Insider Threats And How To Detect Them

320 RibeloBehavioral Cybersecurity covers a wide range of topics; this post of ours from February 2025 gives a nice, short overview.

Sadly, the only kind of Behavioral Cybersecurity that seems to grab people's attention is the Insider threat. Worse, there is the same bias that we see in the way people talk about system outages: crime gets all the attention. For system outages this means that boring old systems administration gets ignored--at least until something fails. Similarly most people focus only on malice as a kind of insider threat when accidents and negligence are right up there.

(Accidents are unforeseeable incidents. Negligence is failing to follow established procedure. Malice is intentionally violating cybersecurity security for profit or satisfaction.)

All three kinds of insider threat deserve your attention but we at Pythia Cyber don't agree with the approach that IT uses and which cybersecurity so often tries to adopt: we don't believe in hunting for bad apples. We believe in empowering management to monitor employees. There wasn't a published solution that addressed this so we developed a unique solution: our Behavioral Analysis of Risks to Cybersecurity or BARC. Pythia Cyber comes in to be an objective, external reviewer and to follow the BARC process.

The BARC process has these well-defined steps:

  1. ‭Conduct executive conversations (2 – CEO & CTO/comparable, possibly also GC)‬
  2. ‭Conduct leadership focus groups (2 or 3)‬
  3. ‭Distribute survey via our platform‬
  4. Analyze quantitative data from survey‬
  5. ‭Integrate qualitative data with quantitative data, submit report, make presentation‬
  6. ‭Conduct behavioral change interventions such as:‬
    1. ‭“Train the trainer” sessions with HR staff‬
    2. ‭One-on-one feedback with managers based on their BARC scores‬
    3. ‭Simulations of cybersecurity interventions for managers who may not feel‬ ‭comfortable having these conversations‬
  7. ‭Reassess after 6 months

The immediate goal of a BARC engagement is to give your executives more data about your current risk of insider threats. The intermediate goal is to give you insight into where those threats might lie. The ultimate goal is to give you a constantly updated handle on your current and future threat level. For your managers the goal is to give them not only an assessment of the threat level but a framework in which to sort past incidents into Accident, Negligence or Malice so you can take action in the present to prevent incidents in the future.

Want to know more? Visit our web site for an overview of BARC, a white paper about BARC and a limited free offer to try BARC.

Comments