Why Public Insider Cases Mislead
- kind
- Analysis
- domain
- Evidence
- stage
- Context
- read
- 3 min
- assumes
- No prior programme in place
The cases that become public are the unrepresentative ones, and building a programme around them produces the wrong priorities.
Insider threat material leans heavily on famous cases. They are memorable, and they are a biased sample in ways that distort programme design.
The selection bias
Public cases are the ones that were caught, prosecuted, and reported. Successful undetected exfiltration does not generate a case study.
They skew to the extreme. Espionage, large-scale theft, sabotage. These are real and they are a tiny fraction of incidents by volume.
They skew to specific sectors — defence, finance, technology — where disclosure obligations and litigation make cases visible.
They are reconstructed after the fact, which makes the warning signs look obvious. They were not obvious at the time; they were selected from a background of ordinary behaviour by people who already knew the answer.
What this does to programmes
Priorities aimed at the wrong scenario. A programme designed around a sophisticated actor systematically collecting data over months will be tuned for patterns that almost never occur, and will drown in the negligence that constitutes most of the caseload.
Overconfidence in indicator lists. "Warning signs of an insider threat" lists are derived from confirmed cases. They describe people who did something and also describe a large number of people who did not. Applied prospectively, they generate suspicion of the innocent.
Underinvestment in the ordinary. Nobody writes a case study about someone emailing a spreadsheet home before a holiday, and that is what most incidents are.
The base rate problem
Suppose an indicator appears in most confirmed insider cases. That sounds strong.
Now apply it across ten thousand employees. If the indicator also occurs in a small percentage of ordinary staff, and genuine incidents are rare, the overwhelming majority of people flagged will be innocent — even with an accurate indicator.
This is the central statistical fact of insider risk detection and it is almost never stated in the material. It is why single-indicator alerting produces unusable output, and why combinations plus human judgement are necessary rather than optional.
What the public cases are useful for
Understanding motivation. The consistent pattern across cases — grievance, financial pressure, belief in entitlement, recruitment — is genuinely informative.
Understanding the timeline. Most cases show activity over weeks or months, not a single act. That supports investment in detecting gradual patterns rather than single events.
Making the case for a budget. Legitimate, provided you do not imply your organisation faces the same threat.
Post-incident learning within your own organisation. Your own cases, anonymised, are worth more than any external example, because they reflect your actual exposure.
Better sources
Your own incident history, including the near misses and false positives.
Aggregate reporting that describes distributions rather than individual cases — proportion of incidents that are accidental, typical time to detection, common channels. Less dramatic and considerably more useful.
Sector peers, informally. What actually happens in organisations like yours is different from what appears in vendor material.
The framing to bring to executives
When a famous case is raised — and it will be — the useful response is not to dismiss it.
It is to say: that scenario is real, it is rare, and we are not currently positioned to detect it. What we can address, at reasonable cost, is the ninety percent of incidents that look like a departing employee taking their contact list. Here is what that costs, and here is what would be required to address the other kind.
That answer is honest, it does not oversell, and it usually gets funded.