insider threat Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/insider-threat/ Breaking news about the market for products, systems and services for the U.S. intelligence community Wed, 20 May 2026 14:37:51 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg insider threat Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/insider-threat/ 32 32 59882712 Marines post insider threat monitoring RFI https://intelligencecommunitynews.com/marines-post-insider-threat-monitoring-rfi/?utm_source=rss&utm_medium=rss&utm_campaign=marines-post-insider-threat-monitoring-rfi Wed, 20 May 2026 14:37:51 +0000 https://intelligencecommunitynews.com/?p=44613 On May 19, the United States Marine Corps (USMC) posted a request for information (RFI) for an insider threat monitoring...

The post Marines post insider threat monitoring RFI appeared first on Intelligence Community News.

]]>
On May 19, the United States Marine Corps (USMC) posted a request for information (RFI) for an insider threat monitoring tool. Responses are due by 10:00 a.m. Eastern on May 29.

USMC is seeking information from interested organizations on capabilities in the marketplace for the maintenance, enhancement, and expansion of the Insider Threat Program Monitoring Tool.

As part of the Marine Corps Insider Threat Program, there is a Monitoring Tool used to detect insider threats on the Marine Corps Enterprise Network (MCEN). The information compiled from these sources, integrated with information from various other sources (e.g., human resources, law enforcement, and counterintelligence) supports analysis and response to counter insider threats on the MCEN. This effort is specific to the monitoring tool application maintenance, capability enhancement, and expansion.

The Marine Corps Insider Threat Program’s Monitoring Tool is mostly fielded. The platform includes the following capabilities:

  1. User Activity Monitoring (UAM)
  2. Behavioral Analytics Platform (User Behavior)
  3. Case Management System

 

To support the USMC Insider Threat Program, the contractor shall field the Behavioral Analytics Platform, operate, enhance, expand, and sustain a comprehensive Insider Threat Monitoring System.

Review the USMC insider threat monitoring tool RFI.

Source: SAM

IC News brings you business opportunities like this one each week. If you find value in our work, please consider supporting IC News with a subscription.

The post Marines post insider threat monitoring RFI appeared first on Intelligence Community News.

]]>
44613
Marine Corps seeks insider threat program support https://intelligencecommunitynews.com/marine-corps-seeks-insider-threat-program-support/?utm_source=rss&utm_medium=rss&utm_campaign=marine-corps-seeks-insider-threat-program-support Wed, 13 Aug 2025 12:57:27 +0000 https://intelligencecommunitynews.com/?p=42421 On August 12, the U.S. Marine Corps Installations Command (MCICOM) released sources sought notice for the Marine Corps Insider Threat...

The post Marine Corps seeks insider threat program support appeared first on Intelligence Community News.

]]>
On August 12, the U.S. Marine Corps Installations Command (MCICOM) released sources sought notice for the Marine Corps Insider Threat Program (MC InTP). Responses are due by 2:00 p.m. Eastern on August 26.

In support of Security Branch, Information Intelligence Division (IID) operating under the Deputy Commandant, Information (DC I), MCICOM intends to solicit support services for the MC InTP. The Government is actively seeking information on potential sources of the requirements.

This sources sought notice is a market research tool being used to determine potential firms capable of providing the products and services described prior to determining the method of acquisition and issuance of a request for proposal. The NAICS code for this requirement is 541690 with a size standard of $16.5M.

Review the US Marine Corps insider threat sources sought notice.

Source: SAM

The right opportunity can be worth millions. Don’t miss out on the latest IC-focused RFI, BAA, industry day, and RFP information – subscribe to IC News today.

The post Marine Corps seeks insider threat program support appeared first on Intelligence Community News.

]]>
42421
INSA releases new insider threat white paper https://intelligencecommunitynews.com/insa-releases-new-insider-threat-white-paper/?utm_source=rss&utm_medium=rss&utm_campaign=insa-releases-new-insider-threat-white-paper Mon, 09 Jun 2025 14:11:24 +0000 https://intelligencecommunitynews.com/?p=41907 On June 2, the Intelligence and National Security Alliance (INSA) released a new white paper, Countering Insider Theft of National...

The post INSA releases new insider threat white paper appeared first on Intelligence Community News.

