Staffing an Insider Risk Function
- kind
- Reference
- domain
- People
- stage
- Programme design
- read
- 3 min
- assumes
- No prior programme in place
The roles a working programme needs, what one person can realistically cover, and where organisations under-resource.
Programmes are budgeted for the product and staffed as an afterthought. The operating cost usually exceeds the licence within two years, and the shortfall shows up as an unreviewed alert queue.
The work that has to happen
Detection engineering. Writing and refining policies, adding context, managing exclusions. Continuous, not a deployment task.
Alert review. Daily. Someone looks at output and decides what it means.
Investigation. Occasional, intensive, and requiring different skills from review.
Exception management. Legitimate workflows need documented exclusions with review dates. Left undone, exclusions accumulate as undocumented holes.
Relationship work. HR, legal, the business. Not optional — this is what turns findings into outcomes.
Reporting and governance. Metrics, access audits, programme review.
What one person can cover
For a mid-sized organisation with two or three channels instrumented and a tuned alert volume: one person can do review, exception management and light detection engineering.
They cannot also run investigations. An investigation consumes days, during which the alert queue is unreviewed — which means the programme is blind exactly when someone is paying attention to it.
The realistic minimum for a functioning programme is one full-time equivalent for operations plus access to investigation capability, whether that is a second person, a wider security team, or a retained external capability.
Organisations that staff it at half a person alongside other duties end up with a log.
Where it should sit
Security operations is the common home. Advantages: existing rota, incident practice, tooling. Risk: insider cases get handled as technical incidents, and the employee-relations dimension is missed.
A separate risk function reporting outside the security line. Advantages: independence, easier relationship with HR and legal. Risk: isolation from technical capability.
Within HR. Unusual, and it works where the emphasis is on negligence and awareness rather than technical detection.
There is no correct answer. What matters is that the reporting line does not create a conflict — for example, the person who investigates reporting to the person whose team is investigated.
Skills that are undervalued
Judgement about people. The core of triage is deciding whether an action was a mistake, a shortcut or something worse. This is not a technical skill and it is the one that determines whether the programme damages people.
Writing. Findings go to HR, legal and executives. An analyst who cannot write a clear factual report produces work that cannot be acted on.
Restraint. The ability to leave an alert alone. Analysts who develop theories about colleagues and pursue them cause the most damage a programme can do.
Business literacy. Knowing what the finance team actually does is what distinguishes an anomaly from a Tuesday.
Skills that are overvalued
Deep forensic capability, for most organisations. Serious investigations are rare and the specialist work can be retained externally when needed. Hiring for it means paying continuously for something used twice a year, and the person will be bored.
The rotation question
Reviewing colleagues' activity is corrosive over time. People in the role develop a suspicious reading of ordinary behaviour, and it affects them.
Rotate where you can. Cap the time anyone spends in continuous review.
Discuss cases in pairs. It checks individual bias and reduces the isolation.
Give the role clear boundaries — what is in scope, what is not — so the person is not carrying an open-ended surveillance responsibility.
This is rarely considered in programme design and it is the reason experienced people leave the role.