Skip to content

Behavioural Indicators in Insider Contexts

The indicators below are grouped by the aspect of insider activity they most directly relate to. Individual indicators may overlap across categories.

  • relationship-building concentrated on approvers, privileged account holders, executive assistants or others whose access exceeds the person’s own
  • becoming the sole point of contact for a supplier, system or process, and resisting rotation, cover arrangements or handover
  • reluctance to take leave, or to allow another person to perform the role during an absence
  • resistance to access review, peer review, approval validation or audit activity, particularly where familiarity or seniority is offered as the justification
  • vouching for another person’s identity, access need or approval outside the normal verification route
  • supplier, contractor or third-party dealings conducted outside the normal commercial relationship, including undisclosed personal or financial connections
  • repeated attempts to bypass or avoid an established process
  • unusual interest in approval thresholds, exception routes, or the conditions under which a control is waived
  • pressure applied to avoid verification, peer review or oversight
  • requests to reroute or restructure activity in a way that bypasses required segregation-of-duties controls
  • exceptions sought outside normal hours, during high-pressure operational periods, or while the usual approver is unavailable
  • earlier exceptions cited as justification for a further one
  • objection to logging, ticketing or written confirmation of a request
  • activity deliberately divided, restructured or kept below thresholds to avoid additional approval, review or scrutiny
  • access requests without a stated business need, or with a justification that does not match the role
  • access to systems, data or areas outside the person’s function, including access carried over from a previous role
  • collection or aggregation of data beyond what the role requires, by volume, breadth or retention period
  • copying to removable media, personal accounts, personal devices or unapproved transfer services
  • unusual increases in access, downloading or copying activity that are inconsistent with the person’s role, business need or normal pattern of use, including around resignation, contract completion or role change
  • attempts to retain credentials, tokens, licences or physical passes through offboarding
  • physical access enabled for another person: tailgating, pass sharing, unescorted visitor movement, or a door or barrier left defeated
  • remote or after-hours activity without an operational reason
  • unusual familiarity with workflows, systems or approval paths outside the person’s role
  • sharing, lending or allowing another person to use credentials, accounts, authentication tokens or other access mechanisms
  • attempts to disable, bypass or interfere with logging, monitoring or other security controls associated with access
  • communication shifted to personal email, personal phone or ephemeral messaging where a record would normally exist
  • pressure not to involve a manager, security function or other oversight role, including suggestions that escalation would be disloyal or damaging to trust
  • familiarity, loyalty, secrecy or personal connection invoked to influence a decision
  • gradual escalation from small informal favours to more sensitive or consequential requests within an existing relationship
  • the same request being redirected to another person after it has already been declined
  • repeated contact with staff whose role carries access the requester lacks, without an operational reason for the contact
  • gifts, favours, incentives or personal benefits offered or exchanged in connection with access, approval or sensitive activity
  • internal terminology, project names, reporting lines or organisational context used to present an unusual request as routine or already approved
  • real but unrelated approvals, projects or relationships cited to lend credibility to the current request
  • requests timed to coincide with busy periods, change windows, incident response or leadership absence
  • an unusual request embedded in an otherwise routine communication, meeting or workflow
  • approval implied rather than evidenced, with verification deferred to a person who is unnamed or unavailable
  • backdated or misleading records created to make an earlier action appear properly authorised
  • visible distress, withdrawal, anger or fearfulness coinciding with risky access, secrecy or process bypass
  • unexplained affluence, or financial pressure evident alongside a change in behaviour at work
  • indications of external pressure, blackmail, or a relationship that creates leverage over the person
  • unreported contact with a competitor, foreign entity or other party holding an interest in the organisation’s information
  • outside employment, directorships or commercial interests that have not been disclosed and may create conflicts of interest, competing obligations or external leverage
  • grievance about the organisation, a decision or an individual, sustained past the point of resolution
  • policy violations or disciplinary matters recurring after they have been addressed
  • disengagement from security obligations, including repeated training failures, ignored attestations or dismissed reporting requirements
  • significant changes in attendance, performance or workplace conduct occurring alongside other security-relevant indicators