]]>
On June 2, the Intelligence and National Security Alliance (INSA) released a new white paper, Countering Insider Theft of National Security Technology, developed by its Insider Threat Subcommittee. Building upon INSA’s 2021 report, Insider Threats and Commercial Espionage, the paper examines the rising risk of insider-enabled intellectual property theft by foreign adversaries targeting U.S. national security technologies.

The paper finds that academic institutions, startups, and small businesses, often at the forefront of innovation in dual-use technologies like artificial intelligence and quantum computing, face heightened risks of insider exploitation. These organizations may lack the security infrastructure and threat awareness found in cleared government or industry settings, making them attractive targets for foreign actors seeking to acquire U.S. intellectual property.

To help close these gaps, the authors offer a series of recommendations to strengthen safeguards across the broader innovation ecosystem, including the formation of a multi-agency task force, improved coordination among government agencies, and support for organizations operating outside the cleared environment.

“Protecting our innovation base requires a broader, more inclusive approach to insider threat mitigation,” said INSA President Suzanne Wilson Heckenberg. “This paper provides practical recommendations that can help government, academic, and industry leaders reduce risk while continuing to foster collaboration and technological progress.”

Download the paper.

Source: INSA

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

The post INSA releases new insider threat white paper appeared first on Intelligence Community News.

]]>
41907
Meeting the Insider Cybersecurity Threat Head-On: A Primer https://intelligencecommunitynews.com/ic-insiders-meeting-the-insider-cybersecurity-threat-head-on-a-primer/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-meeting-the-insider-cybersecurity-threat-head-on-a-primer Mon, 05 May 2025 13:18:33 +0000 https://intelligencecommunitynews.com/?p=41634 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies One of the main...

The post Meeting the Insider Cybersecurity Threat Head-On: A Primer appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

One of the main cybersecurity challenges on the radar of experts in 2025 is insider threat. Federal IT professionals not only need to be aware of this threat, but to take active measures to minimize its potential damage.

A blog posted to the Cloud Security Alliance by a Microsoft security specialist listed insider threats among the top ten cybersecurity threats to watch out for in 2025. And according to the 2025 Ponemon Cost of Insider Threats Global Report, insider threat risks this year could cost organizations an average of $17.4 million. The cost of incident containment and response has been increasing, even though the average time to contain the threat has actually decreased.

There are a variety of strategies already being promoted to protect against insider threats. As far back as 2021, in a commissioned report from Forrester Research, common strategies include implementing database activity monitoring, improving incident detection, investigation and response capabilities, using AI for threat intelligence and breach investigation, and improving identity and access management tools and policies.

The Cloud Security Alliance blog mentioned earlier also notes that organizations looking for ways to address this threat “should implement strict access controls, conduct regular audits, and foster a culture of security awareness. The blog also states that “Behavioral analytics tools can also help identify unusual activities that may indicate insider threats”.

Of course, there is much more to an insider risk mitigation strategy than can be summed up in two short sentences. In this commentary, we’ll take a closer look at the problem of insider threats to cybersecurity, and provide a deeper dive into ways to minimize the risk from insider threats.

Insider threats defined

Simply put, an insider threat is a security risk that comes from an internal source of the targeted organization. It may involve a current or former employee (or business associate) who misuses access to sensitive information or privileged accounts within the organization’s network.

Unfortunately, traditional security measures focus primarily on external threats; they are not always capable of identifying threats coming from inside the organization.

There are several types of insider threats:

Malicious insider. This is a person who intentionally abuses legitimate credentials – most commonly to steal information for financial or personal gain. As an example, a malicious insider might be a person with a grudge against a former employer, or an opportunistic employee who sells secret information to a competitor. These people may have an advantage over other attackers: They are familiar with the organization’s security policies and procedures, as well as its vulnerabilities.

Careless insider. Typically, this person unknowingly exposes the system to outside threats. Unfortunately, this is the most common type of insider threat. Inadequate cyber hygiene training can result in mistakes, such as leaving a device exposed or becoming the unwitting victim to an email phishing scam. An employee with no intention of harming the organization may click on an insecure link, thereby infecting the system with malware.

A mole. Is an imposter – technically an outsider – who has gained insider access to a privileged network. It may be someone from outside the organization posing as an employee or partner.

While not necessarily the most common across every organization, malicious insiders can cause some of the greatest damage. It is important, therefore, to understand some of the key indicators of such threats.

