Insider Threat
An insider threat comes from individuals with legitimate access who misuse it, either intentionally or negligently.
An insider threat originates from people with legitimate access to an organisation. These can be employees, former employees, service providers, or partners.
How it works
A distinction is made between malicious and unintentional insiders. Malicious insiders steal data, sabotage systems, or assist external attackers. This is often due to financial motives or dissatisfaction. Unintentional insiders cause damage through mistakes, for example by sending confidential data to the wrong recipients. An insider's account can also be compromised by an external attacker. The resulting behaviour can look very similar.
Here is a practical example: a sales manager resigns to join a competitor. In their last two weeks, they download unusual amounts of customer data. The behavioural analysis system reports this deviation. The SOC informs the designated contact according to the agreed process. This person then decides on the next steps.
What to look out for
- Revoke access rights immediately and completely when someone leaves. This includes cloud services.
- Grant permissions based on the principle of least privilege.
- Define beforehand who is informed in a suspected case. This usually includes HR, legal, and management.
- Pay close attention during sensitive periods like resignations or restructurings.
- Treat suspected cases confidentially. A false accusation can cause significant damage.
Switzerland and regulation
Employee monitoring in Switzerland is strictly limited. Under Art. 26 ArGV 3, surveillance systems are not permitted if their primary goal is to monitor employee behaviour. Security monitoring is possible if it serves another purpose. It must also be proportionate, and employees must be informed. A clear policy on the use of IT resources is important.
Detection
Insiders use legitimate access. Classic rules therefore rarely detect them. Behavioural analysis, DLP, and monitoring unusual data access are more helpful.
Typical mistakes
Accounts often remain active after an employee's departure. This is common for cloud services and external platforms. A second mistake is the lack of a defined process for suspected cases. IT may then act alone, without involving HR and legal departments.
How we implement it
We detect unusual access and data movements and report them according to the agreed process. You make any decisions regarding personnel yourself.