KPM

Sales Forecasting

Protect Your Network: Know Who Your Privileged Users Are & Aren’t

Given the prevalence of technology in the world today, most organizations have valuable, sensitive data that can be stolen, misused, damaged, or destroyed. There’s a risk of outside hackers harming your network, but there’s also a risk from people within your organization who have special access or “privileged users.”

Simply defined, privileged users are people with elevated cybersecurity access to your organization’s enterprise systems and sensitive data. They typically include members of the IT department, who need to be able to reach every aspect of your network to install upgrades and fix problems. However, privileged users also may include those in leadership positions, accounting and financial staff, and even independent contractors brought in to help you with technology-related issues.

What Could Go Wrong?

Assuming your organization follows a careful hiring process, most of your privileged users are likely hardworking employees who take their cybersecurity clearances seriously.

Unfortunately, sometimes disgruntled or unethical employees or contractors use their access to perpetrate fraud, intellectual property theft, or sabotage. And they don’t always act alone. Third parties, such as competitors, could try to recruit privileged users to steal trade secrets. Or employees could collude with hackers to compromise an organization’s network in a ransomware scheme.

How Can You Protect Yourself?

To best protect your business, you may want to implement a formal privileged user policy. This is essentially a set of rules and procedures governing who gets to be a privileged user, precisely what kind of access each such user is allowed, and how your organization tracks and revokes privileged-user status.

When developing and enforcing the policy, you’ll first need to identify who your privileged users are and what specific security clearances each one needs. A good way to start is to list the privileges required for every position and then compare that list to a separate record of privileges that each employee currently has. What makes sense? What doesn’t? When in doubt whether someone needs a certain type of access, it’s generally best to err on the side of caution.

Also, establish an ‘upgrading’ process under the policy. Only trusted and qualified managers or supervisors should have the power to upgrade or reinstate an employee’s privileges, perhaps in consultation with the leadership team. Use technology to help standardize and track requests and approvals. For sensitive systems and applications, such as those that store customer and financial data, consider requiring two levels of approval to elevate a user’s privileges.

In addition, your privileged user policy should include stipulations to carefully monitor user activity. Observe and track how employees use their privileges. Let’s say a salesperson repeatedly accesses customer data for a region that the person isn’t responsible for. Have the sales manager inquire why. Subtly reminding employees that the organization is aware of their tech-related activities is a good way to help deter fraud and unethical behavior.

Another important aspect of the policy is how you revoke privileges and remove dormant accounts. When employees leave the organization, or independent contractors end their engagements, privileged access should be revoked immediately. Keep clear records of such actions. If a previously deactivated account somehow shows signs of activity, block access right away and investigate how and why it’s come back to life.

Do You Know?

Every organization should be able to definitively say who is a privileged user and who isn’t. If there’s any gray area or uncertainty regarding current or former employees or other workers, the security of your data could be severely compromised. And the ramifications, both financially and for your organization’s reputation, are potentially very serious. Contact us with questions.

Related Articles

Talk with the pros

Our CPAs and advisors are a great resource if you’re ready to learn even more.