How can an organization know that it has been exposed to a malicious insider threat? Certainly, it can be indicated by anomalous activity at the network level. Similarly, if an employee seems to be dissatisfied or holds a grudge, that also can be a sign. Unfortunately, even an employee that is enthusiastically taking on additional responsibilities could mean the potential for foul play.

Some threat indications are easier to track than others are, and they fall generally under the category of unusual behavior. For example, activity at unusual times, such as signing in to the network at 3:00 am, should throw up a red flag. Unusual volumes of traffic, or transferring large amounts of data across the network, can also be a cause for concern, as can unusual types of activity such as accessing resources not typically associated with an employee’s responsibilities.

Best practices to minimize insider threat

There are several strategies an organization can employ to reduce the risk of insider threats.

Protect critical assets. By critical assets, we mean systems, technology, facilities, and people. However, a critical asset can also refer to Intellectual property, including customer data for vendors, proprietary software, schematics, and internal manufacturing processes.

It is important to have a comprehensive understanding of what the organization considers a critical asset. What kind of critical assets does the organization have? Can the assets be prioritized? What is the current state of each asset?

Define, document and defend policies. Organizational policies must be clearly defined and documented in order to enforce them and prevent misunderstandings. Every employee in the organization must be familiar with security procedures and should understand their rights in relation to intellectual property (IP). This is cyber hygiene best practice and it ensures that privileged content is not shared improperly.

Increase visibility. Make use of solutions that can track employee actions and correlate information from multiple data sources. Deception technology, for example, might be useful in luring a malicious insider or imposters and gaining visibility into what they are doing.

Make the right kind of culture changes. Once again, this ties back to good cyber hygiene. Security is a combination of knowledge, attitudes and beliefs. To ensure employees are not being negligent, and to address the root causes of malicious behavior, it is essential that all employees are properly educated in security issues – and that they have what they need to improve their overall satisfaction.

Insider threat detection: Machine learning and other solutions

Insider threats can be more difficult to identify or prevent than outside attacks. What’s more, they often can circumvent or avoid traditional security solutions that focus on external threats, like firewalls and intrusion detection systems. If an attacker can get past an authorized login, conventional security measures may not identify any unusual behavior. Malicious insiders also can avoid detection if they are familiar with the organization’s existing security measures.

That means protecting critical assets must rely on more than a single solution. An insider threat detection strategy must be diversified. One way to do that effectively is to combine several tools, so that insider behavior can not only be monitored but also filtered through a large number of alerts to eliminate false positives.

Machine Learning (ML) applications can help analyze data streams and prioritize the most relevant alerts. Digital forensics and analytics tools, like User and Event Behavior Analytics (UEBA), help detect, analyze, and alert a security team to any potential insider threats. User behavior analytics can establish a baseline for normal data access activity, while database activity monitoring can help identify policy violations.

Insider threat risks are not going away, and in fact may become increasingly pervasive and costly in the years to come. Understanding the types of insider threats and taking proactive measures now will be essential in mitigating the consequences of this cybersecurity challenge.

What to Look for in Insider Threat Solutions

User behavior analysis is the basis of protection from insider threats. Unfortunately, that by itself is not enough. The cybersecurity industry has introduced many providers that offer a range of solutions to monitor how users move through the network, as well as protecting assets on a data level. Therefore, no matter what a malicious insider accesses, the organization remains in control.

Data security solutions must be able to protect data on premises, in the cloud and in hybrid environments. These types of solutions also give security and IT teams full visibility into how the data is being accessed, used, and moved around the organization.

Here are some of the features any organization should look for to ensure they have a comprehensive solution with multiple layers of protection:

  • Database firewall: To block SQL injection and other threats, while evaluating for known vulnerabilities.
  • User rights management: To monitor data access and activities of privileged users, identifying excessive, inappropriate, and unused privileges.
  • Data masking and encryption: To make sensitive data useless to bad actors, even if they are somehow able to access it.
  • Data loss prevention (DLP): To inspect data in motion, at rest on servers, in cloud storage, or on endpoint devices.
  • User behavior analytics: To set baselines for data access behavior, employing machine learning to detect and alert on abnormal and potentially risky activity.
  • Data discovery and data classification: To reveal the location, volume, and context of data on-premises and in the cloud.
  • Database activity monitoring: To monitor relational databases, data warehouses, big data and mainframes, generating real-time alerts on policy violations.
  • Alert prioritization: To look across all security events and prioritize the most significant ones. AI and machine learning technology are particularly helpful in this case.

