Polymer

Download free DLP for AI whitepaper

Summary

  • Coinbase lost $400M in a breach after attackers bribed third-party customer service agents.
  • Support teams often have full access to your most sensitive data.
  • Between bribery and AI data leakage, customer support is a considerable risk to data security.
  • Most orgs treat third-party risk as a compliance checkbox. That’s not enough anymore.
  • Discover a 9-step guide that shows how to build a dynamic, data-first strategy to prevent insider leaks.

On May 15, the crypto giant, Coinbase, announced that malicious actors had gotten away with the personal information of tens of thousands of customers—an incident set to cost the company nearly $400 million. 

But the scale of this breach isn’t the major story. It’s how the cybercriminals did it—bribing outsourced customer service agents to steal sensitive data on their behalf.  

What’s stopping the same thing from happening at your company? With 83% of organizations experiencing insider threats in 2024, one of the biggest risks to your data security could come from inside: from employees and third-parties that have legitimate access to your sensitive data. 

Here’s how to make sure it doesn’t. 

Outsourced support teams: The silent insider threat 

Outsourced customer support has become a de facto standard in modern business. From fintech to healthcare to ecommerce, over 55% of companies worldwide rely on third-party teams to handle customer queries. 

But this convenience comes with a hidden cost: these third-party agents often have extensive access to sensitive data. The result is two troubling types of insider threats: malicious ones (like in the Coinbase breach) and accidental insiders. 

Let’s take a look. 

Malicious insiders 

In cloud-first, SaaS-heavy environments, support agents can log in from anywhere in the world, with nothing more than a browser and a password between them and customer data.

In many cases, support staff aren’t just reading names and email addresses—they’re accessing financial details, health records, internal tickets, and full account histories.

That level of access, combined with minimal oversight, is precisely what made the Coinbase breach possible. Attackers didn’t breach a firewall or exploit zero-day vulnerabilities. They found a simpler path: paying off overseas customer support agents who already had full access to customer data. 

Accidental insiders 

Bribery and bad actors are a serious concern. But many insider threats come from well-meaning employees under pressure to work fast.

Support agents, racing to meet SLAs and handle high ticket volumes, often use AI tools like ChatGPT or Bard to draft replies. In doing so, they may copy-paste sensitive data into tools that are not enterprise-governed—or even secure.

For example, say a support rep pastes a customer’s full billing info into ChatGPT for help writing a professional response. Two months later, a completely different user receives an AI-generated message—containing details from that same billing record.

Because large language models can retain and unintentionally surface user inputs, a simple copy-paste can create a slow-burning breach that causes a blaze far down the line.

Third-party risk management: 9 steps to close the gap

As support operations swell across time zones, platforms, and third parties, the old model of vendor risk management is no longer enough.

It’s time for a dynamic, data-first approach—starting with these nine steps.

1. Inventory all vendors 

Document every third party with access to your systems or data—SaaS tools, contractors, consultants, MSPs, and one-off integrations. No access should go untracked.

2. Assign internal ownership 

Designate a clear internal owner (IT, security, procurement, or legal) for each vendor. They’re responsible for ongoing risk reviews, access decisions, and lifecycle management.

3. Tier vendors by risk level 

Group vendors into risk tiers based on:

  • Level of data/system access
  • Sensitivity of data handled
  • Criticality to business operations
    Focus resources on high-risk vendors first.

4. Standardize onboarding 

No vendor should be onboarded without a formal risk check. Require:

  • Completed security questionnaires
  • Review of SOC 2, ISO 27001, or similar certs
  • Privacy policy and DPA review
  • Internal sign-off in the procurement process

5. Embed security into contracts 

Include security obligations in contracts and DPAs:

  • Required response times for incidents
  • Clear breach notification requirements
  • Audit rights and compliance expectations
  • Make accountability enforceable

6. Monitor vendor activity continuously 

Static reviews aren’t enough. Implement tools for real-time visibility, including:

  • Alerts for vendor security incidents or data access anomalies
  • Human risk management technology in generative AI and collaboration tools 
  • Runtime security protection in collaboration platforms to flag oversharing and unauthorized access

7. Manage the full vendor lifecycle

  • Quarterly: review access and adjust as needed
  • Annually: reassess risk, update contracts
  • End of engagement: revoke access, retain records, document offboarding
    Ensure workflows and responsibilities are clearly defined.

8. Integrate vendors into your incident response plan 

Your IR plan should detail:

  • Vendor communication protocols
  • Escalation paths and timelines
  • Breach disclosure responsibilities
    Review and test the plan regularly.

9. Enable auditability and reporting 

Track and document:

  • Current vendor list with access levels
  • Risk tier and review dates
  • Onboarding and offboarding actions
    This supports compliance and keeps leadership informed.

Real-time defense against insider threats

Visibility is the foundation of effective third-party risk management. It’s how you verify vendors are meeting security commitments and catch insider threats before they escalate.

