詳細検索

Unraveling the cause of internal leakage! The "fraud triangle" and the measures companies should take

Avatar
by 菊池
3 min read

Unraveling the cause of internal leakage! The "fraud triangle" and the measures companies should take
Translated from 日本語 • View original
菊池
菊池

Hello! I'm Kikuchi, a security analyst at Colorkrew. In this article, we will delve into internal leakage, that is, misconduct by employees and related parties. I would like to pay special attention to the theory of the "Fraud Triangle". This is a way of thinking that simply explains the background of why internal fraud occurs.

**What is the Triangle of Dishonesty? **

The "fraud triangle" is a model in which fraud occurs when the following three elements are met.

  1. Motivation / Pressure
  2. Opportunity
  3. Rationalization

1. Motivation / Pressure

There are various reasons why people run fraudulently. For example:

  • Financial hardship
  • Gambling and investment failures
  • Pressure on performance quotas
  • Impatient for promotion and recognition

Countermeasures

・Establishment of an in-house consultation desk: Establishment of a support system for mental health and daily life consultations.

・Re-evaluation of quotas and targets: Avoid unreasonable performance pressure and design realistic KPIs


2. Opportunity

An environment where "if you want to do it, you won't find out" creates fraud.

  • Excessive access permissions
  • Not logged or not checked
  • Loose supervision of administrators

Countermeasures

Countermeasures Description
Principle of Least Privilege Access to only the extent you need
Log Management & Periodic Review Visualize and monitor with SIEM and EDR logs
Division of Duties Creating a system that does not concentrate authority on one person

3. Rationalization

"This is not fraud" or "The company is bad" is a psychological state that justifies the act within oneself.

  • "I don't get paid overtime, so this much is allowed."
  • "My idea was exploited by the company"
  • "People around me are also doing it"

Countermeasures

Countermeasures Description
Implementation of Ethics Education Training to train ethics and judgment, introduction of case studies
Fair Evaluation System Evaluation and reward design that is less likely to generate dissatisfaction and distrust

Examples of Internal Leaks That Actually Existed

Case: Background of the case of taking out blueprint data at a certain manufacturer

:
A mid-level engineer took out the product blueprint data via USB just before changing jobs. Since the new employer was a competitor, it was a serious intellectual property risk.

 

Motivation: Anxiety about the future, gaining an advantage in changing jobs

Opportunity: Full access was granted

Justification: "It's a drawing I made, so it's no problem."

 

Measures that were effective as a precaution:

  • Restrict access to blueprint data (manage by sensitivity)
  • USB control + log monitoring (DLP products, etc.)
  • Immediate suspension of retirement accounts + proactive monitoring (SIEM and MDE utilization)

Conclusion

By understanding the fraud triangle, you can see areas for improvement as an organization, rather than just dismissing it as "employee betrayal."

  • Trust people but protect them with mechanisms
  • Balancing technical measures with psychological considerations
  • "Visualize" early signs

It is easy to take measures against opportunities by introducing Defender, but information security cannot be protected by simply raising the wall. Facing people's psychology and environment may be the real countermeasure.

If you have any problems with internal fraud measures, please contact Colorkrew!

 

Related Articles