 

Make sure your solution provider offers these types of features, and be prepared before the next insider threat comes calling.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Meeting the Insider Cybersecurity Threat Head-On: A Primer appeared first on Intelligence Community News.

]]>
41634
MITRE and DTEX Systems announce partnership https://intelligencecommunitynews.com/mitre-and-dtex-systems-announce-partnership/?utm_source=rss&utm_medium=rss&utm_campaign=mitre-and-dtex-systems-announce-partnership Wed, 02 Feb 2022 12:49:14 +0000 https://intelligencecommunitynews.com/?p=31555 On February 1, McLean, VA-based MITRE and Saratoga, CA-based DTEX Systems announced a partnership to elevate insider risk awareness and...

The post MITRE and DTEX Systems announce partnership appeared first on Intelligence Community News.

]]>
On February 1, McLean, VA-based MITRE and Saratoga, CA-based DTEX Systems announced a partnership to elevate insider risk awareness and human-informed cyber defense strategies through behavioral-based research and the launch of the MITRE Inside-R Protect program.

Today’s employees work within a high-paced, technology-enabled world where they are asked to do more and do so faster than ever before. This workforce requirement, coupled with the rise in the threat of nation-state adversaries aggressively targeting trusted insiders, is driving a call to action within Five Eyes critical infrastructure organizations to manage insider risk more effectively while also protecting increasingly distributed and hybrid workforces.

“The risk to the critical infrastructure entities of the Five Eyes from insider threats is very real, and any compromise to the security of these entities will have a damaging and lasting impact to these nations’ economies and the safety of their citizens,” said Julie Bowen, MITRE’s senior vice president of operations and outreach and chief legal officer.

Under a non-exclusive licensing agreement, MITRE and DTEX will conduct collaborative research and deliver MITRE Inside-R Protect as a set of data-driven, community-oriented service offerings to help industry and government elevate their insider risk programs using behavioral sciences.

MITRE Inside-R Protect will offer Five Eyes critical infrastructure organizations the following service offerings:

  • Expert review of existing or planned insider risk programs,
  • An independent, data-driven, insider risk assessment and support for self-assessments, and
  • Continuous knowledge transfer and closed-door briefings on MITRE insider threat research and actual insider threat cases.

“MITRE recognizes three fundamental challenges in insider threat,” said Deanna Caputo, MITRE’s capability lead for insider threat. “First, there is a lack of data-driven, behavior-based, and rigorous scientific evidence to understand these escalating risks. Second, there is an over-reliance on frameworks and security controls focused on addressing external cyber threats. And third, insights are being made from a small pool of case studies that lack sufficient detail. We feel that these challenges must be addressed immediately as a component of our mission to solve problems for a safer world. We needed to raise the bar.”

“Insider threats, whether the result of a malicious insider, a compromised user, or a negligent employee, represent one of the greatest risks to an organization’s brand, intellectual property, workforce, and supply chain,” said Mohan Koo, CTO and co-founder, DTEX Systems. “Our research with MITRE found new human behavioral indicators and sequences that represent markers that appear in nearly every insider threat event. These indicators, in the hands of MITRE’s experts and scientists, and layered into our DTEX InTERCEPT platform, offer Five Eyes critical infrastructure entities an opportunity to identify and mitigate insider-born risks before data exfiltration, sabotage, and fraudulent behaviors result in permanent operational damage.”

Source: MITRE

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post MITRE and DTEX Systems announce partnership appeared first on Intelligence Community News.

]]>
31555
USMC posts data aggregation RFI https://intelligencecommunitynews.com/usmc-posts-data-aggregation-rfi/?utm_source=rss&utm_medium=rss&utm_campaign=usmc-posts-data-aggregation-rfi Fri, 12 Nov 2021 12:50:47 +0000 https://intelligencecommunitynews.com/?p=30921 On November 10, the U.S. Marine Corps posted a request for information for data aggregation software. Responses are due by...

The post USMC posts data aggregation RFI appeared first on Intelligence Community News.

