Insider Risk: Deliberate and Negligent

Most insider risk is not malice but negligence. What signals to watch, and how to address it without building distrust.

Insider risk attracts a lot of misunderstanding. The imagined case is the vengeful employee stealing data; in reality most incidents stem from negligence: someone mails a file home, copies data to a personal cloud, or stays quiet after clicking a suspicious link.

Addressing it is therefore a question of process rather than surveillance.

Three types

Negligent. The most common. No intent to harm, merely an easier path: sending a document to a personal account, copying to USB, sharing a password with a colleague. Process and training prevent this, not monitoring.

Compromised. They are not acting; their account is being used. From outside it looks the same as a malicious insider, so detection is identical.

Deliberate. Rare, but the most damaging, because they know the systems and the controls. Typically before departure or after conflict.

What to watch

Events rather than people. The aim is not surveillance but noticing unusual patterns.

  • Large-volume downloads in a short window, particularly outside working hours
  • Access to data outside the person's role
  • Data movement to personal storage or webmail
  • Bulk copying to USB
  • A mailbox rule forwarding to an external address
  • Access requests for unusual systems

None of these proves anything alone. Context is what matters: someone who resigns and then bulk-downloads the customer list is a different case from someone doing their usual job.

The most important control is not technical: the leaver process. Revoking access on the day of departure, rotating service account passwords they knew, and recovering devices. This step is the one most often missing.

What not to do

Do not build blanket surveillance. Continuous monitoring of all employees is legally problematic, corrosive to trust, and does not work in practice because it floods the team.

Do not punish reporting. If someone says they clicked a suspicious link, thank them. If they are scolded, next time they stay quiet, and precisely the information enabling fastest response is lost.

Do not overlook the legal framework. Employee monitoring carries strict conditions: prior notice, proportionality, purpose limitation. This must also appear in the privacy notice.

What works

Least privilege. Whoever has no access cannot exfiltrate. Regular access review is the best prevention of insider risk.

Data classification. You must know what is sensitive and where it sits, otherwise its movement cannot be watched. We covered this in our data protection service.

Four-eyes principle for critical operations: payments, granting access, bulk data export.

Logging. Not for surveillance but for reconstruction. When something happens, you must be able to say what and when.

Handling the negligent case

Most internal incidents happen because the official route is cumbersome. If sending a large file is difficult, somebody will use a personal cloud. If the password manager does not work, passwords go on paper.

The most effective measure is therefore often not prohibition but providing a usable alternative. A ban with no working solution behind it merely hides the problem.

Our IT security services include access reviews and designing logging architecture.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.