Insider Threats: The Three Kinds and Who Stops Them

An insider threat is the risk that someone with legitimate access to your systems uses it in a way the business never authorised, whether deliberately, carelessly, or because somebody else has taken over their account. Nothing has to be broken into, so very little of it looks like an attack.

A Nelson engineering consultancy lost a tender it had spent six weeks writing. The engineer who wrote it resigned on a Friday and started with a competitor the following month.

Nobody told IT. The account stayed live for another five months, and so did the access to the tender library it had been used to build.

The firm could not prove the tender had been taken. It could not rule it out either, because eleven people shared the login that opened the file, and the log showed only the username.

Most insider incidents in a small business take that shape. There is no break-in and no alarm, and afterwards there is no record clear enough to settle the argument either way.

Whether the tender was taken is the part the firm can never price, and what follows is only the part it could count.

The figures here are illustrative. That firm employs 34 people and runs Microsoft 365 on a mix of named and shared accounts, an ordinary setup for its size.

Three accounts belonging to people who had left were still licensed. At $34 a user a month that came to $1,224 a year paid for logins nobody used.

The other cost was a one-off. When the tender question turned into a dispute, an external review cost $4,200 and could not answer it, because the shared login made every action anonymous.

Work your own version out from your licence bill and your last three departures, asking who closed each account and on what date.

None of this needed a dishonest employee. It needed a leaver, a shared password, and nobody holding the list.

Has Your Business Already Had an Insider Incident?

Almost certainly, and it was filed as something else at the time. The leaver whose account stayed open, the client list forwarded to a personal address, the shared password unchanged since 2021: each is an insider incident by any working definition, and none of them arrives wearing the label.

Owners tend to picture sabotage, so the category feels like a big-company problem. The incidents that actually occur are carelessness and accounts nobody closed, so they get counted as administration.

This post covers the person as the route in. Our guide to the eight attack types covers the threats arriving from outside, and insider risk is one entry on that list, not a separate discipline.

What separates an insider threat from an ordinary mistake?

Access separates them. If the person was entitled to open the file, the event is an insider incident, and the useful question becomes what that entitlement allowed them to reach.

The Privacy Act draws the same line. Information privacy principle 5 requires an agency to protect personal information against access, use or disclosure that the agency has not authorised, and an agency’s own staff fall inside that wording as squarely as anyone outside it.

That matters for a small business, because the duty does not stop at the firewall. A file opened by a staff member with no business reason to open it is a privacy problem even though every password worked.

Why do insider incidents get recorded as something else?

Because nothing raises an alert, so the event ends up named after its consequence. A missing file becomes a backup restore, a strange invoice becomes an accounts query, and a lost client becomes a sales problem.

Each description is true and none is complete. The common thread appears only when you ask who had access and whether it was ever reviewed.

Add that question to whatever you already do after an incident. It costs nothing and changes what you learn.

What Are the Three Kinds of Insider Threats?

Three: the deliberate insider who acts on purpose, the careless insider who makes a mistake, and the compromised insider whose account is being driven by an outsider.

Insider threats diagram showing deliberate, careless and compromised access using the same key

Most security writing calls the first two the malicious insider and the negligent insider. New Zealand’s Serious Fraud Office splits the same ground into intentional and unintentional, defines an insider threat as somebody who uses inside knowledge to gain a benefit for themselves, and names fraud, intellectual property theft and corruption as the leading risks here.

New Zealand’s National Cyber Security Centre draws those same lines inside a single control. Its principle of least privilege guidance describes limiting access so staff cannot accidentally or intentionally cause a security incident, and so an attacker who steals someone’s credentials cannot get far into the network.

The three need different answers from different people. Deliberate theft is an employment matter with a technical trail behind it. Carelessness is a process problem, while a compromised account is an ordinary security incident wearing a familiar name.

Sorting an incident into one of the three decides who runs the response. Businesses that skip that step send everything to IT, where two of the three cannot be solved.

What does a deliberate insider actually do?

They copy things they already have open. Client lists, pricing, tender documents and design files leave through email or a personal cloud drive, and the last fortnight of employment is when it happens.

The dramatic version, where a leaver deletes a database on the way out, is rare and loud enough to notice within the hour. The undramatic version costs more and can run for months without a symptom.

Watch the notice period first. A short review of what a departing person downloaded in their final fortnight answers most of the question, and it takes minutes when the logging is already on.

How is a compromised insider different from a stolen password?

It is the same event seen from inside your own systems. An attacker signing in with real credentials looks exactly like the person those credentials belong to, so nothing triggers and technically nothing is wrong.

The distinction changes the response without changing who is at fault. Once an attacker is operating the account, containment is access removal and log review, whoever happens to be holding the password.

Tell staff this in advance. They report a suspected takeover far faster when they know it will be treated as a security event with no blame attached.

Why Is the Leaver the Most Common Insider Risk?

Because access outlives employment, and nothing in a payroll system reaches across and closes an account. The leaving date exists in payroll weeks before the last day and travels no further.

