Behavioural Indicators in Insider Contexts
The indicators below are grouped by the aspect of insider activity they most directly relate to. Individual indicators may overlap across categories.
Trust Abuse
Section titled “Trust Abuse”- relationship-building concentrated on approvers, privileged account holders, executive assistants or others whose access exceeds the person’s own
- becoming the sole point of contact for a supplier, system or process, and resisting rotation, cover arrangements or handover
- reluctance to take leave, or to allow another person to perform the role during an absence
- resistance to access review, peer review, approval validation or audit activity, particularly where familiarity or seniority is offered as the justification
- vouching for another person’s identity, access need or approval outside the normal verification route
- supplier, contractor or third-party dealings conducted outside the normal commercial relationship, including undisclosed personal or financial connections
Process Manipulation
Section titled “Process Manipulation”- repeated attempts to bypass or avoid an established process
- unusual interest in approval thresholds, exception routes, or the conditions under which a control is waived
- pressure applied to avoid verification, peer review or oversight
- requests to reroute or restructure activity in a way that bypasses required segregation-of-duties controls
- exceptions sought outside normal hours, during high-pressure operational periods, or while the usual approver is unavailable
- earlier exceptions cited as justification for a further one
- objection to logging, ticketing or written confirmation of a request
- activity deliberately divided, restructured or kept below thresholds to avoid additional approval, review or scrutiny
Access Facilitation
Section titled “Access Facilitation”- access requests without a stated business need, or with a justification that does not match the role
- access to systems, data or areas outside the person’s function, including access carried over from a previous role
- collection or aggregation of data beyond what the role requires, by volume, breadth or retention period
- copying to removable media, personal accounts, personal devices or unapproved transfer services
- unusual increases in access, downloading or copying activity that are inconsistent with the person’s role, business need or normal pattern of use, including around resignation, contract completion or role change
- attempts to retain credentials, tokens, licences or physical passes through offboarding
- physical access enabled for another person: tailgating, pass sharing, unescorted visitor movement, or a door or barrier left defeated
- remote or after-hours activity without an operational reason
- unusual familiarity with workflows, systems or approval paths outside the person’s role
- sharing, lending or allowing another person to use credentials, accounts, authentication tokens or other access mechanisms
- attempts to disable, bypass or interfere with logging, monitoring or other security controls associated with access
Relationship Exploitation
Section titled “Relationship Exploitation”- communication shifted to personal email, personal phone or ephemeral messaging where a record would normally exist
- pressure not to involve a manager, security function or other oversight role, including suggestions that escalation would be disloyal or damaging to trust
- familiarity, loyalty, secrecy or personal connection invoked to influence a decision
- gradual escalation from small informal favours to more sensitive or consequential requests within an existing relationship
- the same request being redirected to another person after it has already been declined
- repeated contact with staff whose role carries access the requester lacks, without an operational reason for the contact
- gifts, favours, incentives or personal benefits offered or exchanged in connection with access, approval or sensitive activity
Legitimacy Building
Section titled “Legitimacy Building”- internal terminology, project names, reporting lines or organisational context used to present an unusual request as routine or already approved
- real but unrelated approvals, projects or relationships cited to lend credibility to the current request
- requests timed to coincide with busy periods, change windows, incident response or leadership absence
- an unusual request embedded in an otherwise routine communication, meeting or workflow
- approval implied rather than evidenced, with verification deferred to a person who is unnamed or unavailable
- backdated or misleading records created to make an earlier action appear properly authorised
Workplace, Welfare & Coercion Indicators
Section titled “Workplace, Welfare & Coercion Indicators”- visible distress, withdrawal, anger or fearfulness coinciding with risky access, secrecy or process bypass
- unexplained affluence, or financial pressure evident alongside a change in behaviour at work
- indications of external pressure, blackmail, or a relationship that creates leverage over the person
- unreported contact with a competitor, foreign entity or other party holding an interest in the organisation’s information
- outside employment, directorships or commercial interests that have not been disclosed and may create conflicts of interest, competing obligations or external leverage
- grievance about the organisation, a decision or an individual, sustained past the point of resolution
- policy violations or disciplinary matters recurring after they have been addressed
- disengagement from security obligations, including repeated training failures, ignored attestations or dismissed reporting requirements
- significant changes in attendance, performance or workplace conduct occurring alongside other security-relevant indicators