Insider Threats: The Three Kinds and Who Stops Them

An insider threat is the risk that trusted access or inside knowledge is used in a way that harms the business, deliberately or accidentally. A compromised account creates similar exposure, because an outsider is operating through a legitimate user’s access. Excess permissions and accounts left open after a departure increase that risk; on their own they do not prove misuse has occurred.

The scenario that follows is illustrative. A Nelson engineering consultancy lost a tender it had spent six weeks writing. The engineer who wrote it resigned on a Friday and started with a competitor the following month.

Nobody told IT. The account stayed live for another five months, and so did the access to the tender library it had been used to build.

The firm could not prove the tender had been taken. It could not rule it out either, because eleven people shared the login that opened the file, and the log showed only the username.

Incidents of that shape are easy to miss. There is no break-in and no alarm, and afterwards the records may not be clear enough to settle the argument either way.

Whether the tender was taken is the part the firm can never price. What follows is only the part it could count.

That firm employs 34 people and runs Microsoft 365 on a mix of named and shared accounts, an ordinary setup for its size. Three accounts belonging to people who had left were still licensed, so it was paying every month for logins nobody used.

The other cost arrived once. When the tender question turned into a dispute, an external review could not answer it, because the shared login left no way to tell which of the eleven had opened the file.

Work your own version out from your licence bill and your last three departures, asking who closed each account and on what date.

None of this needed a dishonest employee. It needed a leaver, a shared password, and nobody holding the list.

Which Access Risks Has Your Business Overlooked?

Start with the ones nobody files as a security problem. The leaver whose account stayed open, the client list forwarded to a personal address, the shared password unchanged since 2021.

Three states are worth keeping apart, because the page you are reading is easy to misuse otherwise. An exposure is a weakness that could be used, such as a dormant account or a shared login. Suspected misuse is activity that needs explaining. A confirmed incident is one where you have established what actually happened. A dormant account is the first of those and not the third, however uncomfortable it looks on a list.

Owners tend to picture sabotage, so the category feels like a big-company problem. What turns up in practice is ordinary and administrative, which is why it gets counted as administration.

This post covers the person as the route in. Our guide to the eight attack types covers the threats arriving from outside, and insider risk is one entry on that list, not a separate discipline.

What separates an insider threat from an ordinary mistake?

Trusted access is what makes it an insider question. The person could reach the information legitimately, so the useful question becomes what that access allowed them to reach and whether anybody had reviewed it.

Being entitled to open a file does not turn every mistake involving it into an incident. Somebody attaching the wrong document has made an error, and whether it becomes an incident depends on what was in it and where it went.

Where personal information is involved the Privacy Act applies. Information privacy principle 5 requires an agency to protect personal information against access, use or disclosure it has not authorised, and an agency’s own staff fall inside that wording as squarely as anyone outside it. That duty covers personal information specifically, so it does not settle every question about a commercial document such as a tender.

Why do insider incidents get recorded as something else?

Because nothing raises an alert, so the event ends up named after its consequence. A missing file becomes a backup restore, a strange invoice becomes an accounts query, and a lost client becomes a sales problem.

Each description is true and none is complete. The common thread appears only when you ask who had access and whether it was ever reviewed.

Add that question to whatever you already do after an incident. It costs nothing and changes what you learn.

What Are the Three Kinds of Insider Threats?

Three: the deliberate insider who acts on purpose, the careless insider who makes a mistake, and the compromised insider whose account is being driven by an outsider.

Insider threats diagram showing deliberate, careless and compromised access using the same key

Most security writing calls the first two the malicious insider and the negligent insider. New Zealand’s Serious Fraud Office splits the same ground into intentional and unintentional, defines an insider threat as somebody who uses inside knowledge to gain a benefit for themselves, and names fraud, intellectual property theft and corruption as the leading risks here.

New Zealand’s National Cyber Security Centre draws those same lines inside a single control. Its principle of least privilege guidance describes limiting access so staff cannot accidentally or intentionally cause a security incident, and so an attacker who steals someone’s credentials cannot get far into the network.

