By Ayokunmi Ogundapo
Insider fraud, a silent threat lurking within organizations, continues to pose a significant risk to businesses worldwide and an increasing trend in Nigeria that needs nipping. The 2023 Annual Fraud Landscape published by Nigeria Inter-Bank Settlement Systems (NIBSS) revealed a staggering loss of over 17.6 billion naira due to fraud. This figure, however, represents a fraction of the actual economic impact as NIBSS reported that less than half of financial institutions comply with fraud reporting regulations. This suggests that many organizations are silently grappling with the consequences of fraud, with the true extent of the problem remaining obscured in Nigeria.
Recent media reports have highlighted a concerning trend of increasing insider fraud within the fintech ecosystem and financial institutions. High-profile cases, such as the employee-facilitated laundering of over 40 billion naira at one of the Nigeria first-generation banks and the $24 million siphoned by an employee and merchants at one of the Nigerian fintech unicorns, underscore the significant risks posed by internal threats.
Insider fraud poses a significant threat to an organization’s security, reputation, and financial stability. Insider frauds, particularly those affecting financial services organizations, can have far-reaching consequences. If left unchecked, they can not only tarnish the reputation of the affected organizations but also destabilize the national economy and inflict significant harm on customers.
The Anatomy of Insider Fraud
The motivations behind insider fraud are diverse and complex. Financial gain is often a primary driver, but other factors, such as personal grievances, job dissatisfaction, or a desire for revenge, can also play a role. Additionally, external pressures, such as addiction, financial difficulties, or some cases blackmail may push individuals to engage in fraudulent activities.
Unlike external threats, insider fraud is perpetrated by individuals who have legitimate access to sensitive information and systems. This privileged position enables them to exploit system weaknesses, manipulate data, and even falsify logs to conceal their actions.
Given their privileged access and understanding of organizational processes with a motivation to commit fraud, insider threat actors can often perpetrate fraud undetected for extended periods. Unlike external threats, they are usually aware of suspicions and investigations in respect of their activities in the company and usually have enough information to make their discovery unlikely thereby maintaining a stealthy presence within the organization.
Combatting the Insider Threat
To effectively combat insider fraud, organizations must adopt a multi-layered strategy encompassing human factor techniques and technological solutions. Below are some of the human factor and technological solutions that organizations may adopt to curtail the menace of insider fraud within the Nigerian organizations.
Human Factor Strategies
- Systemic and psychological screening of new hires:
It is deeply concerning that individuals with a history of financial crime can still secure employment within the financial sector. While the lack of a centralized debarring service in Nigeria contributes to this issue, organizations must prioritize rigorous hiring practices to mitigate the risk of insider threats. Employing individual with fraud related or other financial crime records is a risk. It is importance for organizations not to only conduct psychological assessments can help identify individuals with personality traits that may predispose them to fraudulent behavior, such as impulsivity, dishonesty, or a lack of integrity but to also screen potential new hires for the tendencies to engage in fraud through thorough background checks to identify individuals with a history of financial crimes, particularly those involving fraud, embezzlement, or money laundering especially when considered for financial management roles or financial processing system administration roles. This has the potential of stopping to be insider threat at the gate before they even make it into the organization.
Although, there is no centralized Debarring Service data in Nigeria that organization may rely on to make this judgement unlike in developed countries in Europe for instance where Debarring Services is centralized. there is, however, an initial step with the Central Bank of Nigeria (CBN) currently maintaining a blacklist of financial crime offender in Nigeria, this should be a good starting point for organizations to use for background check for potential hire. Also, the Nigeria Police Force (NPF), the Economic and Financial Crime Commission (EFCC), and Independent Corrupt Practices and Other Related Offences (ICPC) commission maintains disparate records of fraud and other financial crime matters treated in their respective jurisdiction. These are other institutions organizations may consult to obtain supplementary information in screening out individual with financial offence records.
To effectively mitigate insider threats, a centralized debarring service is essential. This would allow organizations to access a comprehensive database of individuals with a history of financial crime. While the government should take the lead in establishing such a service by mandating each arm of the government involved in the prosecution of financial crime to submit name of financial crime offenders to the centralized debarring service, organizations and risk professionals can also collaborate to share information and best practices.
By implementing robust hiring practices and advocating for a centralized debarring service, organizations can significantly reduce the risk of insider fraud and protect their assets, reputation, and wealth of their customers entrusted in their care.
- Employee Awareness and Training:
Employee awareness and training are crucial components of a comprehensive insider threat mitigation strategy. For the first part, there is a first-time offender who may already be in the system and secondly a lot of employees have been social engineered into aiding fraud and other financial related crime unaware. It is essential to educate employees about the risks of insider fraud, social engineering tactics, and their role in preventing such incidents.
