MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Insider Threats and Corporate Data exfiltration

Insider Threats and Corporate Data exfiltration

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Jane Lo, Singapore Correspondent speaks with Dagmawi Mulugeta, Threat researcher with Netskope Threat Labs.

Dagmawi has his OSCP and has previously worked at Cyrisk (a subsidiary of 4A Security), Sift Security (acquired by Netskope), and ECFMG as a researcher, security engineer, and developer. He has innate interests in public CTFs, exploit development, and abuse of cloud apps.

He has his MSc in Cybersecurity from Drexel University. In this interview, Dagmawi shared the behavioural insights found for employees preparing to leave, and how these indicators could enable organizations to protect their data more effectively.

He noted the concern that many organisations have with “flight risk” users – that is, employees that are getting ready to leave – taking corporate data with them. A common question to address this concern, is how to efficiently identify such risks – without sifting through hundreds of alerts and spending hundreds of man-hours.

Dagmawi shared how they approached this problem by analysing anonymized data of over 4 million users from more than 200 different organizations worldwide., and some interesting key revelations:

(i) 15% of leavers used personal cloud apps (e.g. Google drive, Gmail) to take data with them
(ii) 2% were violating corporate policy (exfiltrating sensitive corporate information)
(iii) majority of the data movement happens 50 days before leaving. Dagmawi highlighted how they identified three key signals to filter out alerts with potential flight risks:
a) volume – identifying whether the data being moved is anomalous for the individual in the organisation
b) nature of data – whether the data being moved is sensitive
c) direction – whether the cloud application is outside of the organisation’s management (e.g. google drive).

Wrapping up, Dagmawi recommended that encoding the three signals into the detection systems could help reduce the size for reviews by 43x – that is, for every 50 alerts, the signals could help to filter out the 1 or 2 concerning ones.

Recorded 11th May 2023, 3.30pm, Black Hat Asia 2023, Singapore Marina Bay Sands.

#bhasia #mysecuritytv #insiderthreat

OTHER VIDEOS IN THIS SERIES

s1
March 31, 2026
Filmed at Edith Cowan University in Perth, Reuben Rajasingham, CEO and Co-Founder of LC60.AI, shares an inside look at the company’s new satellite manufacturing facility.Watch Now
furgo
March 27, 2026
In this episode we visit Fugro’s Remote Operations Center (ROC) in Houston, Texas, USA and speak with Finn Richard, Regional Manager for the Americas, about how the company manages offshore survey operations and uncrewed vessels from a 24/7 command facility.Watch Now
sp
March 17, 2026
In this exclusive interview from Axiom Space headquarters in Houston, Aaron Tullos, Vice President of Station Engineering, gives Australia in Space TV an inside look at the engineering behind the Axiom Station, a commercial space station designed to operate in low Earth orbit.Watch Now
a6
March 8, 2026
At Zero Trust World #ZTW26 in Orlando, we speak with Emile Barakat, Director of Operations – APAC at ThreatLocker, about the new Australian regional office and partners and clients in the APAC region.Watch Now

ENQUIRE NOW

PLEASE COMPLETE