{"id":14816,"date":"2018-11-26T18:21:39","date_gmt":"2018-11-26T18:21:39","guid":{"rendered":"https:\/\/www.customerservicemanager.com\/?p=14816"},"modified":"2022-10-05T15:57:48","modified_gmt":"2022-10-05T15:57:48","slug":"stop-blaming-your-agents-for-call-center-breaches","status":"publish","type":"post","link":"https:\/\/www.customerservicemanager.com\/stop-blaming-your-agents-for-call-center-breaches\/","title":{"rendered":"Stop Blaming Your Agents for Call Center Breaches"},"content":{"rendered":"<img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-14824\" src=\"https:\/\/www.customerservicemanager.com\/wp-content\/uploads\/2018\/11\/csrlaptop.jpg\" alt=\"CSR working on a laptop\" width=\"598\" height=\"399\" srcset=\"https:\/\/www.customerservicemanager.com\/wp-content\/uploads\/2018\/11\/csrlaptop.jpg 598w, https:\/\/www.customerservicemanager.com\/wp-content\/uploads\/2018\/11\/csrlaptop-300x200.jpg 300w\" sizes=\"(max-width: 598px) 100vw, 598px\" \/>\n<p><strong>No matter what the industry, consumers trust organizations to look after their data. No more so when dealing with agents and customer service representatives who have access to vast amounts of sensitive data.<\/strong><\/p>\n<p>This trusted access for employees to cardholder data, personal details or medical records helps ensure the best customer experience. However, it also makes the call center a prime target for a security breach.<\/p>\n<p><strong>The Insider Threat<\/strong><\/p>\n<p>Whilst it\u2019s commonly understood that the greatest risk of a breach comes from the employee, blaming your agents is never the right route to take. Call center agents are human. They are careless, flawed and often exploited. In fact, attackers love exploiting the naivety of your employees because it\u2019s so easy.<\/p>\n<p>All it takes is one successful phishing email to persuade just one user to hand over their organizations login details. Once that hacker gains entry to your systems, you\u2019re not going to find out until it\u2019s too late \u2014 your anti-virus and perimeter systems aren\u2019t programmed to pick up on access using legitimate login details, giving snoopers all the time in the world to, well, snoop.<\/p>\n<p>And also keep in mind that almost every external attack eventually looks like an insider threat. The use of compromised internal credentials by an external attacker is the most common threat action in data breaches (Verizon, Data Breach Investigations Report 2018).<\/p>\n<p>So, how are you supposed to spot inappropriate employee access when it\u2019s already been defined as appropriate?<\/p>\n<p><strong>Spotting the threat<\/strong><\/p>\n<p>Security must be there to protect against both careless and malicious employee behavior and to protect against outsiders trying to gain access by pretending to be employees.<\/p>\n<p>When you boil it down, the only way to really tell if someone is a malicious insider or an intent external threat actor is by allowing them to perform actions (such as launching applications, authenticating to systems, accessing data, etc.) and determine whether the actions are inappropriate.<\/p>\n<p>But given the majority of your employees don\u2019t act the same way everyday \u2013 let alone the next week or month \u2013 it makes more sense to spot the threat actor by looking at leading indicators of threat activity, rather than waiting for the threat activity itself.<\/p>\n<p>One of the most accurate leading indicators is one no malicious insider or external threat actor can get around \u2013 the logon (local, remote, via SMB, via RPC, etc.). Endpoints require logons for access, lateral movement of any type requires authentication to access a target endpoint, and access to data first requires an authenticated connection.<\/p>\n<p><strong>No patch for employees but you can enhance access security<\/strong><\/p>\n<p>The leveraging of logon management solutions provides organizations with not only the ability to monitor logons and identify suspicious logon activity, but to also craft logon policies to limit the scope of account use and automatically shut down access based on inappropriate logon behavior. By using the contextual information around a user\u2019s logon (origin, time, session type, number of access points, etc.) genuine logins become useless to would-be attackers.<\/p>\n<p>So, while there might not be a patch for the employee quite yet, keep in mind that you do have a foolproof way to make sure call center staff are who they say they are, identify any \u2018risky\u2019 user behavior and put a stop to it before it ends up costing you capital, customers and your company\u2019s reputation.<\/p>\n<p><a href=\"https:\/\/www.isdecisions.com\/products\/userlock\/call-center-information-security\/\" target=\"_blank\" rel=\"noopener\">Learn more about how call centers can verify access to the network and the data within<\/a>.<\/p>\n<p><strong>About the Author<\/strong><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-14821\" src=\"https:\/\/www.customerservicemanager.com\/wp-content\/uploads\/2018\/11\/Francois-Amigorena.jpg\" alt=\"Fran\u00e7ois Amigorena\" width=\"117\" height=\"120\" \/>Fran\u00e7ois Amigorena is the founder and CEO of <a href=\"https:\/\/www.isdecisions.com\/\" target=\"_blank\" rel=\"noopener\">IS Decisions<\/a>, and an expert commentator on cybersecurity issues.<\/p>\n<p>IS Decisions is a provider of infrastructure and security management software solutions for Microsoft Windows and Active Directory. The company offers solutions for user-access control, file auditing, server and desktop reporting, and remote installations.<\/p>\n<p>Its customers include the FBI, the US Air Force, the United Nations and Barclays \u2014 each of which rely on IS Decisions to prevent security breaches; ensure compliance with major regulations, such as SOX and FISMA; quickly respond to IT emergencies; and save time and money for the IT department.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>No matter what the industry, consumers trust organizations to look after their data. No more so when dealing with agents and customer service representatives who have access to vast amounts of sensitive data..<\/p>\n","protected":false},"author":397,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[12,145,166],"_links":{"self":[{"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/posts\/14816"}],"collection":[{"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/comments?post=14816"}],"version-history":[{"count":8,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/posts\/14816\/revisions"}],"predecessor-version":[{"id":14857,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/posts\/14816\/revisions\/14857"}],"wp:attachment":[{"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/media?parent=14816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/categories?post=14816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.customerservicemanager.com\/wp-json\/wp\/v2\/tags?post=14816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}