Knowledge / identity IR acsc-glossary

Insider threat

Harm from someone who already had the keys — malice, negligence, or a very bad accident. The badge was valid.

An insider is anyone with authorised logical or physical access, now or last year. An insider threat is that person causing damage, on purpose or by stuffing up. Some programs count only malice. The data does not care about your taxonomy.

Least privilege, logging of privileged use, joiner-mover-leaver that actually leaves, and a culture where reporting a mistake is cheaper than hiding it. Monitoring without a lawful, proportionate policy is how you grow a different incident.

Fact source: ASD's ACSC glossary.