The three are a useful way to organise this guide rather than a universal classification. The first two come from the same place, since the Serious Fraud Office splits insider threat into intentional and unintentional, while a compromised account is different in kind because it describes an outsider using trusted access.

They need different answers from different people. Deliberate misuse is an employment matter with a technical trail behind it, carelessness is a process problem, and a compromised account is an ordinary security incident wearing a familiar name.

The response cannot wait until you know which one it is. Limit further harm and preserve the relevant records first, with IT handling technical investigation and containment and management coordinating the rest, bringing in HR, the privacy officer or other advisers where they are needed. Establish the facts before drawing conclusions about intent. Businesses that skip that step send everything to IT, where two of the three cannot be resolved.

What does a deliberate insider actually do?

Usually they copy things they already have open. Client lists, pricing, tender documents and design files leave through email or a personal cloud drive, and a notice period is an obvious time to be paying attention.

The dramatic version, where a leaver deletes a database on the way out, is loud enough to notice quickly. The undramatic version can run for months without a symptom.

A review of what a departing person downloaded during their notice period is worth doing where the logging supports it. Treat it as one input rather than a conclusive test: ordinary work produces downloads too, and finding nothing is not proof that nothing left.

How is a compromised insider different from a stolen password?

It is the same event seen from inside your own systems. An attacker signing in with real credentials carries the name of the person those credentials belong to, so the authentication itself succeeds. That does not mean nothing is noticed. Unfamiliar locations, impossible travel and unusual activity can still raise alerts, and a valid login is not a clean bill of health.

The distinction changes the response without changing who is at fault. Once an attacker is operating the account, containment is access removal and log review, whoever happens to be holding the password.

Tell staff this in advance. They report a suspected takeover far faster when they know it will be treated as a security event with no blame attached.

How Does Access Left Behind Increase Insider Risk?

Because access outlives employment. Nothing in a payroll system reaches across and closes an account, so the leaving date sits in payroll weeks before the last day and travels no further unless somebody carries it there.

The National Cyber Security Centre puts this plainly in its guidance on third-party breaches. It asks organisations to revoke system access as soon as staff leave, to review the directory against HR records and disable accounts belonging to people who have gone, and to change shared account passwords whenever a holder of that password moves on.

Those three checks cover most of the exposure for a business under fifty people. Running them as a standing discipline is a wider subject, and our post on joiners, movers and leavers covers the governance built around it.

Role changes leak access the same way. The Serious Fraud Office calls it privilege slide, where a person keeps the permissions from an old job after moving to a new one, and three moves later they reach more than anybody intended.

How long does access usually survive a departure?

Longer than most owners expect, because the process has no step that closes an account. Payroll knows on the day. IT finds out when a licence bill is queried, or when a manager spots a name still in a group chat.

Cloud services add to it. A departing person keeps whatever they signed up for with a work email address, and the business has no list of what that includes.

Check your last three departures against your user list this afternoon. It takes about ten minutes and few owners like what they find.

Who owns offboarding, IT or HR?

Both, and that is why it fails. HR knows the leaving date and IT holds the switch, so when neither owns the handover the account stays live by default and nobody has done anything wrong.

Agree the exact time access must end, and tell the people responsible before that time arrives. It is usually the end of the last working day, though some departures call for something earlier. HR or the manager confirms the departure, one named process owner coordinates it, and IT or the service owner removes the access.

The final pay run is not the trigger. It is a useful reminder that somebody has gone, but it runs to its own timetable and can land well after the access should already have ended.

Cover the separate cloud services, the devices, the shared credentials and any active sessions, and preserve the business records that still need keeping before anything is deleted. Removing a licence is not the same as blocking access, disabling an account does not recall copies already downloaded, and what to do about the licence is a separate decision to make afterwards.

Put the IT steps on the same checklist as the company phone and the building key. Access is easier to remember when it travels with the phone and the key.

What about contractors and suppliers?

They belong in the same list and are usually missing from it. A contractor’s account is created for a project and outlives it, with no HR record attached, so no departure triggers a review.

Give every external account an end date when it is created, and a named owner. An expiry date helps only where the platform supports it, somebody has configured it, and somebody reviews what is about to lapse, so it reduces the remembering rather than removing it.