The National Cyber Security Centre puts this plainly in its guidance on third-party breaches. It asks organisations to revoke system access as soon as staff leave, to review the directory against HR records and disable accounts belonging to people who have gone, and to change shared account passwords whenever a holder of that password moves on.

Those three checks cover most of the exposure for a business under fifty people. Running them as a standing discipline is a wider subject, and our post on joiners, movers and leavers covers the governance built around it.

Role changes leak access the same way. The Serious Fraud Office calls it privilege slide, where a person keeps the permissions from an old job after moving to a new one, and three moves later they reach more than anybody intended.

How long does access usually survive a departure?

Longer than most owners expect, because the process has no step that closes an account. Payroll knows on the day. IT finds out when a licence bill is queried, or when a manager spots a name still in a group chat.

Cloud services add to it. A departing person keeps whatever they signed up for with a work email address, and the business has no list of what that includes.

Check your last three departures against your user list this afternoon. It takes about ten minutes and few owners like what they find.

Who owns offboarding, IT or HR?

Both, and that is why it fails. HR knows the leaving date and IT holds the switch, so when neither owns the handover the account stays live by default and nobody has done anything wrong.

Name one owner and give them a written list. The person who processes the final pay is the right choice, because they always know when a person has gone and they are already working to a deadline.

Put the IT steps on the same checklist as the company phone and the building key. Access is easier to remember when it travels with the phone and the key.

What about contractors and suppliers?

They belong in the same list and are usually missing from it. A contractor’s account is created for a project and outlives it, with no HR record attached, so no departure triggers a review.

Give every external account an end date when it is created. An account that expires on its own removes the need to remember it at all.

Are Staff Using AI Tools an Insider Threat?

Yes, whenever company information goes into a tool the business never approved. A site supervisor pastes three pages of a client contract into a free chatbot on his phone to find the variation clause before a Monday meeting, and that contract has now left every control the business owns.

The intent is helpful, which places the act alongside carelessness. It belongs with emailing a spreadsheet home to finish after dinner. The copy now lives somewhere the business cannot reach and has no practical way of deleting.

Our post on business information going into AI tools covers what the tools retain and what a business agreement changes. The insider question here is narrower, and it is whether the business would ever know it had happened.

The tool itself is frequently unapproved, and our post on software nobody approved covers how those arrive and why blocking them alone fails. Staff reach for whatever is quicker when the sanctioned option is slower.

What does an AI insider incident look like?

It looks like nothing at all, which makes it the hardest of the categories to count. There is no file transfer to find and no email to trace, and whatever record exists belongs to the AI provider.

Two things close most of the gap and neither is monitoring. Give people a sanctioned tool good enough that they stop reaching for their phone, and put one line in the acceptable use policy about company information.

Do the policy line first, because it is the part you can point at afterwards. A rule written before an incident changes the conversation after one.

What Do Insider Threats Cost a New Zealand Business?

Insider threats cost a business in dormant licences and in the time spent proving what happened. On the Nelson example those two came to $1,224 a year and $4,200 once.

Dormant accounts are the visible part. Three unused Microsoft 365 licences at $34 a month is $1,224 a year, and every departure that goes unclosed adds another $408 a year.

You only pay the second cost when a question gets asked. Answering who opened a file eighteen months ago is cheap with named accounts and logging, and a paid forensic exercise without them.

The third cost deserves an honest sentence. A tender lost after a resignation may or may not be connected, and a business that cannot see who opened what will never find out.

What does fixing it cost?

It takes about a morning and the upkeep after that is minimal. Writing an offboarding checklist, tying it to the final pay run and replacing the shared login with named accounts is roughly half a day of work, or about $600 if the time is billed to you.

A quarterly reconciliation of the user list against HR records takes an hour. On the illustrative figures that turns $1,224 a year of wasted licences into about $340 a year of review time, so roughly $884 comes back annually.

The $600 stays on its own and does not net off, sitting beside the $4,200 the firm had already spent on a review that answered nothing.

Price it against your own licence bill. Count the accounts belonging to people who have left, then multiply by your per-user cost.

How Do You Detect an Insider Threat in Your Business?

With logs you can actually read, and with named accounts so that the log means something when you read it.

Insider threats diagram showing eleven staff behind one shared login and a single log entry

Centralised logging appears in the same set of critical controls for exactly this reason. Without a feed from every system in one place, an investigation depends on whoever happens to remember what normal looked like.

People notice before logs do. The Serious Fraud Office reports that whistleblower disclosures remain a primary way malicious conduct by an employee is found, and the Protected Disclosures (Protection of Whistleblowers) Act 2022 protects anyone who raises one.

None of it works behind a shared login. Eleven people behind one username produces eleven possible answers and no way to choose. A two-hour question in Nelson became a $4,200 one for that reason alone.

What can a small business realistically see?

Most owners can see more than they expect using tools they already pay for. Microsoft 365 keeps a sign-in log and an audit log, and between them they answer who opened what and from where.

Retention is shorter on the cheaper licences, so the question has to be asked within weeks. Check which plan you are on before you rely on it.

Turn the audit log on before you need it, because it records nothing retrospectively. The day you want it is the day it starts collecting, and that is too late to answer anything.

How Do You Prevent Insider Threats in a Small Business?

