Some of the employees who steal corporate information are “entrepreneurial,” that is, they take the information with the intent to peddle it to a competitor. In this way, they are similar to a “walk-in” case in traditional espionage, where a would-be spy steals information and then approaches a foreign intelligence agency. Others may be recruited by a competitor and steal information on their way out the door at the behest of their new bosses.
One-Hit Wonders are not Optimal
These advancements in drone technology have had incredible implications for war fighters, but they also have security implications that reach outside of active war zones. However, it is important to note that while drones are now more plentiful and easier to acquire than ever, munitions availability will continue to constrain the deadliness of FPV drones. FPV drones are only as lethal as the weapons they carry, and outside of war zones like Ukraine, it remains difficult to obtain destructive items like RPG warheads and military-grade high explosives.
As evidenced by many failed or thwarted bombing plots in the West in recent years, threat actors have struggled to obtain or synthesize explosives. As a result, we have witnessed an increase in terrorist attack plans involving armed assaults, vehicular assaults, and edged weapons instead of bombings.
While many Ukrainian drones do in fact use 3D printed munitions, these munitions are filled with military-grade high explosives that are harvested from landmines, artillery shells, or bulk shipments from arms factories. They are not using homemade explosives to fill these munitions.
Conversely, non-state groups are increasingly using drones. We continue to see groups such as the Mexican cartels using low-explosive chlorate mixtures in their locally fabricated drone munitions. These are not nearly as powerful and deadly as munitions filled with military grade high explosives.
Certainly, it is necessary to continue to develop effective countermeasures to protect against FPV drone attacks, and efforts must be made to stop the proliferation of military ordnance from active war zones and the diversion of ordnance from military use. However, we have not yet reached the point where drones pose as great a threat to people and armored vehicles as they do on the battlefield.
I can foresee some ways in which cheap FPV drones could be used against infrastructure and aviation targets, even accounting for munition constraints, but I don’t really want to delve too deeply into that topic in a public forum.
But aside from using drones for attacks, the drone advancements we have seen on the battlefield in Ukraine also bring some other implications.
Drones have appeared in increasing numbers over private estates, corporate headquarters, government facilities, airports, and public events. In addition to causing significant havoc by shutting down airports and disrupting major events, drones have become a serious threat to privacy and proprietary information.
While California passed legislation in 2015 to prevent aerial snooping using drones, paparazzi continue to use them to pry into the private lives of celebrities. Police also report that high-end robbery crews are using drones to conduct preoperational surveillance of estates to help in planning robberies.
The use of quieter drones will make it harder for security teams to detect paparazzi, criminals, or corporate spies using drones, and using fiber optic drones will make it more difficult to track and arrest illegal drone operators. Fiber optic-equipped drones specifically will also provide higher definition video feeds, which will serve to embolden such actors to behave even more brazenly.
These implications underscore a hard truth: if we don’t keep advancing drone detection and defeat systems, we will be flying blind to the emerging threats they pose.
The Confluence
Today, companies (and organizations) are being brazenly and persistently targeted by state intelligence agencies. Some of them, such as Russia and China, have been quite open about their intent to steal trade secrets from Western companies. A well-documented case of this type was the thwarted recruitment of a GE Aviation engineer by the Chinese Ministry of State Security (MSS) that resulted in the arrest of an MSS officer in Belgium in 2018.
In addition to the threat posed by state intelligence agencies, companies across the globe employ former intelligence officers in various capacities. In Russia, Siloviki (roughly translated as securocrats) from Vladimir Putin’s circle have taken critical positions in a number of important companies. Likewise, it is extremely difficult to disentangle most Chinese companies from the Chinese Communist Party and various government security agencies. But of course, China and Russia are not the only countries with companies that employ former intelligence officers.
These government intelligence officers and former intelligence officers will bring their traditional espionage ethos and tradecraft with them when they conduct corporate espionage. Because of this, it is important for insider threat programs to look beyond the massive downloads of data that are an easily detected signal of an untrained “one-hit wonder,” and expand their focus to include searching for the more subtle behaviors exhibited by trained agents who will attempt to remain in place inside the company.
If a government intelligence officer or former officer recruits a spy inside a corporation or organization, they are very likely to provide them with at least some degree of intelligence tradecraft training. This will result in them having a profile and exhibiting behavior that will be far different from more amateurish, untrained corporate spies. Instead of the mass downloads of a one-hit wonder, they will be encouraged to gradually and carefully gather information and taught how to do so without leaving much of a trace.
Also, instead of a scattergun approach of gathering anything they think could be of value, these agents will be more selective, focused on obtaining the specific items of intelligence they’ve been tasked to collect. Additionally, their handlers will be more subtle in the way they use the stolen information so as not to jeopardize their agent in place.
To help protect their intellectual property, many companies are using cyber tools to detect when an employee accesses sensitive information they should not have access to. These tools can also help detect attempts to download large amounts of information, send it to a cloud storage service, or print it. But unless these tools are designed so that they can help spot the more surreptitious behavior of agents in place, an overreliance on technological tools could leave companies with a blind spot to more subtle corporate espionage tradecraft.
Mitigating the Threat of Agents in Place
The first step in mitigating any threat is awareness, and this threat is no different. Effective mitigation of the threat posed by insiders who remain in place to commit espionage requires awareness of the threat at every level of the company or organization, including leadership. If organizational leadership does not support an insider threat program, it is extremely difficult for lower-level personnel to be effective.
The primary means to create the needed awareness is through education and training. As noted above, cyber tools are helpful, but the bottom line is that there is no technological silver bullet that will catch every corporate spy. Employees are a critical front-line defense against agents in place, and there simply is no other insider risk countermeasure that is as valuable as the personal knowledge of trusted employees and the interactions they have with their coworkers.
The corporate security team, HR, corporate legal, etc., commonly do not have much daily interaction with most employees in an organization—far less contact than co-workers and direct supervisors have. Because of this, co-workers and managers need to be educated about the threats posed by insiders, how they operate, and what signs to look for. Most people can intuitively recognize deceptive behavior, even if they may struggle to articulate what it is that strikes them as being off or wrong.
Employees must feel empowered to report suspicious behavior, and insider threat education programs must include instructions on whom to report suspicious activity to and how to report it. The way that reporting of suspicious activity is handled will make or break an insider threat program. Trust is hard to earn and easy to lose, and if reports of suspicious activity are not handled in a confidential and competent manner, employees will quickly become reluctant to report anything.
Another critical component of an insider threat program is vetting. This applies not only to pre-hire screening, but also periodic re-screening, or even better, ongoing monitoring. One area of vetting that is often overlooked is contract employees. It is important to check on the vetting programs of companies that are supplying contract employees to ensure that they meet the standards of your organization, rather than just assuming that contract employees have been properly vetted.
Finally, it is important to emphasize that countering the threat of corporate espionage is not just the responsibility of corporate security and the FBI. It is a community responsibility, and every person in your organization plays a critical role in keeping your company’s sensitive information safe—and helping ensure the future viability of the company. Corporate espionage can place everyone’s job in jeopardy.
