Organizations are fixated on driving profits and staying competitive that they gobble up any tangible asset they can. Companies are more likely to begin a merger or acquisition first and worry about the insider threat risk later. Too many companies are using risk management as a substitute for solid internal security audits. Risk management is no substitute for good information security practices, authors say. Do not bypass building an information security program in favor of accepting or mitigating every risk that will rear its head, they say. Investigate the individuals that will most likely be assimilated into the new environment and never assume that were routine background checks were done.”]