]]>
On November 10, the U.S. Marine Corps posted a request for information for data aggregation software. Responses are due by 11:00 a.m. Eastern on November 29.

The Marine Corps Installations, National Capital Region – Regional Contracting Office (MCINCR-RCO), Marine Corps Base, Quantico, VA is seeking information on behalf of Marine Corps Intelligence Surveillance Reconnaissance Enterprise (MCISRE) Insider Threat Program (InTP).

The Marine Corps Intelligence Surveillance Reconnaissance Enterprise (MCISRE) Insider Threat Program (InTP) requires the continuing capability to use a data aggregation capability, which ties in specific algorithms (ML/AI) to audit and other information in order to provide network behavioral analysis and risk scoring which is managed by the MCISRE InTP.

The requirement is for a data aggregation capability, which ties in specific algorithms (ML/AI) to audit and other information in order to provide network behavioral analysis and risk scoring.

Review the full USMC data aggregation RFI.

Source: SAM

The right opportunity can be worth millions. Don’t miss out on the latest IC-focused RFI, BAA, industry day, and RFP information – subscribe to IC News today.

 

The post USMC posts data aggregation RFI appeared first on Intelligence Community News.

]]>
30921
CISA releases new insider threat tool https://intelligencecommunitynews.com/cisa-releases-new-insider-threat-tool/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-releases-new-insider-threat-tool Thu, 30 Sep 2021 12:06:59 +0000 https://intelligencecommunitynews.com/?p=30595 On September 28, the Cybersecurity and Infrastructure Security Agency (CISA) released an Insider Risk Mitigation Self-Assessment Tool, which assists public and private sector...

The post CISA releases new insider threat tool appeared first on Intelligence Community News.

]]>
On September 28, the Cybersecurity and Infrastructure Security Agency (CISA) released an Insider Risk Mitigation Self-Assessment Tool, which assists public and private sector organizations in assessing their vulnerability to an insider threat.  By answering a series of questions, users receive feedback they can use to gauge their risk posture.  The tool will also help users further understand the nature of insider threats and take steps to create their own prevention and mitigation programs.

“While security efforts often focus on external threats, often the biggest threat can be found inside the organization,” said CISA Executive Assistant Director for Infrastructure Security David Mussington.  “CISA urges all our partners, especially small and medium businesses who may have limited resources, to use this new tool to develop a plan to guard against insider threats.  Taking some small steps today can make a big difference in preventing or mitigating the consequences of an insider threat in the future.”

Insider threats can pose serious risk to any organization because of the institutional knowledge and trust placed in the hands of the perpetrator.  Insider threats can come from current or former employees, contractors, or others with inside knowledge, and the consequences can include compromised sensitive information, damaged organizational reputation, lost revenue, stolen intellectual property, reduced market share, and even physical harm to people.

Source: CISA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post CISA releases new insider threat tool appeared first on Intelligence Community News.

]]>
30595
NCSC issues insider threat mitigation report https://intelligencecommunitynews.com/ncsc-issues-insider-threat-mitigation-report/?utm_source=rss&utm_medium=rss&utm_campaign=ncsc-issues-insider-threat-mitigation-report Fri, 02 Apr 2021 13:03:08 +0000 https://intelligencecommunitynews.com/?p=29050 On March 23, the National Counterintelligence and Security Center (NCSC) issued “Insider Threat Mitigation for U.S. Critical Infrastructure Entities: Guidelines...

The post NCSC issues insider threat mitigation report appeared first on Intelligence Community News.

]]>
On March 23, the National Counterintelligence and Security Center (NCSC) issued “Insider Threat Mitigation for U.S. Critical Infrastructure Entities: Guidelines from an Intelligence Perspective.”

The new publication focuses on the human threats to U.S. critical infrastructure, including employees at critical infrastructure organizations who may be exploited by foreign adversaries.  The publication provides guidance on how to incorporate these threat vectors into organizational risk management plans and offers best practices for critical infrastructure entities to mitigate insider threats.

All organizations are vulnerable to insider threats from employees who may use their authorized access to facilities, personnel, or information to harm their organization, intentionally or unintentionally.  The harm can range from negligence — such as failing to secure data or clicking on a spear-phishing link — to malicious activities like sabotage, intellectual property theft, fraud, or workplace violence.

