What is insider sabotage?¶
The practical answer¶
Insider sabotage is deliberate activity by a person with legitimate or former access intended to damage systems, data, operations or trust.
The key evidential caution¶
The dangerous assumption is that every destructive act by an employee account was performed by a disgruntled employee.
It may not be.
The account may be compromised, shared or used after departure by another person.
Sabotage may involve:
Key points¶
- deleting data
- changing configuration
- disabling services
- destroying backups
- altering code
- locking accounts
- withholding credentials
- damaging equipment
- creating hidden access
- disrupting business processes
What investigators should establish¶
Investigators should establish:
Key points¶
- the action
- technical effect
- account and device
- authority
- timing
- communications
- motive or grievance evidence
- whether the action was concealed
- whether alternative technical causes exist
Intent should not be inferred solely from impact.
A mistaken command or failed deployment can cause severe harm.
Evidential limits¶
Likewise, an unsuccessful attempt may still show deliberate sabotage.
Preserve administrator logs, change records, communications, HR timelines, access termination records and system evidence.
Sabotage may be planned before departure or triggered after a dispute, disciplinary process or access change. Preserve the timeline without assuming that grievance proves intent. Communications and technical preparation may be more probative than the existence of workplace conflict alone.
Where credentials or access are retained after departure, sabotage may be carried out remotely and appear to originate from valid organisational accounts. Preserve offboarding, token revocation and device-return records so continued access and personal action can be assessed separately.
Operational takeaway¶
Link the destructive action, person, authority and intent, and distinguish sabotage from error, compromise and poorly controlled administration.