Insider Risk in Small Organisations
- kind
- Checklist
- domain
- Programme
- stage
- Context
- read
- 2 min
- assumes
- No prior programme in place
Most guidance assumes a security team and a budget. What to do with neither.
Advice in this field is written for organisations with a security function, a DLP platform and someone to review alerts. Most organisations have none of these and the same exposure.
What does not transfer
Behavioural baselines. With twelve people, everyone is an outlier and peer comparison is meaningless.
Separation of duties. The person who would investigate is the person who administers the systems is frequently the person who would be investigated.
A tuned alert queue. Nobody has capacity to review anything daily.
A DLP platform. The licence and the operating cost exceed what is available, and an unmaintained deployment is worse than none.
What does transfer, and costs almost nothing
Access reduction. The most effective control at any size and the cheapest at small size, because the systems are few and the decisions are quick. Who can reach the customer list, the financials, the code? In a small organisation that question has a short answer and the answer is usually "more people than necessary".
Cloud audit logs. Your email and file platforms already record external sharing, forwarding rules and bulk downloads. Reviewing them monthly costs an hour and catches most of what matters.
Alerting on forwarding rules. Available in every mail platform, near-zero false positives, covers both compromise and deliberate exfiltration.
Restricting external sharing defaults. Change the default from "anyone with the link" to "specific people". One setting, large effect.
Removable media policy. Block or restrict. The exceptions in a small organisation are enumerable.
A departure process. Written down: access removed same day, cloud files reassigned, equipment returned, shared credentials rotated, and an explicit conversation about what belongs to the company.
That list costs a few days of work in total and addresses most realistic exposure.
The specific small-organisation risks
Everyone can access everything. Frequently deliberate โ small teams need to move quickly. It also means a single departure can take the entire business.
Founder and administrator overlap. One or two people hold complete access with no oversight at all. Uncomfortable to raise and worth raising.
Shared accounts. A single login for a critical service, credentials known to several people, never rotated. Attribution is impossible and departure means the credential is gone.
No offboarding. People leave and accounts persist because nobody owns the process.
Personal accounts holding company assets. A domain registered to someone's personal email, a cloud account under a founder's personal identity. This is the risk that ends companies and it is almost universal in small ones.
The one-page programme
For an organisation without a security function:
Write down the three things that would hurt most if they left. Note who can reach each, and remove anyone who does not need it. Turn on alerts for external forwarding rules. Set external sharing to require named recipients. Review the sharing report monthly. Have a written departure checklist and follow it. Make sure company assets are registered to company accounts.
That is the whole programme. It is not sophisticated and it covers more than most enterprise deployments do in their first year.
When to buy something
When you have someone who will operate it. Not before.
A DLP product with nobody reviewing its output produces licence cost, an unreviewed log, and a false belief that the problem is handled. The order is capacity first, tooling second, at any size.