A prime example of the dangers of insider threats is the case of the Database Administrator (DBA) at the defunct First Atlantic Bank. By exploiting their privileged access to the financial database, the DBA was able to manipulate data, create fictitious accounts, and siphon money from the bank. This went unnoticed for several months with many colleagues implicated in the process as their accesses were used in some of the fraud cases. This incident highlights the importance of employee awareness and limiting access privileges and creating approval later for sensitive actions like manipulating financial records. The practice of sharing system access among colleagues, while seemingly innocuous, can create significant security vulnerabilities. Such practices can facilitate unauthorized access, increase the risk of fraud, and make it difficult to trace the source of malicious activity.
To effectively combat insider threats, organizations should incorporate employee training program create awareness on financial crime looking at the human psychological element of previous fraud cases and use these scenarios as a learning point for employee to glean from.
Since social engineering also involved leveraging on human vulnerabilities – bias and psychological weaknesses, it is important that these are spotlighted in training and awareness. This will help employees in understanding various types of insider threats, their motivations, and the techniques they may use to perpetrate fraud. Recognize and resist social engineering attacks, such as pretexting and baiting which is often associated with insider threat. Reminded of importance of ethical behavior and conduct which include reporting suspicious activities observed.
Organizations must begin to evaluate the effectiveness of risk and security awareness programs not solely based on compliance but also on the improvement in staff awareness. This includes the ability to identify social engineering attempts, even those originating from colleagues, and the willingness to report suspicious activity through appropriate channels, such as whistleblower programs.
Technological Solution
- Process Re-engineering:
Many observed cases of social engineering in Nigeria financial sector exploit weaknesses in organizations’ separation of duties and ineffectual approval processes. It’s crucial to recognize that human behavior is complex and can change over time and thus a big risk for organizations to trust individuals blindly. To mitigate these risks and enhance fraud detection, organizations should implement robust approval processes for financial transactions, requiring multiple individuals to authorize expenses.
High-risk processes such as settlements, reconciliations, chargebacks, and financial record updates which are usual conduit for insider fraud should be monitored closely and have streamlined and automated approval process. A system or business workflow should be in place to ensure activities are tracked and logged and individual cannot move money or make expense decision without approval of many more individuals. Inherent risks within these processes should be assessed, and conflicting activities that could potentially lead to fraud should be identified and assigned to different individuals. This will help prevent overlap in responsibilities and provide valuable input for identity governance systems to monitor conflicting roles and flag potential security risks before they can manifest.
- Implement Identity and Access Management Solutions:
Beyond a streamlined process, organizations should implement a robust identity and access management systems to manage employee relationship and their access level throughout their lifecycle in the organization. The importance of Identity Governance System cannot be over emphasized. When the right solution that evaluate the uniqueness of organization and processes is properly implemented, it makes it possible for organization to automate access provisioning while ensuring individuals have just enough access to what they need to perform their job and streamline the access request process. This will create clear visibility into access levels and make it easier to model access risk.
Segregation of duty can also be implemented by policy while ensuring that potential conflicting accesses are flagged as risk for resolution. Privilege access use within the enterprise can be closely monitored, subjected to approval process, audited and recorded to prevent privilege exploitation. Implementing robust identity governance is will not only prevent likelihood of fraud but also makes it easy to overcover fraudulent activities early before they can become a problem.
Conclusion
Insider fraud poses a significant threat to organizations, their customers, and the national economy. A collaborative effort involving risk professionals, organizations, security agencies, and the government is essential to effectively address this challenge.
Organizations should actively share information about fraud incidents to strengthen collective security and encourage transparent reporting of fraudulent activities to regulatory authorities. By doing so, organizations can contribute to a more accurate understanding of the extent of the problem and facilitate the development of targeted countermeasures. Organizations should also seek not to be reactive but proactive in preventing fraud by implementing both human factor strategy and technological solutions that prevents fraud.
Risk professionals play a crucial role in identifying best practices, sharing knowledge, and advocating for robust security measures. By working closely with organizations and government agencies, risk professionals can help develop effective strategies to prevent, detect, and respond to insider fraud.
The establishment of a centralized debarring service is a critical step in mitigating insider threats. By maintaining a comprehensive database of individuals with a history of financial crime, organizations can make more informed hiring decisions and reduce the risk of employing individuals who pose a threat.
Finally, law enforcement agencies such as the EFCC, ICPC, and NPF should prioritize the submission of records of convicted financial criminals to the centralized debarring service. By sharing insights into emerging trends and tactics, these agencies can help organizations improve their security practices and stay ahead of evolving threats.
Ogundapo, an expert, wrote in from Lagos
Disclaimer
Comments expressed here do not reflect the opinions of Vanguard newspapers or any employee thereof.