Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What is unauthorised data access by an insider?

This occurs when a person with available access views information outside their permitted or necessary purpose. One opened record may result from preview, mistaken selection, reassignment or legitimate support and does not automatically prove deliberate misuse.

Establish the actual access

Identify the data, event type, account, device and session, search terms, filters and results. Determine whether content was fully viewed, repeated, printed, photographed, exported or communicated.

A broad search can return records never opened, while direct access may occur without search. Product audit terms and sequence help distinguish those routes.

Test authority and pattern

Compare case assignment, emergency or supervisory purpose, instructions and role at the time. Repeated searches for unrelated people or return visits can support targeted interest more strongly than one event.

Copying, disclosure and exploitation require separate evidence. Subsequent behaviour may support intent, but its absence is not proof of innocence; report the supported pattern and remaining alternatives.

Key takeaway

Prove the precise data interaction, the authority and purpose applicable, and the wider pattern before distinguishing accidental, necessary and deliberate insider access.

Reference: CIM-235Cyber Incidents & Offender Methods