That’s where Polymer comes in. Our runtime security solution gives you real-time visibility into what support agents are doing across platforms like Zendesk, Microsoft Teams, and ChatGPT. It offers:

  • In-the-moment nudges to prevent oversharing
  • Adaptive access controls
  • Human risk management across AI and collaboration tools
  • 24/7 monitoring and automated remediation

Don’t wait until it’s too late. Discover how Polymer can give you the visibility and control you need to protect your business from insider threats. Request a demo today.

Polymer is a human-centric data loss prevention (DLP) platform that holistically reduces the risk of data exposure in your SaaS apps and AI tools. In addition to automatically detecting and remediating violations, Polymer coaches your employees to become better data stewards. Try Polymer for free.

SHARE

Get Polymer blog posts delivered to your inbox.

thor311 tajen bali

thor311 alternatif

situs toto4d

thor311 toto4d

thor311 akses

ceri188

KUPU178

daftar ceri188

cery188

ceri188

KUPU178

KUPU178

slot gacor

kupu 178

kupu178

ceri1888

ceri188

slot online

hoki311

togel online

ceri188

ding dong

ratu311

slot gacor

kupu178

live casino

kupu178

RATU311

RATU311

RATU311

mix parlay

ceri188

judi bola online

thor311 slot

RATU311

RATU311

HOKI311

HOKI311

THOR311

RATU311

RATU311

RATU311

RATU311

KUPU178

THOR311

THOR311

ceri188

ratu311

slot online

hoki311

kupu178

togel online

kupu178

slot gacor

ceri188

judi bola online

ceri188

ratu311

kupu178

RATU311

RATU311

live casino roullete

ceri188

slot pg soft

kupu178

KUPU178

KUPU178

THOR311

THOR311

THOR311

THOR311

RATU311

KUPU178

KUPU178

THOR311

THOR311

THOR311

RATU311

thor311 domino qq

thor311 akses

thor dingdong

THOR311

ceri188

ceri188

KUPU178

RATU311

RATU311

kupu178

kupu178

HOKI311

togel

kupu178

mix parlay

ceri188

slot online

kupu178

THOR311

THOR311

KUPU178

KUPU178

kupu178

hoki311

togel online

kupu178

ceri188

ceri188

www.vrcorporate.in

phbalance.vn

togel hongkong

kupu178

slot gacor

kupu178

kupu178

ceri188

kupu178

RATU311

RATU311

KUPU178

RATU311

RATU311

slot online

kupu178

THOR311

KUPU178

slot mahjong ways

hoki311

slot gacor

ceri188

kupu178

Casino Baccarat Online

kupu178

kupu178

ceri188

toto macau

KUPU178

Slot Gacor

KUPU178

RATU311

Mahjong ways

KUPU178

THOR311

RATU311

RATU311

RATU311

RATU311

KUPU178

KUPU178

RATU311

RATU311

RATU311

Toto Togel

KUPU178

CERI188

Slot Sweet Bonanza 2500

KUPU178

RATU311

RATU311

KUPU178 X SLOT777

judi bola online

THOR311

KUPU178 SLOT TERPERCAYA

KUPU178 TOGEL

TOTO 4D MACAU

KUPU178

KUPU178

RATU311

THOR311

HOKI311

KUPU178

RATU311

Slot Mahjong Ways

KUPU178

CERI188

Slot Online Resmi

KUPU178

RATU311 SLOT ONLINE

KUPU178

KUPU178: Link Akses Resmi

KUPU178: Strategi Menang Di Game Live Casino

KUPU178

KUPU178: Minimal 200 Rupiah

THOR311

THOR311

THOR311

THOR311

THOR311

KUPU178

Slot Thailand

CERI188

CERI188

THOR311 RTP

RATU311

RATU311

CERI188

KUPU178 TOTO SLOT

CERI188 TOTO Singapore

THOR311

CERI188

RATU311: Alternatif karnpuracollege

RATU311

Thor311 Terbaru

THOR311 MAHJONG

RATU311: BONUS SABUNG AYAM

CERI188: Masuk Akun Slot Super Cepat

CERI188

CERI188

THOR311

HOKI311

HOKI311

RATU311

HOKI311

KUPU178

RATU311

RATU311

RATU311

THOR311

CERI188

CERI188

RATU311

RATU311

RATU311

Game Thor311

HOKI311

HOKI311

RATU311

HOKI311

HOKI311

THOR311

RATU311 NONTON BOLA

HOKI311 Link QRIS EWALLET

RATU311

HOKI311 Link Apk Resmi

CERI188

RATU311 judi bola

KUPU178

HOKI311

RATU311

THOR311

HOKI311

KUPU178

KUPU178

KUPU178

RATU311

RATU311

KUPU178

THOR311

KUPU178

RATU311

THOR311