Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is insider misuse?

Insider misuse is improper or harmful use of access by someone with a current or former legitimate organisational relationship. It includes deliberate, reckless and accidental conduct and is not synonymous with employee data theft.

Establish the authority boundary

Define the person's employment, contractor, supplier or volunteer relationship, technical access, duties and authority at the time. Then identify the action, affected system or data, and how it exceeded that authority.

Legitimate access can make activity appear routine, but unusual employee activity may also reflect mistake, undocumented work or a compromised account.

Prove personal action and intent separately

Use session, device, access-control, file, communication, approval, policy and witness evidence. Determine whether another person, remote controller or automation could have used the account or device.

Intentional theft, curiosity, policy breach, careless disclosure and coercion require different conclusions. State technical action, authority breach, personal responsibility and mental state only at their supported levels.

Key takeaway

Define the insider's legitimate relationship and authority, then prove the exceeded action, personal control and intent as separate findings.

Reference: CIM-231Cyber Incidents & Offender Methods