Index / Context

Remote Work and Insider Risk

kind
Analysis
domain
Evidence
stage
Context
read
3 min
assumes
No prior programme in place

Distributed working changed the exposure and the detection surface. What actually changed, as opposed to what was assumed.

The shift to remote work produced a great deal of commentary about insider risk, much of it asserting that risk rose. The picture is more specific and partly the opposite.

What genuinely changed

The network perimeter stopped carrying the traffic. Data moves between the endpoint and cloud services directly. Network inspection sees a fraction of what it used to, which shifted detection onto endpoint agents and cloud audit logs.

Physical observation vanished. Not a formal control, but colleagues noticing unusual behaviour was a real detection mechanism, and it is gone.

Home networks and shared devices. Printing to a household printer, files on a personal machine, screens visible to other people.

Departures became invisible. In an office, a leaver's last week is observable. Remotely, the entire notice period happens where nobody can see it, and equipment return is a logistics problem rather than a handover.

Access provisioning got looser. Rapid remote onboarding, broad access granted to reduce friction, and access reviews that were already weak becoming weaker.

What did not change as much as claimed

Motivation. The reasons people take data — leaving for a competitor, grievance, belief in ownership — are not created by working location.

Volume of incidents. Where organisations measured properly, the increase was less dramatic than the commentary suggested. What increased noticeably was the difficulty of detecting them.

The dominance of error. Most incidents remain mistakes rather than malice, remotely as in the office.

The genuinely new exposures

Personal cloud storage as a working tool. Sync clients on home machines blur the boundary between corporate and personal data continuously rather than in discrete acts.

Screen sharing. People share screens constantly, frequently showing more than intended. This is a real and unmeasured route.

External AI assistants. Pasting proprietary content into a language model is now routine in many organisations, is invisible without endpoint or inspection coverage, and was not in anyone's threat model three years ago.

Blurred device ownership. Corporate mail on a personal phone, a personal laptop used because the corporate one is slow.

What actually works

Cloud audit logs, which became the primary source when network visibility fell. Sharing state, external access, bulk download — all visible in the platforms.

Endpoint agents, now carrying more of the load than they were designed for. Worth reviewing whether coverage matches that expectation.

Access reduction, which is location-independent and reduces the population who could take anything.

The departing employee process, which needs deliberate design remotely because none of it happens by observation.

What works less well

Behavioural baselines, which were disrupted by the transition and by the continuing variability of remote working patterns. Someone working unusual hours across time zones looks anomalous permanently.

Peer group comparison, where the group is now distributed across contexts that differ substantially.

Physical controls. Clear desk, restricted printing, visitor management — all irrelevant to a home office.

The disproportionate response

The most common organisational reaction was to deploy employee monitoring software framed as insider risk management: screen recording, activity tracking, keystroke logging.

This addresses none of the exposures above. It does not see cloud sharing, does not see AI paste, does not see the departing engineer's repository clone. What it produces is a surveillance capability with its own legal obligations, and a measurable cost to trust.

The controls that address the actual change are unglamorous: cloud audit logs, access reduction, endpoint coverage, and a departure process that runs deliberately rather than by observation.