Are Staff Using AI Tools an Insider Threat?

It can be, and it depends on the information, the purpose, the permissions and how the tool is configured. Looking up a public standard in an unapproved tool is a different matter from a site supervisor pasting three pages of a client contract into a free chatbot on his phone to find the variation clause before a Monday meeting.

The intent is usually helpful, which places the act alongside carelessness. It belongs with emailing a spreadsheet home to finish after dinner. What happens to that copy depends on the service and its settings, since visibility, retention and deletion all vary, and an approved tool can still be misused.

Our post on business information going into AI tools covers what the tools retain and what a business agreement changes. The insider question here is narrower, and it is whether the business would ever know it had happened.

The tool itself is frequently unapproved, and our post on software nobody approved covers how those arrive and why blocking them alone fails. Staff reach for whatever is quicker when the sanctioned option is slower.

What does an AI insider incident look like?

Often it leaves little behind for you to find, which makes it the hardest of the categories to count. There may be no file transfer and no email to trace, and whatever record exists sits with the provider rather than with you.

Two things close much of the gap and neither is monitoring. Give people a sanctioned option good enough that they stop reaching for their phone, and say plainly which tools and uses are allowed, what information must stay out, and how to report an accidental disclosure.

Do the policy line first, because it is the part you can point at afterwards. Then review the approved tool itself: its settings, who can reach it, and what it retains.

What Do Insider Threats Cost a New Zealand Business?

Insider risk costs a business in two visible ways: licences nobody uses, and the time spent trying to prove what happened.

Dormant accounts are the easier of the two to see. Count the accounts belonging to people who have left and multiply by your per-user cost. Whether removing them lowers the bill is a separate question, because contract terms, renewal dates and whether a seat can be reused all affect it, and replacing shared logins with named accounts can add licences rather than save them. Treat the access decision and the licence decision separately, and take the access one first.

You only pay the second cost when a question gets asked, and what it costs depends on whether the records still exist. Within retention, named accounts and audit logging can answer it quickly. Beyond retention, no amount of money will, and the retention windows are shorter than most people assume. They are set out further down.

The third cost deserves an honest sentence. A tender lost after a resignation may or may not be connected, and a business that cannot see who opened what will never find out.

What does fixing it cost?

What drives it: how many accounts are involved, how many separate applications hold their own logins, how much shared access has to be replaced with named accounts, what records have to be retained before anything is removed, and how often you want the reconciliation run afterwards.

There is an initial piece of work and an ongoing one, and they are worth quoting separately. Writing an offboarding process, replacing shared logins on the systems that matter and turning auditing on is the first. A periodic reconciliation of the user list against HR and contractor records is the second.

Set the recovered licence cost against the ongoing review rather than against the initial work. Netting a one-off cost against an annual saving makes any project look like it pays for itself immediately, which is how a first year gets planned badly.

Price it against your own licence bill. Count the accounts belonging to people who have left, then multiply by your per-user cost.

How Do You Detect an Insider Threat in Your Business?

With logs you can actually read, and with named accounts so that the log means something when you read it.

Insider threats diagram showing eleven staff behind one shared login and a single log entry

Centralised logging appears in the same set of critical controls for exactly this reason. Separate logs are still useful on their own, and bringing the relevant ones together mainly makes analysis faster, provided the events you care about are being captured, protected and retained.

People often notice before logs do. The Serious Fraud Office reports that whistleblower disclosures remain a primary way malicious conduct by an employee is found, so give staff a clear and trusted channel for raising a concern. New Zealand’s Protected Disclosures (Protection of Whistleblowers) Act 2022 provides protections for qualifying disclosures of serious wrongdoing, and the Ombudsman explains who can make one and how the protections apply. It is not a blanket protection for raising any workplace issue.

Shared logins make all of this harder. Eleven people behind one username means the log names the account and not the person, so attribution has to come from somewhere else if it can come at all. Device, session, network and application records sometimes narrow it down and often they do not, and that uncertainty is the real cost.

What can a small business realistically see?