“Although often less appreciated than remote-access cyber threats, insider threats to critical infrastructure entities are growing and can be more difficult to mitigate.  Whether intentional or unintentional, the actions of insider threats in critical infrastructure can cause grave harm to national security, public safety, as well as individual organizations and state and local governments,” said Acting NCSC Director Michael Orlando.  “This publication provides a roadmap for critical infrastructure organizations to build effective insider threat programs.”

To help guard against such threats, the publication recommends that critical infrastructure entities, at a minimum: 1) have an insider threat program that identifies individual anomalous behavior at an early stage and the resources to respond appropriately, and that they 2) respond in a way that fosters trust across the organization and leverages the workforce as a partner.

While insider threats come in many forms, foreign adversaries often seek to exploit employees in U.S. and allied critical infrastructure entities to advance their interests.  In October 2018, the Justice Department announced charges against Chinese intelligence officers and their hackers who recruited employees at a French aerospace manufacturing company to introduce malware into the company’s networks in order to steal trade secrets.  The employees later alerted the hackers when the company learned about the malware so they could cover their tracks.

Some recent examples of insider threats at critical infrastructure entities include:

  • Transportation / Manufacturing:In March 2021, a Russian national pleaded guilty to offering an employee at a U.S. electric car manufacturing company $1 million to introduce malware into the company’s computer networks.  The Russian national planned to use the malware to exfiltrate data and extort the company.  The employee reported the approach to his company and the FBI later arrested the Russian national.
  • Energy: In February 2020, a former scientist at a U.S. petroleum company was sentenced to 24 months in prisonfor stealing trade secrets via a thumb drive from the petroleum company.  The stolen trade secrets related to next-generation battery technology and were valued at more than $1 billion.  A participant in China’s Thousand Talents Plan, the scientist planned to move to China with the trade secrets for use at a Chinese company where he had been offered a job.
  • Health Care: In February 2021, a former researcher at a U.S. medical institute was sentenced to 30 months in prisonfor stealing trade secrets on the treatment of pediatric conditions from the medical institute and attempting monetize the secrets via a company she had created in China.  She had received benefits from the Chinese government and had applied to multiple Chinese government talent programs.
  • Defense: In November 2020, a former engineer at a major U.S. defense contractor was sentenced to 38 months in prisonfor illegally exporting controlled data associated with advanced missile guidance systems to China.  While employed by the defense firm, the engineer transported the data on his company-issued computer to China.

The NCSC houses the multi-agency National Insider Threat Task Force (NITTF). Since its inception in 2012, the NITTF has been working to assist federal agencies build programs at their agencies that deter, detect, and mitigate insider threats, considering the distinct needs, missions, and systems of each individual agency.  NITTF has also expanded its outreach to entities beyond federal agencies to help raise awareness of insider threats and best practices for mitigation.

Source: NCSC

The post NCSC issues insider threat mitigation report appeared first on Intelligence Community News.

]]>
29050
Parsons wins NGA MOJAVE contract https://intelligencecommunitynews.com/parsons-wins-nga-mojave-contract/?utm_source=rss&utm_medium=rss&utm_campaign=parsons-wins-nga-mojave-contract Wed, 24 Feb 2021 14:09:15 +0000 https://intelligencecommunitynews.com/?p=28728 Parsons Corporation has been awarded a task order by the National Geospatial-Intelligence Agency (NGA) on the MOJAVE Functional Area 2...

The post Parsons wins NGA MOJAVE contract appeared first on Intelligence Community News.

]]>
Parsons Corporation has been awarded a task order by the National Geospatial-Intelligence Agency (NGA) on the MOJAVE Functional Area 2 (FA2) indefinite-delivery indefinite-quantity (IDIQ) contract, the company announced February 22. This award is the seventh task order Centreville, VA-based Parsons has won on the MOJAVE FA2 contract since 2017, totaling more than $200 million.

“We are excited to continue our partnership with NGA and its insider threat program,” said Laurie Ternes, senior vice president of Parsons’ threat intelligence directorate. “We appreciate NGA’s confidence in our ability to apply our knowledge, insight, and Scaled Agile Framework approach and deliver innovative solutions which mitigate the threats they face.”

The recompete contract from NGA has a six-month base with two option years and will continue providing security and engineering to the larger NGA mission as they seek to strengthen the nation’s counter insider threat mission. The MOJAVE FA2 contract provides a variety of security operations support including polygraph support, security specialist support, clinical psychology, counterintelligence support and insider threat analysis to assist NGA in executing their mission to the fullest.

