Insider threats are risks from people with legitimate access: employees, contractors, partners. The spectrum ranges from the negligent insider (misdirected mail, bypassed rules, phishing victim) via the malicious one (data theft on departure, sabotage) to the compromised one — whose account an external attacker has taken over.
The insidious part: insiders do not breach a perimeter — they are already inside. Classic outward defence does not see them; you need controls that also question legitimate access.
The three insider types and their patterns
The negligent insider causes most incidents — not by intent but through convenience and mistakes. The malicious one acts deliberately, often in the context of resignation or conflict; typical are unusual mass downloads and private cloud drops shortly before departure. The compromised insider is formally external: stolen credentials make the attacker look like a colleague.
The defence is similar for all three: least privilege limits what an account can reach at all; offboarding revokes rights on the last day, not weeks later; behavioural signals — atypical access, volumes, times — make abuse visible, whether the person or their stolen account is acting.
Effective controls against insiders
- Least privilege and recertification: nobody keeps rights in reserve.
- Consistent offboarding — including contractor and technical accounts.
- DLP and egress monitoring on the paths to the outside.
- Four-eyes principle for critical actions instead of solo runs.