Edward Snowden and the NSA: A Lesson About Insider Threats

Edward Snowden during an interview in Hong Kong.Photograph by The Guardian via Getty Images
Lock
This article is for subscribers only.

In all the mysteries surrounding the Edward Snowden affair, there’s one that hasn’t received much attention: Why didn’t the NSA, one of the most technologically sophisticated organizations on the planet, have a way to detect that Snowden was downloading thousands of documents?

The corollary question every chief executive should ask of his or her top security officer: “Does our organization have a way to detect unauthorized access to our data?” According to the recent SANS 2013 Critical Security Controls survey, less than 10 percent of companies actually have proactive monitoring of security controls, the area that governs unauthorized access.