Simply implementing best practices is not enough to address the risk coming from your own employees.
Source: Threadpost