Most security controls are built to keep outsiders out. Insider risk is awkward precisely because it does not look like an intrusion: the account is real, the login is legitimate, and nothing trips an alarm designed to spot a stranger.
It is worth saying at the outset that the great majority of insider incidents are accidents. Somebody shares a folder more widely than they meant to, forwards a file to a personal address to work on at home, or approves a sign-in prompt while distracted. Treating your staff as suspects is both unpleasant and ineffective. The useful question is not who might do something wrong, but which mistakes your systems currently allow.
The four ways it usually shows up
Someone makes an honest mistake
By far the most common. A sharing link set to “anyone with the link” instead of named people. A spreadsheet emailed to a similar-looking address. A file copied to a personal device before a holiday. No intent, real exposure.
Someone leaves and takes something with them
Usually a contact list or a folder of their own work, taken in the belief that it is theirs. Occasionally more deliberate. Either way it tends to happen in the fortnight before a leaving date, which is a useful thing to know.
A supplier or contractor has more access than they need
Third parties frequently get access set up quickly during a project and never reviewed afterwards. The account outlives the engagement, and nobody owns it.
Someone else is using a real account
The most consequential of the four. Once an attacker has valid credentials they are, as far as your systems are concerned, a legitimate user. This is why compromised credentials sit behind so many breaches, and why the controls below lean heavily on identity.
What actually reduces it
Multi-factor authentication, without exceptions
The single most effective control against the fourth category, and the one most often undermined by exempting the people with the most access. If your directors are excluded, the control has a hole in exactly the wrong place.
Give people the access they need and no more
Most accounts accumulate permissions over years, as people change roles and nobody removes the old ones. Reviewing this periodically shrinks the damage any single account can do, deliberately or accidentally.
Make joiners and leavers a process, not a favour
Access should be granted on a defined day and removed on a defined day. Where that is handled ad hoc, leavers keep access for weeks, which is the gap that matters.
Watch for the unusual, not the individual
Monitoring should be about patterns, not surveillance: a sign-in from a country you do not operate in, a sudden large download, an account touching files it has never touched before. That is a very different thing from reading people’s email, and worth being clear about internally.
Make the safe thing the easy thing
Give people a business password manager so they are not reusing passwords. Set sharing defaults to named people rather than anyone with the link. Most accidental exposure comes from a default nobody chose, and defaults are much easier to change than habits.
Show people what to look for
Short, regular awareness training works better than an annual session, because the aim is familiarity rather than knowledge. Somebody who has seen a convincing prompt before is far more likely to pause at the real one.
And keep a way back
Not everything is preventable. Deleted or encrypted data is recoverable if your backup is independent and has actually been restored from. That is the control that decides how serious an insider incident turns out to be, whoever caused it and whether or not they meant to.
Where to start
Look at three things. Whether MFA genuinely covers everybody. Whether anyone still has access who left. And whether your sharing defaults are set to named people. Those three cover most of what we find, and none of them costs anything beyond the time to check.
If you would rather someone went through it with you, we are happy to look and tell you what we find.
