If a network is attacked from within (i.e. with involvement by company staff), the attack will succeed much more frequently than an attack from outside. It’s difficult to guard against attacks from within: one good precautionary measure is to make sensitive data accessible only to employees who really need these data. In order to avoid unintentional attacks from within, e.g. due to mistakes caused by ignorance, good staff training is recommended, plus formulating clear rules for handling data. If something happens nevertheless, your data back-ups are your most important aid.