Insider Threat Research Group mark: a squared plate rule

INSIDER THREAT RESEARCH GROUP

The CISO Guide to Managing Insider Threats

Manual home / Contents / Chapter 03

Chapter 03 · Foundations

Warning signs and what they are worth

Written for teams assembling a list of things worth looking into, and for anyone being asked to justify why such a list is not a scoring system.

Read this before the lists

Important

The observations below are reasons to look, not findings. Each of them describes far more people who will never do anything than people who will. Used as a checklist against individuals, they produce a queue of innocent colleagues and a programme that loses the confidence it depends on. Nothing here is a screening instrument, and none of it supports a judgement about a person's state of mind.

Technical observations

  • Collection that does not match the work: bulk reads across repositories the person's role touches individually but rarely in aggregate.
  • A change in the shape of routine activity rather than its type — the same export, an order of magnitude larger.
  • Access to systems the person retains rights to but has not used since a role change.
  • Activity that avoids a control rather than failing it: work moved to an unmonitored path when the monitored one remains available.
  • Privileged actions taken outside change control, particularly against logging, backup or alerting.
  • Credential sharing, including the benign kind, which removes attribution from everything that follows.

Every one of these has an ordinary explanation that is more likely than the alarming one. Their value is comparative: they are worth attention when they are new for that person and that role, which means the programme needs a sense of normal before it can have a sense of unusual.

Situational context

Situational factors are properly used to decide where controls should be tightest, not to grade individuals. A resignation is not evidence of anything; it is a reason to apply the leaver procedure properly. A restructure is not evidence of anything; it is a reason to check that access followed people's new roles rather than accumulating alongside them.

  1. Announced departures, including internal moves.
  2. Periods of organisational change, when access review lags reality.
  3. Contract endings, where withdrawal is owned by a supplier rather than by the organisation.
  4. Long-standing accumulated access in people who have held several roles.

Managing the cost of looking

Every observation costs something to investigate, and the cost is not only analyst time. Being looked into is visible to colleagues and is remembered. A programme that generates many enquiries will find that the next genuine concern arrives later, because people have learned that raising one has consequences for the person named.

The practical control is a threshold agreed in advance and written down: which combinations justify a look, who authorises it, and what the person is told and when. Chapter 4 covers where that decision sits.