Skip to content
CIM-238 Cyber Incidents & Offender Methods

What is insider sabotage?

The practical answer

Insider sabotage is deliberate activity by a person with legitimate or former access intended to damage systems, data, operations or trust.

The key evidential caution

The dangerous assumption is that every destructive act by an employee account was performed by a disgruntled employee.

It may not be.

The account may be compromised, shared or used after departure by another person.

Sabotage may involve:

Key points

  • deleting data
  • changing configuration
  • disabling services
  • destroying backups
  • altering code
  • locking accounts
  • withholding credentials
  • damaging equipment
  • creating hidden access
  • disrupting business processes

What investigators should establish

Investigators should establish:

Key points

  • the action
  • technical effect
  • account and device
  • authority
  • timing
  • communications
  • motive or grievance evidence
  • whether the action was concealed
  • whether alternative technical causes exist

Intent should not be inferred solely from impact.

A mistaken command or failed deployment can cause severe harm.

Evidential limits

Likewise, an unsuccessful attempt may still show deliberate sabotage.

Preserve administrator logs, change records, communications, HR timelines, access termination records and system evidence.

Sabotage may be planned before departure or triggered after a dispute, disciplinary process or access change. Preserve the timeline without assuming that grievance proves intent. Communications and technical preparation may be more probative than the existence of workplace conflict alone.

Where credentials or access are retained after departure, sabotage may be carried out remotely and appear to originate from valid organisational accounts. Preserve offboarding, token revocation and device-return records so continued access and personal action can be assessed separately.

Operational takeaway

Link the destructive action, person, authority and intent, and distinguish sabotage from error, compromise and poorly controlled administration.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.