The Danger from Within

by David M. Upton and Sadie Creese

WE ALL KNOW ABOUT the 2013 cyberattack on Target, in which criminals stole the payment card numbers of some 40 million customers and the personal data of roughly 70 million. This tarnished the company’s reputation, caused its profits to plunge, and cost its CEO and CIO their jobs. What’s less well known is that although the thieves were outsiders, they gained entry to the retail chain’s systems by using the credentials of an insider: one of the company’s refrigeration vendors.

Target’s misfortune is just one recent example of a growing phenomenon. External attacks—pervasive intellectual-property hacking from China, the Stuxnet virus, the escapades of Eastern European gangsters—get plenty ...

Get HBR's 10 Must Reads on Managing Risk (with bonus article "Managing 21st-Century Political Risk" by Condoleezza Rice and Amy Zegart) now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.