Often more than expected, using tools already paid for. But the two Microsoft 365 record sets are different things with different coverage and different retention, and they are not interchangeable.

Record What it helps establish Typical default retention
Entra sign-in logs Authentication activity and the details attached to a sign-in 7 days on Entra ID Free, 30 days on P1 or P2
Purview Audit (Standard) Supported user and administrator activity across Microsoft 365 services 180 days for records generated under the current standard policy

Those are defaults rather than a promise about your tenant. Check your licensing, whether collection is switched on, which services are covered, and whether anybody has configured longer retention or an export.

Check that auditing is on, because it may not be. Microsoft states that auditing is not enabled by default for Microsoft 365 Business Basic, Business Standard and Business Premium, and that it has to be enabled manually. Those are the plans most small businesses run. It records nothing retrospectively either, so the day you switch it on is the day it starts collecting.

Then confirm the specific thing you care about is captured. Check that the activity you would want to ask about actually appears in the records before you rely on them to answer a question later.

How Do You Prevent Insider Threats in a Small Business?

Give people the access their job needs and no more, then make the leaving process reliable. Both reduce what any account can reach regardless of who is driving it, which helps against all three categories without depending on knowing which one you are facing.

They are not the whole answer. A current employee can misuse access their role genuinely requires, so strong authentication, safe working practices, proportionate detection and a response process all still matter.

Indiscriminate surveillance is expensive and it costs trust. Proportionate monitoring is a different thing: use it for a clear security purpose, collect only what you need, tell staff what is recorded and how it may be used, limit who can read it and how long it is kept, and review unusual activity in context rather than treating an alert or a change in behaviour as proof of anything.

1

Name one owner and agree the access cutoff

Not the pay run. Agree the exact time access ends for each departure, and make sure HR, the manager, the process owner and IT all know it before it arrives.

2

Replace shared logins on the systems that matter

List every shared login, then replace the ones tied to a real system with named accounts. A shared mailbox or folder reached through individual identities is a different thing and works fine.

3

Reconcile the user list against HR and contractor records

Quarterly, and investigate anything unmatched rather than disabling it. Service accounts, contractor accounts and break-glass accounts are unmatched by design, and each needs a recorded owner and a reason to exist.

4

Give every external account an end date and an owner

On the day it is created, where the platform supports expiry, and review what is about to lapse so nothing is renewed by accident or cut off mid-project.

5

Reduce standing access to what each role needs

Starting with the folders holding client, pricing and personal information, and including the permissions people kept after changing roles.

6

Turn auditing on, then confirm it is on

It is off by default on the Microsoft 365 Business plans. Once it is running, check you can actually answer who opened a named file last month, because that is the test that matters.

7

Write down what is allowed with AI tools

Which tools and uses are permitted, what information must stay out, and how to report an accidental disclosure. Then give people an approved option good enough to use.

Most of that is bookkeeping applied to access, done once and then reviewed a few times a year. Some of it, the logging in particular, is a form of monitoring, which is a reason to be open about it rather than a reason to avoid it.

Say why you are doing it. Staff accept access limits far more easily when the reason is keeping them out of an investigation they had nothing to do with.

The Nelson consultancy paid every month for accounts nobody used, then paid again for a review that its own records could not support. The process that would have prevented both fits on a single page.

Could You Say Who Opened That File Last Month?

Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. Our cyber security team reviews who holds access to what, closes the accounts that should have gone, and puts named logins where shared ones are doing the work.

How quickly a departure closes an account depends on being told in time and on the systems being in scope. What a question about last month can be answered from depends on what was being recorded and for how long. We set both of those up so the answer is there when you need it.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

What is an insider threat?

An insider threat is the risk that trusted access or inside knowledge is used in a way that harms the business, deliberately or accidentally. Current staff, departed staff whose accounts remain open, and contractors all fall inside it. So does an outsider running a hijacked account, because the activity carries a trusted name and the authentication succeeds. A dormant account or a shared login is an exposure that could enable misuse rather than proof that any has occurred.

What are the three types of insider threat?

