A subject is influenced by a personal, familial, romantic, or close social relationship with an individual whose interests are affected by the subject’s organizational responsibilities. The relationship may involve a colleague, applicant, customer, supplier representative, contractor, investigation subject, complainant, or another person connected to an organizational decision. The conflict may arise where the subject can approve access, influence recruitment, award work, alter a case outcome, disclose information, suppress scrutiny, or provide another form of preferential treatment. The existence of a personal relationship does not itself establish harmful intent. The investigative concern arises where the relationship creates a material conflict with the subject’s duties and is not disclosed through the organization’s required process. Relevant indicators may include repeated favorable decisions, unusual access to information concerning the connected person, involvement in matters from which the subject should have recused themselves, or communications inconsistent with the stated professional relationship. Investigators should establish the nature and timing of the relationship, the subject’s disclosure obligations, the decisions or access affected by it, and whether the subject took steps to conceal the connection. The resulting infringement may separately involve abuse of decision-making authority, unauthorized data access, data disclosure, fraud, or interference with an investigation.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active....
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests and their organizational responsibilities. Disclosures should be required when a conflict arises and through periodic attestations. They should be reviewed by an authorized function such as Human Resources, Legal, Compliance, or Ethics, with the outcome and any management measures formally recorded. Controls may include recusal, independent approval, reassignment, segregation of duties, access restrictions, or removal from the affected activity. Subjects should not participate in relevant decisions while a material conflict remains undisclosed or unresolved. The policy should define consequences for deliberate non-disclosure, false declarations, failure to follow an agreed management plan, and retaliation against individuals who report suspected conflicts.
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests a...
An Acceptable Use Policy (AUP) is a set of rules outlining acceptable and unacceptable uses of an organization's computer systems and network resources. It acts as a deterrent to prevent employees from conducting illegitimate activities by clearly defining expectations, reinforcing legal and ethical standards, establishing accountability, specifying consequences for violations, and promoting education and awareness about security risks.
An Acceptable Use Policy (AUP) is a set of rules outlining acceptable and unacceptable uses of an organization's computer systems and network resources. It acts as a deterrent to prevent employees fro...
Implement a process whereby HR data and observations, including those from managers and colleagues, can be securely communicated in a timely manner to investigators, triggering proactive monitoring of potential insider threats early in their lifecycle. Collaboration between HR teams, managers, colleagues, and investigators is essential for detecting concerning behaviors or changes in an employee's personal circumstances that could indicate an increased risk of insider threat. Mental Health and Personal StrugglesTrigger Event: HR receives reports or observes a significant change in an employee's behavior or performance, which may indicate mental health issues or personal struggles that could elevate the likelihood of an insider threat. This information may come from managers, colleagues, or direct observations within HR.Indicator: Multiple reports from managers, direct supervisors, or colleagues highlighting behavior changes such as stress, depression, or erratic actions.Response: HR teams should notify investigators of high-risk employees with visible signs of distress or any reported instances that might indicate susceptibility to manipulation or exploitation. Negative Statements or Discontent with the CompanyTrigger Event: HR identifies instances of employees making negative statements about the company, its leadership, or its operations, potentially through personal social media channels, internal communications, or third-party reports. Additionally, such concerns might be raised by managers or colleagues.Indicator: Recorded incidents where employees voice dissatisfaction in forums or interactions that may expose vulnerabilities within the company, which may come from colleagues, managers, or HR’s internal channels.Response: Immediate referral to investigators for further investigation, including tracking if such sentiments are coupled with any increase in risky behaviors (e.g., accessing sensitive data or systems without authorization). Excessive Financial Purchases (Potential Embezzlement or Third-Party Influence)Trigger Event: HR or finance teams notice discrepancies in an employee's personal financial behavior—particularly excessive spending patterns that appear inconsistent with their known salary or financial profile. This could indicate embezzlement, financial mismanagement, or payments from third parties. Such concerns may also be raised by managers or colleagues.Indicator: Transactions that show a high degree of personal spending or financial behavior inconsistent with the employee’s compensation, possibly flagged by HR, finance, or colleagues who notice unusual behaviors.Response: Referral to investigators for correlation with employee access to financial or sensitive company systems, along with further scrutiny of potential illicit financial transactions. Third-party or whistleblower reports, including from colleagues or managers, may also be investigated as part of a broader risk assessment. Hearsay and Indirect ReportsTrigger Event: Anonymous or informal reports—such as rumors or gossip circulating in the workplace—that hint at potential insider threat behaviors. These reports, often from colleagues or managers, may be unsubstantiated, but they still warrant an alert if the volume or credibility of the information increases.Indicator: Reports or concerns raised by employees, colleagues, or external parties suggesting that an employee may be engaging in unusual behaviors, such as excessive contact with external vendors, financial irregularities, or internal dissatisfaction.Response: Investigators work with HR to assess the situation by cross-referencing any concerns, including those from colleagues or managers, with the employee's activity patterns, communication, and access to sensitive systems. Implementation ConsiderationsCollaboration Framework: A clear and secure protocol for HR, managers, colleagues, and investigators to share critical information regarding employees at risk. This should maintain employee privacy and legal protections, while still enabling timely alerts.Confidentiality and Privacy: All information related to personal behavior, health, or financial matters must be handled with sensitivity and in accordance with legal and regulatory frameworks, such as GDPR or local privacy laws.Continuous Monitoring: Once flagged, employees should be monitored for any other risk indicators, including changes in data access patterns, unapproved system access, or behavior that correlates with identified risks.
