Insider threat programmes often begin with the wrong mental image: a hostile employee deliberately exfiltrating intellectual property. That case exists and is serious, but it is the least common of three categories, and building a programme around it produces surveillance that damages trust while missing most actual incidents.
Three genuinely different problems
- Negligent insiders — the largest category by volume. Data sent to the wrong recipient, a sensitive file shared with an over-broad link, credentials reused, a laptop lost. No intent to cause harm.
- Malicious insiders — deliberate theft, sabotage or fraud, usually motivated by financial gain, grievance or an imminent departure to a competitor. Rare but potentially severe, and difficult to detect because the access used is legitimate.
- Compromised insiders — an external attacker operating with a genuine employee's credentials. Technically an external intrusion, but behaviourally identical to an insider, which is why identity monitoring belongs in this discussion.
Why detection is hard
Insiders use access they are supposed to have, on systems they are supposed to use, at times they are supposed to be working. Nothing is technically anomalous.
Detection therefore depends on behavioural context rather than rule violation — comparing activity against what is normal for that person and role. That makes false positives more likely and makes proportionality essential, because the same techniques that spot exfiltration can easily drift into intrusive monitoring of ordinary work.
Signals worth monitoring
- Bulk access or download of records well outside a role's normal pattern, particularly from repositories the person rarely touches.
- Access to systems unrelated to current work, especially shortly after a resignation is submitted.
- Large transfers to personal cloud storage, personal email or removable media.
- Repeated authorisation failures, which can indicate someone probing the edges of their permissions.
- Sharing links set to broad or public access on sensitive repositories.
- Privileged actions taken outside normal working patterns, correlated with location and device.
- Mailbox forwarding rules created to external addresses.
Prevention beats detection
Most insider risk is reduced structurally rather than by watching people.
- Least privilege, reviewed. Access accumulates as people change roles; periodic review with a named owner removes what is no longer needed.
- Reliable offboarding. Departure should revoke access everywhere on the same day, including SaaS tools outside central identity management, which is where orphaned access hides.
- Separation of duties so no single person can complete a sensitive transaction unchecked.
- Sensible defaults — sharing that defaults to restricted rather than open prevents a large share of negligent exposure with no monitoring at all.
- Make the safe path easy. People route around controls that obstruct their work; if approved file transfer is painful, personal cloud storage fills the gap.
- Practical training aimed at the common mistakes rather than at the rare malicious case.
Proportionality and privacy
Insider monitoring touches employment law, privacy regulation and works-council obligations in many jurisdictions, and requirements differ significantly by country. Programmes are frequently designed technically and only later discover they are not lawful where staff are based.
Involve legal and HR before deployment, be transparent about what is monitored and why, restrict access to the monitoring data itself, and set retention deliberately. A programme perceived as surveillance damages the culture that makes people report their own mistakes — and self-reporting catches far more than any tool.
Related from TechBiz Security
Sources & further reading
- CISA — Insider Threat Mitigation
- CISA — Insider Threat Mitigation Guide
- NIST SP 800-53 — Security and Privacy Controls
- MITRE ATT&CK
0 comments
Leave a comment