What is insider sabotage?¶
Insider sabotage is deliberate damaging activity by someone with a current or former legitimate relationship. An employee account causing harm does not prove a disgruntled employee acted; compromise, error and failed deployment are alternatives.
Link person, action and effect¶
Preserve account and device, commands, configuration, affected systems, timing, authority, access termination and communications. Identify the technical effect and exclude accidental or administrative causes.
Workplace conflict or departure creates context but is not proof of intent. Preparation, instructions, concealment and targeted technical action may carry greater weight.
Account for retained and remote access¶
Sabotage may be planned before departure or performed later through unrecalled credentials and sessions. Preserve offboarding, token revocation, device return and remote-access records.
An unsuccessful destructive attempt can still evidence deliberate action. Keep grievance, access opportunity, technical execution and personal responsibility at their separately supported levels.
Key takeaway
Establish sabotage through a deliberate damaging action linked to the person and authority context, distinguishing it from account compromise, mistake and poor administration.