Insider Threat
Definition
An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence (misconfiguration, misdirected email). Insider incidents require different evidentiary handling than external intrusions.
- Source
- A person with legitimate access to the organisation
- Types
- Malicious (theft, sabotage) or negligent (misconfiguration, misdirected data)
- Field
- Incident response and information security
- Handling
- Requires different evidentiary approach than external intrusions
Common questions
Why does an insider incident need different evidence handling than an external attack?+
The suspect already has legitimate credentials and normal-looking access patterns, so investigators must establish intent and distinguish authorised activity from misuse, often relying on HR records, access logs, and behavioural baselines rather than the network perimeter evidence typical of external intrusions.
Are negligent insider incidents as damaging as malicious ones?+
They can be. A misconfigured cloud storage bucket or a misdirected email containing sensitive data can expose as much information as a deliberate theft, and negligent incidents are statistically more common in many organisations than malicious insider activity.
Related terms
- Advanced Persistent Threat (APT)
- A category of attacker, typically nation-state or state-sponsored, characterised by high technical capability, long dwell times, specific targets, and disciplined operational security....
- Alert
- A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent...
- Data Breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Ransomware
- Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted...
- Security Event
- Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast...
- Security Incident
- An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information...
- Threat Actor
- An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...
- Threat Intelligence
- Processed, analysed information about adversaries, their capabilities, and their current or anticipated activities. Includes strategic intelligence (actor motivations and trends) and tactical...
- Threat Vector
- The pathway or method a threat actor uses to gain access or cause harm. Examples include phishing email, unpatched software vulnerabilities, compromised...
Explained in these topics
- The Threat Landscape and Threat ActorsA security risk originating from within the organisation, including current or former employees, contractors, and business partners who have or had authorised...
- What Is a Security Incident