APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Varonis

Gilad Raz, CIO

It's Time to Turn Security Inside Out

Gilad Raz

Gilad Raz

When 100,000 U.S. taxpayers were the victims of identity theft at the IRS earlier this year, it seemed like just the latest in a long line of cases that constantly remind us: everyone’s at risk. But there was something unique about this particular episode—it prompted business leaders to rethink their security priorities.

IRS Commissioner John Koskinen actually told The Wall Street Journal that what happened to them specifically was “not a hack or a data breach.” Why? Because the IRS security systems weren’t actually compromised. “These are imposters pretending to be someone,” he said.

This draws a startling parallel to Edward Snowden, the famous NSA contractor who leaked classified information in 2013. While Snowden had the authority and clearance to access all of the classified documents that he ended up exploiting (which was far more access than he needed to do his job), no one inside the NSA was tracking Snowden’s digital footsteps. No one was looking at what he was opening and exploring. How could the country’s leading surveillance organization not be tracking the activity of its own people surrounding these sensitive files?

“Unstructured data is the data we have the most of, and know the least about”

Perhaps most surprising is the fact that this same pattern is not uncommon, and–despite all the hype around Snowden–it remains a massive issue in every industry.

Gartner refers to unstructured data (our emails, word documents, spreadsheets, presentations, etc.), as “dark data” because, let’s face it, when it comes to what’s going on with these files, most organizations are clueless. And so much of data contains sensitive information, like social security numbers, credit cards numbers, personal health information, financial records, or confidential forecasts and roadmaps. Unstructured data is the data we have the most of, and know the least about.

It would seem that protecting these assets where they live would be given. But unfortunately, our culture of convenience and rapid innovation has led us all down a path that has spurred exponential creation, duplication, and sharing of business data while leaving it virtually unmonitored and poorly secured. According to IDC, the world’s data is expected to grow by 50x over the next decade, and 90 percent of that new data will be unstructured business data. And, according to Forrester Research, many of the highest-profile breaches have involved compromised identities of individuals authorized to access some part of an organization’s computing environment.

One of our light-bulb moments happened when we were approached by a large military organization where a trusted insider stole and sold hundreds of thousands of files without anyone noticing. The organization had invested tens of millions of dollars in every security technology you can think of and had dozens of people managing access to data, but it wasn’t enough.

This employee had access to the same sensitive files as their supervisor, 90 percent of which were not relevant to their job. Even after the organization realized there was a breach, they couldn’t respond effectively because they didn’t know the scope of the damage. They couldn’t even figure out what files were taken after the fact.

If we had effective walls up to protect these files from getting stolen or leaving our networks, much of this wouldn’t matter. But let’s be honest: there is no security perimeter anymore. Cyber criminals are getting good, excellent even, at their jobs.

If a hacker or rogue employee wants something, they can get it. And exploit it. All they need is access to a few (maybe even one) employee accounts, and it’s entirely possible that no one will notice they are accessing, modif or copying information once they are inside. And the wrong person merely seeing certain information they shouldn’t, can be a compromise. Nothing needs to be infiltrated but one’s memory.

We need to turn security inside out. For years, the C-suite has been asking the security team to focus on sealing the borders and identifying the criminals. But why invest disproportionately in the perimeter when there’s no certainty that the threats are outside and the assets are inside at this point?

The reality of insider threats (malicious, unintended, or caused by co-opted identities) is a major factor driving new approaches to user behaviour analytics (UBA). Organizations can now use constantly collected metadata to monitor risky user behaviour, unusual patterns of data access and other signs of risk from their employee populations as well as vendors, customers and other third parties with access to their networks. Alerts can be customized and automated. Turning security inside out means recognizing that users are often the weak link in the chain.

Juniper Research recently predicted that breaches will cost the US $2.1 trillion by 2019. When will this be a big enough business problem to convince enterprises to flip their perspective?

Varonis Systems (NASDAQ: VRNS) is an American software company which also has operations in Singapore. Founded in 2004, the company employs over 1000 people worldwide with a turnover of $164.5 million.


The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    ISS Facility Services Australia & New Zealand

    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO

  • Willis Towers Watson

    BPAY Group

    Building BPAY Group's New Digital Foundation

    Angela Donohoe, Chief Information Officer

  • Willis Towers Watson

    Bvn Architecture

    How Have Recent Advancements in Big Data Been Impacting Businesses?

    Marc Solomon, CIO

  • Willis Towers Watson

    Tassal Operations

    BI & Analytics in Aquaculture

    Matthew Leary, CIO

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security.apacciooutlook.com/leadership-perspective/its-time-to-turn-security-inside-out-nwid-4170.html