Get in touch
Data protection

Insider risk: the threat already inside

Published:

Most businesses invest significant sums in firewalls, antivirus, threat detection systems and cybersecurity services. Yet one of the biggest threats is not outside the organisation. It is already inside it.

So-called insider risk is the risk that comes from employees, partners or people with legitimate access to a company's systems and data. It is not always malicious. It can result from negligence, a mistake or a breach of procedure. But when the action is deliberate, the consequences can be devastating.

The scenario nobody wants to live through

The example that follows is hypothetical.

John had worked for more than seven years at a mid-sized trading company. As a sales executive he had access to customer lists, financial reports, contracts, quotation files and strategy documents. At some point he decided to leave to work for a competitor.

In his last days before leaving, nothing seemed unusual. He kept working normally, attending meetings and handling his daily duties. Two days before handing in his company equipment, he plugged a USB stick into his computer. Within a few hours he copied more than 10,000 files.

The folders that were moved held customer lists, quotation files, communication histories, commercial agreements, strategy presentations and internal market analyses. The action went unnoticed. No system alerted the IT department. No alert was created. Nobody knew that an employee, a few hours before leaving, had moved a huge volume of company data out of the organisation.

The truth came out months later, when the competitor began approaching customers with strikingly targeted offers. Only then did the investigation start. The problem was that it was now too late.

Why traditional solutions are not enough

Most security solutions are designed to detect external attacks. When a user has valid access rights, however, their behaviour can look normal. Downloading thousands of files, copying them to removable media, sending them to a personal email or moving them to cloud services is often not treated as a clear threat by traditional security tools.

This is exactly where the need for specialised insider risk management solutions appears.

How Microsoft Purview Insider Risk Management helps

Microsoft Purview Insider Risk Management is designed to detect behaviour that may indicate data leakage or other breaches of security policy. Using signals from Microsoft 365, endpoint devices and user activity, it can recognise events such as:

  • Mass copying of files to USB devices.
  • Moving company data to personal cloud accounts.
  • Unusual downloading or deletion of large volumes of files.
  • Access to sensitive data shortly before an employee leaves.
  • Sharing confidential information outside the organisation.

In John's example, Purview could detect that a user in the process of leaving carried out an unusually large export of data to a USB device, and create an alert for the security team to investigate further.

What it takes to work

Insider Risk Management is not switched on with a single button. According to Microsoft's documentation, before deployment you need:

  • A suitable Microsoft 365 licence. Microsoft gives the Microsoft 365 Enterprise E5 plan as an example.
  • For the departing-users template: a connection to HR data (resignation or end dates) or a setting that starts scoring when the account is deleted in Microsoft Entra.
  • For indicators such as copying to USB: enabling device indicators and onboarding the devices.
  • Planning with IT, compliance, privacy, security, human resources and legal, especially for the personal data protection requirements of each country.

Microsoft notes that the solution is built with privacy in mind: users appear pseudonymised by default to analysts and investigators, and there are role controls and audit logs. It also recommends testing with a small group of users before wider rollout.

Prevention matters more than recovery

The cost of a data leak is not limited to the loss of information. It includes lost customers, legal consequences, damage to the company's reputation and reduced competitiveness. Organisations that invest only in protection against external threats often ignore one of the most important risks: the person who already has access to the data.

Effective security needs visibility both outwards and inwards. And in a world where data is a business's most valuable asset, the ability to spot suspicious actions early can make the difference between an incident that is prevented and a crisis that costs millions.

How ITHACA can help

ITHACA helps organisations implement Data Loss Prevention (DLP) solutions and in particular Microsoft Purview, to protect sensitive data, comply with regulatory frameworks and detect insider risks early. If you want to see how Microsoft Purview can protect your organisation from data leaks and insider risk incidents, get in touch.

Frequently asked questions

What is insider risk?

It is the risk that comes from employees, partners or people with legitimate access to a company's systems and data. It can result from a malicious act, but also from negligence, a mistake or a breach of procedure.

Are antivirus and a firewall not enough?

Most security solutions were designed for external attacks. When a user has valid rights, mass copying of files can look normal, which is why tools that examine behaviour are needed.

What is needed to deploy Purview Insider Risk Management?

A suitable Microsoft 365 licence, configuration of the templates (for example a connection to HR data for departing users), onboarding of devices for indicators such as USB, and planning with the IT, privacy, HR and legal teams.

Does the security team see employees' names?

According to Microsoft, users appear pseudonymised by default to analysts and investigators. Settings and use should be planned with human resources and legal, to respect employee privacy.