Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Three Years Since Snowden – Lessons We Still Haven’t Learned current page
Link copied

Three Years Since Snowden – Lessons We Still Haven’t Learned

Aug 30, 2016
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
Three Years Since Snowden – Lessons We Still Haven’t Learned
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Snowden lessons not learned

It’s been more than three years since Edward Snowden perpetrated the largest leak of classified information in United States history. With the movie coming out soon, it’s a good time to remind everyone about how the techniques he used for hacking, copying and storing volumes of critical information – and especially his use of privileged credentials – demonstrated weaknesses in cybersecurity protection. Once obtained, and used inappropriately, the story of his insider threat espionage proved we were not doing enough to protect users, accounts, and credentials.

Ready to take the next step in assessing your organization’s risk of a Snowden-style crime? Download our 2016 definitive Privilege Access Benchmarking Study today.

Or should I say, we are not doing enough? It’s surprising how little has changed three years on.

To understand how widespread the insider threat is, BeyondTrust has embarked on several privilege studies throughout the past few years to capture the risk of privileges by industry. For 2016, the definitive BeyondTrust Privilege Benchmark Study has revealed that the threat is still very real and that the disparity in maturity is staggering.

Statistics from the survey reveal fragmentation around the potential threat they face by maturity of the vertical (low end verses high end tiers as described in the complete survey).

Snowden lessons learned

Why is this still the case?

Highly regulated environments such as financial and healthcare fall into the high end tier but manufacturing and others just do not have the drive to solve this problem without a compelling event such as regulation, outage, or breach. What is more curious is that government entities should fall into the high end but prove that a true insider threat, with malicious intent, is still possible without the proper checks and balances, audits and reporting, and overall access accountability. Snowden proved that unmonitored access, even with his or someone else’s account, when left unchecked can cause a great deal of damage.

Where do we go from here?

His insider knowledge, coupled with unmonitored security controls, allowed Snowden to have privileged access to sensitive information that he leaked. The simple facts are that he:

  • Hacked his own place of employment
  • Leveraged unmonitored privileged access to copy and exfiltrate sensitive information
  • Used the information to cause significant damage

These three facts could happen to any other organization or business. The BeyondTrust Privileged Access Benchmark Study proves that most organizations are still not maintaining privileges well, are not monitoring when those credentials are used, and not considering the threats of other users knowing account credentials. All three the basic points Snowden used.

It is time we consider the threats from inside.

Here are five quick steps to improve the maturity of your privileged access management strategy using the guidance from the best PAM practitioners:

  1. Be granular: Implement granular least privilege policies to elevate applications, not users.
  2. Know the risk: Never elevate an application’s privileges without knowing if there are known vulnerabilities.
  3. Augment technology with process: Reinforce enterprise password management hygiene with policy and an overall solution. As the first line of defense, establish a policy that requires regular password rotation and centralizes the credential management process.
  4. Take immediate action: Real-time monitoring and termination capabilities are vital to mitigating a data breach as it happens, rather than simply investigating after the incident.
  5. Close the gap: Integrate solutions across deployments to reduce cost and complexity, and improve results. Avoid point products that don’t scale. Look for broad solutions that span multiple environments and integrate with other security systems, leaving fewer gaps.

Ready to take the next step in assessing your organization’s risk of a Snowden-style crime? Download our 2016 definitive Privilege Access Benchmarking Study today.

Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • December 2018 Patch Tuesday
    Dec 14, 2018 December 2018 Patch Tuesday
    Blog
    1m
  • Cyber Attack on Water Treatment Plant a Wake-Up Call to Harden Remote Access Security
    Feb 10, 2021 Cyber Attack on Water Treatment Plant a Wake-Up Call to Harden Remote Access Security
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.