Read these first
This article assumes the following earlier in its learning path.
Insider Threat and Access Governance: The Hardest Attack Surface Is Inside
Core premise: most enterprises invest in "stopping outsiders", yet the largest historical losses usually involved an insider factor. Angle: risk taxonomy and governance design. No surveillance-technique detail.
Why "inside" is especially hard
An external attacker must first breach the perimeter; an insider is already inside:
- they hold a legitimate account;
- they know what the systems look like;
- they know which data is most valuable;
- their behaviour often looks normal in the logs.
Perimeter defence is therefore nearly useless against insider threat. The real lever is permission design, not "watching everyone".
Three types, three responses
Treating "insider threat" as one problem produces the wrong countermeasures. There are three:
Type one: malicious (deliberate theft or sabotage)
Traits: clear intent, usually tied to a moment — before leaving, after being passed over, under financial pressure.
Behavioural signals (common, not conclusive):
- bulk access to data unrelated to their role, outside working hours;
- a sudden large download before resignation;
- handling company data on personal devices or personal cloud storage.
Response: least privilege, dual control on sensitive operations, a rigorous offboarding process (revoke access the day notice is given).
Type two: negligent (no malice, real risk)
Traits: no bad intent — copying data to a personal USB stick, writing credentials on a sticky note, configuring systems for personal convenience.
Why this is the most common: because convenience is usually the opposite of security, and people choose convenience.
Response: reduce the friction between "secure" and "convenient". If compliance is painful, people route around it. Providing simple, safe alternatives (a sanctioned file-sharing tool) beats prohibition.
Type three: coerced (unwilling, but exploited)
Traits: the account is phished, socially engineered, or the person is pressured into providing access.
Response: multi-factor authentication (so stealing a password alone is insufficient), anomaly detection (logins from unusual locations), and a culture that encourages reporting so victims speak up immediately.
Why "surveilling employees" is a poor strategy
The intuitive move is more monitoring. It has three problems:
- Cost exceeds benefit: always-on monitoring generates far more alerts than humans can process;
- It erodes trust: heavy surveillance makes staff conceal problems, lowering reporting rates;
- It treats symptoms: if permissions are excessive, monitoring only discovers loss after the fact.
A better frame: make data that should not be accessed impossible to access. What is technically unreachable needs no trust to enforce.
Four governance levers that actually work
Lever one: least privilege
Everyone holds only the permissions their job requires. This is the most fundamental layer — if the permission does not exist, it cannot be abused.
Lever two: just-in-time access
High-risk operations do not hold standing permissions; they are requested when needed, revoked after use, and recorded.
Lever three: separation of duties
Sensitive operations require two people: one initiates, another approves. This is not distrust — it is institutional design that also protects the employee from bearing sole responsibility.
Lever four: offboarding and transfers
This is where insider risk concentrates. Effective practice includes:
- access revocation effective the same day (not "next week");
- covering cloud services, SaaS, and third-party tools (many enterprises only handle internal systems);
- a handover list stating what they owned and who takes over.
How this relates to AI agents
A recurring theme in this series: credentials are the pivot of the attack chain. In the insider context it becomes subtler.
- When enterprises adopt AI agents (automation assistants, internal Q&A bots, reporting tools), those agents usually receive broad access — restrict them too much and they are useless;
- That makes the agent a new kind of insider identity: it does not resign, cannot be socially engineered — but its credentials can be stolen;
- More importantly, an agent's behaviour looks more "normal" in logs than a human's (no office hours, no moods, regular patterns).
Practical advice: design agent permissions on the same principles as employee permissions — least privilege, just-in-time, full audit — and periodically re-ask whether this agent still needs those permissions.
Three one-liners
- Insider threat is not one problem but three. Malicious, negligent, and coerced need different responses.
- Access governance beats surveillance. Unreachable access needs no trust to enforce.
- Change permissions the day notice is given. That is the window where insider risk concentrates.
Next steps
- For cloud permission design, read cloud identity and permissions
- For where credentials sit in the attack chain, read credentials and AD concepts
- For an overall defensive review, read defense lessons from a red-team postmortem
Next on this path
More in Evidence
- Tunnel Techniques Explained: When an AI Agent Needs to Pave a Road into the Internal Network
- Agentic Attack Tooling Research Series: A Guide to All Fourteen Parts
- AI Supply Chain Poisoning: When the Risk Hides in Models, Data, and Tools
- When AI Learns to Pentest: The ARTEX Case and the Rise of Agentic Attack Tooling