Deliberate, careless and compromised. A deliberate insider acts on purpose, usually by copying information they already have open. A careless insider makes an ordinary mistake, such as emailing a file to the wrong address, and a compromised insider has had their account taken over, so the activity carries their name without their knowledge.

Can an insider incident be accidental?

Yes. An ordinary mistake, such as attaching the wrong document or emailing a file to a personal address to finish at home, can expose information just as effectively as a deliberate act. The Serious Fraud Office treats intentional and unintentional insider threat as two sides of the same subject. The response differs, because carelessness is a process problem and deliberate misuse is an employment matter, but the exposure can be the same.

How quickly should a leaver’s access be removed?

At an agreed access cutoff, usually the end of the last working day, with the people responsible told before it arrives. New Zealand’s National Cyber Security Centre asks organisations to revoke system access as soon as staff leave, including access to cloud services and physical devices. Shared account passwords should change at the same time, because a departing person knows those too. The final pay run is a reminder rather than a trigger, since it runs to its own timetable. Removing a licence is not the same as blocking access, and preserving business records comes before deleting anything.

Is a shared login an insider threat?

A shared login weakens your ability to answer a question about an incident, because the log records the account name and not which of the people behind it was using it. Device, session and application records sometimes narrow it down and often they do not. Replace shared logins on any system holding client, financial or personal information. A shared mailbox or folder reached through individual identities is a different arrangement and does not have the same problem.

Is an employee using ChatGPT an insider threat?

It can be, and it depends on the information, the purpose and how the tool is configured. Looking something public up is different from pasting a client contract into a free chatbot. The intent is usually helpful, which puts it in the careless category, and what happens to the copy depends on the service, since visibility, retention and deletion vary. Say which tools and uses are allowed, what information must stay out, and how to report an accidental disclosure, then give people an approved option good enough to use.

Do small businesses really face insider threats?

Yes, and often with less protection than a large one, because smaller teams share more logins, have fewer separate roles and rarely run a formal offboarding process. An account left open after somebody leaves is one of the easiest exposures to create and one of the easiest to close.

What are the warning signs of an insider threat?

Behaviour and access patterns together. The Serious Fraud Office lists repeated after-hours access, reluctance to take leave, attempts to reach information outside a person’s role, and repeated security breaches among its red flags. None of them proves anything alone, and a cluster of them is worth a conversation before it becomes an investigation.

Does the Privacy Act 2020 cover insider misuse of data?

Yes. Information privacy principle 5 requires an agency to hold personal information with security safeguards that are reasonable in the circumstances, protecting it against loss and against access, use or disclosure the agency has not authorised, and misuse by an organisation’s own staff falls inside that wording.

Should we monitor staff to prevent insider threats?

Indiscriminate surveillance is expensive and it costs trust. Proportionate monitoring is different: use it for a clear security purpose, collect only what you need, tell staff what is recorded and how it may be used, limit who can read the records and how long they are kept, and review unusual activity in context rather than treating an alert as proof of wrongdoing. Reducing what each account can reach achieves a great deal for less effort and works regardless of intent. Note that logging identifiable staff activity is itself a form of monitoring, which is a reason to be open about it.

How much does it cost to reduce insider risk?

There is an initial piece of work and an ongoing one, and they are worth quoting separately. What drives the cost is how many accounts are involved, how many separate applications hold their own logins, how much shared access has to be replaced with named accounts, what records must be retained before anything is removed, and how often you want the reconciliation run. Set any recovered licence cost against the ongoing review rather than against the initial work, and check first whether removing a licence actually changes your bill.

Does Exodesk help New Zealand businesses manage insider risk?

Yes. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand, reviewing access, closing dormant accounts, replacing shared logins with named ones and checking that audit logging is actually switched on.

NEXT STEP

Could you name everyone who can still open your client folder?

Most businesses cannot, and the account nobody closed is the one that answers the question badly. An IT assessment lists who holds access to what, which accounts belong to people who have left, and where a shared login is standing in for a named one.

Or read more about our managed IT services.

Start typing and press Enter to search

Defence in Depth: a corridor of differently shaped gates with an intruder stopped at the secondData backup strategy banner showing three drives with one standing apart and unplugged Call Us Now