Index / Programme design

Working With HR and Legal

kind
Procedure
domain
People
stage
Programme design
read
3 min
assumes
No prior programme in place

The relationships that determine whether findings lead to outcomes or sit in a queue.

A security team can detect an insider incident and do nothing about it. Consequences for an employee run through HR and legal, and a programme without those relationships produces findings that go nowhere.

Why the relationship is difficult

The three functions have different starting positions, and each is reasonable.

Security sees risk and wants to act quickly.

HR is responsible for fair process, employee relations and the consequences of getting an accusation wrong. They have seen investigations collapse and know the cost.

Legal is responsible for defensibility — whether evidence was lawfully obtained, whether process was followed, whether the organisation is exposed.

These conflict most sharply at the moment security wants to act and the others want to slow down. That moment is not the time to build the relationship.

Establish the process before the first case

Agree who is told, when. At what point does a security finding become an HR matter? Too early and you generate cases from unreviewed alerts; too late and evidence is stale and process is compromised.

A workable threshold: security triages, and involves HR when the evidence suggests deliberate action or when a person will need to be interviewed.

Agree who leads. Once it involves an employee's conduct, HR usually leads and security supports with technical findings. Security teams that continue to drive tend to make process errors that undo the case.

Agree what security provides. A factual technical report, not a conclusion about intent. "This account transferred 4,200 files to an external drive on these dates" is evidence. "This employee stole data" is a determination HR and legal make.

Agree confidentiality. Who knows an investigation is running. The subject's manager frequently should not, at least initially.

What security gets wrong

Presenting conclusions instead of evidence. It provokes resistance and, when the conclusion is wrong, destroys credibility for years.

Over-claiming certainty. Behavioural analytics produce probabilities. Presenting an anomaly score as proof invites a challenge you will lose.

Ignoring process requirements. Interviewing an employee without HR present, or without the representation they are entitled to, can make the whole case unusable.

Going too early. A referral based on an untuned alert costs credibility disproportionately. Two bad referrals and HR treats everything from security as noise.

What HR and legal get wrong

Treating technical evidence as unintelligible and therefore discounting it. Security has an obligation to explain findings in language that a non-specialist can evaluate, and frequently does this badly — but the answer is explanation, not dismissal.

Delay. Insider cases have a clock: the person still has access. A process taking six weeks to decide whether to suspend access is not a process.

Reluctance to act on negligence. The majority of incidents are careless rather than malicious, and the correct response is usually not disciplinary. But "not disciplinary" is not the same as "nothing" — education and process change need someone to own them.

The practical mechanism

A standing forum, monthly, with the three functions represented. Reviews cases, patterns and process. Builds the relationship before a crisis requires it.

A written joint procedure covering thresholds, roles, evidence handling, confidentiality and timelines. Agreed and signed by all three.

A rehearsal. Walk through a hypothetical case end to end. Every organisation that does this discovers a gap, and discovering it in a rehearsal is considerably cheaper.

The point of alignment

All three functions want the same outcome: harm prevented, people treated fairly, and the organisation able to defend what it did.

Stated that way the disagreements are about sequencing rather than goals, which is a much easier conversation than the one that happens at 5pm on a Friday with an employee's access still active.