end user computing sheffield

Insider Threats

The hardest activity to spot comes from accounts that are supposed to be there. How insider risk shows up, and what detects it.

Most security controls are built to keep outsiders out. Insider risk is awkward precisely because it does not look like an intrusion: the account is real, the login is legitimate, and nothing trips an alarm designed to spot a stranger.

It is worth saying at the outset that the great majority of insider incidents are accidents. Somebody shares a folder more widely than they meant to, forwards a file to a personal address to work on at home, or approves a sign-in prompt while distracted. Treating your staff as suspects is both unpleasant and ineffective. The useful question is not who might do something wrong, but which mistakes your systems currently allow.

The four ways it usually shows up

Someone makes an honest mistake

By far the most common. A sharing link set to “anyone with the link” instead of named people. A spreadsheet emailed to a similar-looking address. A file copied to a personal device before a holiday. No intent, real exposure.

Someone leaves and takes something with them

Usually a contact list or a folder of their own work, taken in the belief that it is theirs. Occasionally more deliberate. Either way it tends to happen in the fortnight before a leaving date, which is a useful thing to know.

A supplier or contractor has more access than they need

Third parties frequently get access set up quickly during a project and never reviewed afterwards. The account outlives the engagement, and nobody owns it.

Someone else is using a real account

The most consequential of the four. Once an attacker has valid credentials they are, as far as your systems are concerned, a legitimate user. This is why compromised credentials sit behind so many breaches, and why the controls below lean heavily on identity.

What actually reduces it

Multi-factor authentication, without exceptions

The single most effective control against the fourth category, and the one most often undermined by exempting the people with the most access. If your directors are excluded, the control has a hole in exactly the wrong place.

Give people the access they need and no more

Most accounts accumulate permissions over years, as people change roles and nobody removes the old ones. Reviewing this periodically shrinks the damage any single account can do, deliberately or accidentally.

Make joiners and leavers a process, not a favour

Access should be granted on a defined day and removed on a defined day. Where that is handled ad hoc, leavers keep access for weeks, which is the gap that matters.

Watch for the unusual, not the individual

Monitoring should be about patterns, not surveillance: a sign-in from a country you do not operate in, a sudden large download, an account touching files it has never touched before. That is a very different thing from reading people’s email, and worth being clear about internally.

Make the safe thing the easy thing

Give people a business password manager so they are not reusing passwords. Set sharing defaults to named people rather than anyone with the link. Most accidental exposure comes from a default nobody chose, and defaults are much easier to change than habits.

Show people what to look for

Short, regular awareness training works better than an annual session, because the aim is familiarity rather than knowledge. Somebody who has seen a convincing prompt before is far more likely to pause at the real one.

And keep a way back

Not everything is preventable. Deleted or encrypted data is recoverable if your backup is independent and has actually been restored from. That is the control that decides how serious an insider incident turns out to be, whoever caused it and whether or not they meant to.

Where to start

Look at three things. Whether MFA genuinely covers everybody. Whether anyone still has access who left. And whether your sharing defaults are set to named people. Those three cover most of what we find, and none of them costs anything beyond the time to check.

If you would rather someone went through it with you, we are happy to look and tell you what we find.

Next step

Have a look at your setup with us

Thirty minutes, no obligation, and no scripted sales call. You'll come away knowing where you stand, whether or not you work with us.

Book a 30-minute review →