Implement a process whereby HR data and observations, including those from managers and colleagues, can be securely communicated in a timely manner to investigators, triggering proactive monitoring of...
The process for having software installed on a corporate endpoint by IT should require approval from the employee's line manager to ensure the request is legitimate and appropriate.
The process for having software installed on a corporate endpoint by IT should require approval from the employee's line manager to ensure the request is legitimate and appropriate....
Multi-party approval enforcement requires that designated high-risk or sensitive actions undergo validation by two or more independent approvers before execution. This control ensures that no single subject can unilaterally authorize actions that carry elevated operational, financial, or security impact. Sensitive actions should be clearly defined and may include privilege elevation, financial transactions above defined thresholds, production changes, access to restricted data, or policy exceptions. Approval must be enforced at the system level, preventing execution unless all required approvals are obtained. To maintain effectiveness, approvers must be independent of the requesting subject, with separation enforced through role design, reporting lines, or system constraints. Approval chains should not be user-selectable where possible, and must be resistant to manipulation or bypass. This control directly mitigates behaviors associated with oversight degradation by introducing mandatory independent validation, reducing the likelihood that actions can proceed without scrutiny or through unilateral influence.
Multi-party approval enforcement requires that designated high-risk or sensitive actions undergo validation by two or more independent approvers before execution. This control ensures that no single s...
An agent capable of User Activity Monitoring (UAM) is a software agent installed on organization endpoints (such as laptops); typically, User Activity Monitoring agents are only deployed on endpoints where a human user Is expected to conduct the activity. The User Activity Monitoring agent will typically record Operating System, application, and network activity occurring on an endpoint, with a focus on activity that is or can be conducted by a human user. The purpose of this monitoring is to identify undesirable and/or malicious activity being conducted by a human user (in this context, an Insider Threat). Typical User Activity Monitoring platforms operate in an agent/server model where activity logs are sent to a server for automatic correlation against a rule set. This rule set is used to surface activity that may represent Insider Threat related activity such as capturing screenshots, copying data, compressing files or installing risky software. Other platforms providing related functionality are frequently referred to as User Behaviour Analytics (UBA) platforms.
System logs
An agent capable of User Behaviour Analytics (UBA) is a software agent installed on organizational endpoints (such as laptops). Typically, User Activity Monitoring agents are only deployed on endpoints where a human user is expected to conduct the activity. The User Behaviour Analytics agent will typically record Operating System, application, and network activity occurring on an endpoint, focusing on activity that is or can be conducted by a human user. Typically, User Behaviour Analytics platforms operate in an agent/server model where activity logs are sent to a server for automatic analysis. In the case of User Behaviour Analytics, this analysis will typically be conducted against a baseline that has previously been established. A User Behaviour Analytic platform will typically conduct a period of ‘baselining’ when the platform is first installed. This baselining period establishes the normal behavior parameters for an organization’s users, which are used to train a Machine Learning (ML) model. This ML model can then be later used to automatically identify activity that is predicted to be an anomaly, which is hoped to surface user behavior that is undesirable, risky, or malicious. Other platforms providing related functionality are frequently referred to as User Activity Monitoring (UAM) platforms.
System logs
Provide a process for all staff members to report concerning and/or suspicious behaviour to the organization's security team for review. An internal whistleblowing process should take into consideration the privacy of the reporter and the subject(s) of the report, with specific regard to safeguarding against reprisals against reporters.
Multiple sources
This technique is part of the Forscie® Insider Threat Matrix™. Copyright 2026 Forscie® Limited. Licensed under Apache License 2.0.
View on Forscie® Insider Threat Matrix™