What is insider misuse?¶
The practical answer¶
Insider misuse is the unauthorised, improper or harmful use of access by someone who has, or previously had, a legitimate relationship with the organisation.
The key evidential caution¶
The dangerous assumption is that insider misuse always means a malicious employee deliberately stealing data.
It may involve:
Key points¶
- deliberate theft
- fraud
- sabotage
- unauthorised curiosity
- policy breach
- careless disclosure
- misuse of privileged access
- coercion
- account sharing
- activity by a former employee or contractor
What investigators should establish¶
Investigators should establish:
Key points¶
- what access the person legitimately had
- what action occurred
- whether the action exceeded that authority
- what data or system was affected
- what motive or explanation is supported
- whether another person could have used the account or device
Legitimate access can make activity appear normal.
That does not make every action authorised.
Equally, an unusual action by an employee is not automatically malicious.
The account may be compromised, the instruction may be mistaken, or the person may be carrying out an undocumented business task.
Relevant evidence¶
Relevant evidence may include account and session logs, access-control records, file activity, communications, approval records, policy, role information, device evidence and witness accounts.
Insider misuse may be intentional, reckless or accidental.
Those distinctions matter for attribution, harm and organisational response.
The relationship to the organisation also matters. Employees, contractors, suppliers, volunteers and former staff may each have different access, duties and records. Preserve the relevant employment or contractual context so technical activity is assessed against the authority that actually existed at the time.
Operational takeaway¶
Define the person’s legitimate access, identify the action that exceeded or misused it and prove intent and personal responsibility separately from account activity.