Give people the access their job needs and no more, then make the leaving process automatic. Both handle all three categories, because they shrink what any account can reach regardless of who is driving it.

Monitoring everybody is expensive and damages the trust that prevents most incidents. Reducing standing access costs nothing and casts suspicion on no one.

  1. Name one owner for offboarding and tie the checklist to the final pay run.
  2. List every shared login, then replace the ones tied to a real system with named accounts.
  3. Reconcile the user list against HR records quarterly and disable anything unmatched.
  4. Give every contractor and supplier account an end date on the day it is created.
  5. Reduce standing access to what each role needs, starting with the folders holding client and pricing data.
  6. Turn on audit logging, then confirm you can answer who opened a named file last month.
  7. Add one line to the acceptable use policy about company information and AI tools.

None of that is surveillance. It is bookkeeping applied to access, and most of it is done once and then reviewed four times a year.

Say why you are doing it. Staff accept access limits far more easily when the reason is keeping them out of an investigation they had nothing to do with.

The Nelson consultancy paid $1,224 a year for accounts nobody used and $4,200 to answer a question its own records could not. The checklist that would have prevented both fits on a single page.

Could You Say Who Opened That File Last Month?

Exodesk has supported South Island businesses since 1989 and works with clients across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. Our cyber security team reviews who holds access to what, closes the accounts that should have gone, and puts named logins where shared ones are doing the work.

We set it up so that a departure closes an account on the same day, and so that a question about last month has an answer you can read.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

What is an insider threat?

An insider threat involves a person who already holds a valid login and puts it to a use the employer never sanctioned. Current staff, departed staff whose accounts remain open, and contractors all fall inside that definition. So does an outsider running a hijacked account, because the activity carries a trusted name. Every check it meets is one the account is entitled to pass.

What are the three types of insider threat?

Deliberate, careless and compromised. A deliberate insider acts on purpose, usually by copying information they already have open. A careless insider makes an ordinary mistake, such as emailing a file to the wrong address, and a compromised insider has had their account taken over, so the activity carries their name without their knowledge.

Are most insider threats malicious?

No. The majority of incidents in a small business come from carelessness or from an account nobody closed when a person left. Deliberate theft happens and it is expensive when it does, and it is far less common than the paperwork suggests.

How quickly should a leaver’s access be removed?

On the last day, ideally as part of the same process that runs the final pay. New Zealand’s National Cyber Security Centre asks organisations to revoke system access as soon as staff leave, including access to cloud services and physical devices. Shared account passwords should change at the same time, because a departing person knows those too.

Is a shared login an insider threat?

A shared login removes your ability to answer a question about an incident, because the log records the username and nothing about which of the eleven people used it. Replace shared logins on any system holding client, financial or personal information.

Is an employee using ChatGPT an insider threat?

It can be, when company information goes into a tool the business has not approved. The intent is usually helpful, which puts it in the careless category, and the effect is that a copy of the information now lives outside every control the business owns. One line in an acceptable use policy plus a sanctioned tool staff are allowed to use handles most of it.

Do small businesses really face insider threats?

Yes, and often with less protection than a large one, because smaller teams share more logins, have fewer separate roles and rarely run a formal offboarding process. The most common incident of all is an account that simply stayed open.

What are the warning signs of an insider threat?

Behaviour and access patterns together. The Serious Fraud Office lists repeated after-hours access, reluctance to take leave, attempts to reach information outside a person’s role, and repeated security breaches among its red flags. None of them proves anything alone, and a cluster of them is worth a conversation before it becomes an investigation.

Does the Privacy Act 2020 cover insider misuse of data?

Yes. Information privacy principle 5 requires an agency to hold personal information with security safeguards that are reasonable in the circumstances, protecting it against loss and against access, use or disclosure the agency has not authorised, and misuse by an organisation’s own staff falls inside that wording.

Should we monitor staff to prevent insider threats?

Monitoring everybody is expensive and it damages the trust that prevents most incidents. Reducing what each account can reach achieves more for less and works regardless of intent. Keep logging in place so a specific question can be answered later. Avoid general surveillance of people doing their jobs.

How much does it cost to reduce insider risk?

For most small businesses this is a one-off half day of work with no monthly subscription behind it. An offboarding checklist, named accounts in place of shared logins and audit logging switched on costs about $600 if the work is billed to you, then roughly an hour a quarter to keep current. Recovering the licences on dormant accounts often covers that in the first year.

Does Exodesk help New Zealand businesses manage insider risk?

Yes. Exodesk works with businesses across Canterbury, Otago and Southland from offices in Christchurch and Dunedin, reviewing access, closing dormant accounts and replacing shared logins with named ones, and we have operated in the South Island since 1989.

NEXT STEP

Could you name everyone who can still open your client folder?

Most businesses cannot, and the account nobody closed is the one that answers the question badly. An IT assessment lists who holds access to what, which accounts belong to people who have left, and where a shared login is standing in for a named one.

Or read more about our managed IT services.

Start typing and press Enter to search

Defence in Depth: a corridor of differently shaped gates with an intruder stopped at the secondData Backup Call Us Now