Insider Threats Drive 34% of SMB Breaches; Three Password Controls Can Help
The Verizon 2025 Data Breach Investigations Report found that insider threats are responsible for 34% of breaches at small and medium businesses, with abused or mismanaged passwords as the leading attack vector. Insider incidents fall into three categories: malicious actors, negligent employees, and compromised credentials, with negligent behaviour accounting for the majority at 56%. Security experts recommend three practical controls to reduce exposure: just-in-time privileged access that auto-expires, credential check-in and check-out vaults for shared accounts, and automated offboarding workflows that revoke access immediately upon departure. Most business-grade password managers already support these features without requiring a dedicated security operations centre. Together, these measures limit the damage from malicious insiders, remove conveniences exploited by careless staff, and shorten the window during which a stolen credential remains useful.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in