Parsons has supported the NGA insider threat program since 2012, helping to implement large-scale analytics that automate the review of big data. The delivered technology and analytic solutions drive efficiencies that enable NGA to increase the volume of data being reviewed while reducing the time it takes to detect patterns of activity indicative of an insider threat. Parsons’ insider threat services have advanced NGA’s insider threat program and helped NGA to achieve multiple awards from the National Counterintelligence and Security Center.

Source: Parsons

The post Parsons wins NGA MOJAVE contract appeared first on Intelligence Community News.

]]>
28728
Identifying HR and Security Vulnerabilities Through Advanced Analytics with Alteryx https://intelligencecommunitynews.com/identifying-hr-and-security-vulnerabilities-through-advanced-analytics-with-alteryx/?utm_source=rss&utm_medium=rss&utm_campaign=identifying-hr-and-security-vulnerabilities-through-advanced-analytics-with-alteryx Tue, 01 Sep 2020 13:12:36 +0000 https://intelligencecommunitynews.com/?p=27401 From IC Insider Alteryx By Andrew MacIsaac, Director, Solutions Marketing, Public Sector, Alteryx, Inc. Author’s Note: This article describes a use...

The post Identifying HR and Security Vulnerabilities Through Advanced Analytics with Alteryx appeared first on Intelligence Community News.

]]>
From IC Insider Alteryx

By Andrew MacIsaac, Director, Solutions Marketing, Public Sector, Alteryx, Inc.

Author’s Note: This article describes a use case related to employee well-being and issues related to national security posed by insider threats. For those who work in sensitive areas of government (such as the Department of Defense (DOD) and the Intelligence Community), there is always a delicate balance between security, ethics, and privacy. Each agency should have a well-defined data governance and ethical use strategy that protects both the employee and the ability of the agency to fulfill its mission objectives.

The basis of any security clearance in the United States starts with a background check based on information individuals provide on the Standard Form 86 (SF 86). Financial information, employment history, family relationship, social networks, and educational background are just some of the personal information that those seeking a security clearance need to provide. The information is detailed, and omissions or inaccuracies can result in clearance not being granted and even worse — could lead to federal charges. The sharing of all this personal information could seem excessive or even intrusive, but when evaluated through the lens of protecting state secrets and sensitive information in a high-stakes environment, the protocols are necessary.

What is not readily apparent is the amount of stress that jobs dealing with national security issues can generate. In 2018, a study of 128 tactical cyber operators, including both civilian and military personnel, attempted to measure the dangerous impact of stress on employees, specifically on levels of fatigue, frustration, and cognitive workload. The study found that longer operations (those over five hours) drove 10% higher levels of fatigue and frustration. The authors of the study wrote that, “We’re not trying to take stress away from tactical cyber-operations. Stress is not bad when it’s managed. When it’s unmanaged and people don’t feel they have control, that’s where we see the negative effects.”

It is the attempt to identify levels of rising stress and frustration and other sources of potential threats to employees that makes human resources analytics imperative, and makes the focus on the well-being of people in these critical roles more important than ever.

The authors of the study put forth the following, “The National Security Agency (NSA) is part of the Department of Defense and is here to protect the nation. A mistake could affect things for a lot of people, so we have to make sure they [operators] also take care of themselves.”

For those who manage the human resources and internal security functions such as human resource officers (HROs) and facility security leaders (FSOs) at organizations that employ individuals with security clearances have dual concerns about the personal welfare of their employees, and they need to be diligent in finding vulnerabilities or possible threats that could potentially pierce the veil of required secrecy.

According to one recent article on Military.com, human resource and security offices are “Concerned about stress in the workplace, because too much stress or chronic stress can lead to poor judgment. No employee ever exploded in violence, committed suicide, stole government property, became a spy, or engaged in any other destructive or self-destructive behavior because they were happy and relaxed. They were stressed out and desperate. A safe and secure office environment is one in which employees know how to recognize and manage the negative aspects of stress.”

