Managing the insider threat risk in customer service

By Jeff Schilling, CISO, TaskUs [ Join Cybersecurity Insiders ]
25

A blind spot for many B2C CISOs is the risk they accept in their customer service delivery. Many security teams are surprised by an unexpected, very public data breach or account takeover of a high-value customer caused by a malicious insider in the customer service department.  

Whether the customer service is managed by their internal teams or outsourced to a third party, the risks are the same. Like a water leak in a house that always finds the weak point, the threat actors recruiting insiders are innovative and will always find the weak point to exploit in customer service operations.  

Every security team should assume a customer service representative (CSR) will be successfully recruited by a threat actor to become an insider threat. Having more than 5 years experience as a BPO CISO, I have firsthand observations of how it happens. And the unfortunate truth is, it’s impossible to prevent entirely when you work at scale. If you design your customer service delivery with this assumption, you can manage the risk and achieve your business objectives. Below are the top three mistakes I see in customer service security, along with recommendations for how to get it right.

Mistake #1: Granting unlimited access to CRMs.

Many companies grant their CSRs continual access to the customer relations management (CRM) applications–even when not engaged on a call or text chat with a customer. This gives a malicious insider the opportunity to query customer records, looking for high-value targets to pass on to threat actors or making unauthorized transactions. Many companies manage this risk by monitoring CSRs’ transactions, looking for anomalous activities. While this is a good reactive strategy, this approach typically fails to catch the insider until after the damage is done.  

The best practice I have seen to prevent this malicious activity is to give the CSR access to the CRM only when actively engaged in a call or chat with the customer. This can be accomplished in two ways.  

  1. Linking the CRM application with your telephony solution through APIs that grant access only if a CSR is engaged with the client in a call/chat.  
  2. Often more effective is to design the CRM application such that it requires the customer to either approve access to their account through an SMS message link or provide an account PIN to the CSR during the call/chat.

Mistake #2: Sharing unnecessary customer information.

When CSRs are actively working on a customer case with a CRM, they’re often able to see more customer information than is strictly necessary. CRMs are often used for many different customer service use cases. Typically, profiles contain all the information known about a given customer, including payment methods and high-risk personal identifiable information (PII). Many B2C companies sometimes make the bad choice to just accept this risk rather than address it. 

Whether in the CRM application or through secure browser technology, there are many options available to obfuscate, tokenize and/or hide unnecessary PII based on the type of service being provided. RBAC can also make a big difference here. The bottom line is: CSRs don’t need to see everything to get their jobs done.

Mistake #3: Letting CSRs edit CRM data without customer consent.

Too often, CSRs are given the ability to change customer account information without the knowledge or approval of the customer. If a malicious CSR has the access necessary to change a payment method and provide refunds, they can architect an easy money-making machine for a threat actor. Another common use case involves CSRs changing a customer’s shipping address and using the account’s payment information to send valuable merchandise to an untraceable post office box. Many B2C companies rely on transaction monitoring to detect this criminal activity. But it’s often too late–by the time the activity has been detected, the insider has moved on and never shows up for work again.  

To preempt this fraud vector, companies can ensure customers are notified via SMS or email of any account information being changed.These notifications could also include links that give customers the ability to approve or disapprove the change.

Customer service is a threat vector hiding in plain sight  

Customer support is the predominant friction point many criminal gangs are attacking, especially in the digital currency and retail B2C space. Many of the biggest data breaches and largest fraud cases have come from business’ customer service functions. But too often, it’s overlooked as B2C security teams execute their company-wide strategies.  

Threat actors are increasingly working with malicious customer service insiders to achieve their goals, and they’re getting more sophisticated. B2C security teams can’t assume that customer service security is done after the service contract is signed. It requires continual engagement with the third party, threat monitoring and the execution of informed risk management strategies. Security teams need to scrutinize the latitude they give their CSRs and work under assumption that there will eventually be an insider threat. 

With the right protocols, you can continue to deliver white-glove service while protecting valuable customer data. That’s how you manage the pernicious risk posed by the insider threat.

 

Join our LinkedIn group Information Security Community!

No posts to display