Skip to content
Cyber Unboxed

Inside the organisation

Insider Threats

An insider threat comes from someone with legitimate access. It can be deliberate, but is more often a mistake, such as sending data to the wrong person or falling for a scam.

Motivation: Varies: financial gain, grievance, or, most often, honest error.

Overview

An insider is anyone who already has authorised access: an employee, contractor or partner. Insider threats are unusual because normal security, which is built to keep outsiders out, does not apply. The person is already inside.

Most insider incidents are accidents: a file shared with the wrong person, a laptop left on a train, a link clicked. A smaller number are deliberate, often linked to a grievance, financial pressure or a departure. A third category is an outsider using an insider's stolen account, which looks the same from the outside.

Because access is legitimate, the useful signals are changes in behaviour: unusual volumes, unusual hours, or access to data outside someone's role. The best programmes combine good access hygiene, fair and transparent monitoring, and a culture in which mistakes are reported quickly and without blame.

How it unfolds

  1. 1

    Legitimate access

    The person is trusted and allowed to reach the data.

  2. 2

    Trigger

    A mistake, pressure, grievance, or a compromised account.

  3. 3

    Action

    Data is exposed, copied out or misused.

  4. 4

    Detection

    Behaviour differs from that person's normal pattern.

  5. 5

    Response

    Access is limited, evidence preserved and the situation handled fairly.

Common techniques

  • Bulk downloads

    Large amounts of data copied or downloaded, often before someone leaves.

  • Personal storage and email

    Work data sent to personal accounts or devices.

  • Excess access

    Using permissions collected over the years that the role no longer needs.

  • Misdirected sharing

    Files sent or shared to the wrong person or made public by mistake.

  • Account misuse

    Shared or borrowed logins that make actions hard to attribute.

Who is targeted

  • Customer and personal data
  • Source code and product plans
  • Financial information
  • Systems with privileged access

An example

An employee about to leave downloads far more files than usual from a shared drive and copies them to a personal cloud account. The activity matches no current project, and a data-loss alert flags it to the security team, who speak with the person and their manager the next day.

An illustrative scenario, not a report of a specific incident.

What to look for

  • Access outside a person's usual pattern or role
  • Large downloads or transfers, especially before a departure
  • Use of personal storage for work data
  • Sharing settings that expose data publicly

How to defend

  1. Apply least privilege and review access regularly
  2. Remove access promptly when people change role or leave
  3. Use data-loss controls on the most sensitive data
  4. Monitor in a transparent, proportionate way, and tell staff how
  5. Make it safe to report mistakes quickly, without blame

Key terms

Least privilege
Only the minimum access needed to do a job.
DLP
Data loss prevention: controls that spot and stop sensitive data leaving.
Offboarding
The process of removing access when someone leaves.
Negligent insider
Someone who causes harm by accident or carelessness.

This is a general profile of a type of threat. It does not attribute any specific incident to any named group.

Go deeper on insider threats

Back to the Threat Atlas