Analytic Process Automation

To evaluate possible vulnerabilities impacting employees of organizations involved in national security issues, HR and security leaders of these organizations need to access and analyze a lot of information to put together a complete a picture of behaviors that can indicate stress or be significant factors in causing stress. The following is a potential use case which illustrates how these teams can use Alteryx Analytic Process Automation (APA™) to streamline their analytic processes to find potential threats, protect their employees, and if necessary, determine interventions that will help their employees and protect their organizations.

With the Alteryx APA Platform, analysts can leverage over 80+ supported data connections, making it extremely easy to connect into different data sources, prep and blend the data into an acceptable structure, and then aggregate that data into a unified dataset. The dataset can then be output in a variety of different file types or third-party dashboards of choice. In this example below featuring dummy data, we simulate the aggregation of a job satisfaction survey, an employee HR database, and collected SF-86 information. This provides us a dataset for analysis that includes variables such as salary, debt, marital status, loans, mental illness diagnosis, etc.

Alteryx makes it easy to filter for desired subsets of data. In the above workflow, we have identified employees that have reported recent mental health and marital hardships. These can be included into a report that is sent via email to alert the necessary officials. Using the Join category of building blocks, the platform enables the ability  to dereference  personally identifiable information (PII) with unique Employee ID’s or another “primary key” to protect privacy.

To provide the necessary help to these individuals, users can perform spatial analytics to determine the closest health or counseling resources available to them to get the aid they may need. This same concept can be applied to find those with reported financial or gambling hardships access to the help they need.

Visual Insight

With Alteryx, users can very easily create interactive visual insights and graphs for data analysis. In this example below, we can create a bar graph to analyze the financial history of an employee that is known to have reported debt and gambling issues. With this analysis it would be possible to identify anomalies or trends in their financial activity. By analyzing the previous four years of financial trends, we can see that there seems to be some anomalies in May, August, and October of 2019. This data can also be run through a machine learning algorithm (Neural Network) to confirm this behavior is in fact an anomaly and could indicate the need for further investigation and/or intervention.

Sentiment Analysis

With the intrusion of social media platforms into our lives, it stands to reason that what we may say or the content we interact with can provide some insight into our state of mind. In this environment, text and sentiment analysis can play a critical role in identifying alarming behavior and potential vulnerability. Alteryx allows users to quickly create an analytics story around a user’s social media or communication activity. In this example below, social media data was ingested.

We can identify an increasing trend in negative sentiment being posted to the account with interactive charting. The analysis shows a high level of negative sentiment in 2019. With the creation of a word cloud around the 2019 posts, we can identify words like “depression,” “suicide,” “hate,” and more being used within the posts. These types of words can be used to trigger an alert of a possible situation where an individual could use some help.

Each section of this analytic workflow highlights different formats of visualizations, analysis, algorithms, and insights. Now that this workflow is created, it can be shared within a governed environment. With the Alteryx APA Platform, a collaborative and governed environment can be created where enterprise-wide users can run workflows, share, control user access, and schedule workflows to completely automate analytic processes. The functionality is created through a customizable user interface that allows authorized members of your organization to run workflows with different input variables. Alteryx also provides drag and drop integration with other third-party visualization products such as Tableau, Power BI, Qlik, and more.

Additional Analysis through Analytic Process Automation

The prototyped solution illustrated here is not an exhaustive overview of what could accomplished in the way of analysis that HR and security teams need. Additional analysis could include:

  • Social network analysis to show links between entities as well as known foreign adversaries.
  • Financial and banking network analysis with models to map out financial and banking networks to identify patterns of financial vulnerability and potential foreign adversary involvement.
  • Natural Language Processing (NLP) based analytics to conduct sentiment analysis across organizational-sponsored communication (e.g., email, instant messaging) comparing it to social media or sentiment analysis associated with an individual. This would create benchmark models to help with employee triage and intervention.

For more information on the Alteryx Intelligence Suite, click here.

About Alteryx, Inc.

Revolutionizing business through data science and analytics, Alteryx offers an end-to-end analytics platform that empowers data analysts and scientists alike to break data barriers, deliver insights, and experience the thrill of getting to the answer faster. Organizations all over the world rely on Alteryx daily to deliver actionable insights. For more information, visit www.alteryx.com.

Alteryx is a registered trademark of Alteryx, Inc.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Identifying HR and Security Vulnerabilities Through Advanced Analytics with Alteryx appeared first on Intelligence Community News.

]]>
27401