A subject owns, operates, advises, supports, or materially benefits from an external business whose activities or interests conflict with their responsibilities to the organization. The external interest may include a private company, consultancy, partnership, directorship, freelance operation, side business, or commercial activity conducted through another person. The business does not need to be a direct competitor. A conflict may also arise where it supplies similar services, seeks access to the same customers, depends on organizational resources, or could benefit from information available through the subject’s role. The subject may use organizational working time, information, equipment, personnel, customer relationships, intellectual property, or decision-making authority to support the external business. They may also direct opportunities away from the organization, influence supplier or customer decisions, or conceal the extent of their involvement. Investigators should establish the subject’s ownership, management, advisory, or beneficial relationship with the external business and determine whether it was disclosed. Relevant evidence may include corporate records, professional profiles, business websites, invoices, communications, device activity, customer contact, use of organizational resources, and work performed during contracted hours. This Sub-section should be distinguished from IF038 – Undisclosed Concurrent Employment. Undisclosed Concurrent Employment captures the infringement of maintaining or performing undisclosed external work where disclosure is required. External Business Interest describes the conflict acting as a motive that may influence a wider range of harmful conduct.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active.
Routine reviews of user accounts and their associated privileges and permissions should be conducted to identify overly-permissive accounts, or accounts that are no longer required to be active....
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests and their organizational responsibilities. Disclosures should be required when a conflict arises and through periodic attestations. They should be reviewed by an authorized function such as Human Resources, Legal, Compliance, or Ethics, with the outcome and any management measures formally recorded. Controls may include recusal, independent approval, reassignment, segregation of duties, access restrictions, or removal from the affected activity. Subjects should not participate in relevant decisions while a material conflict remains undisclosed or unresolved. The policy should define consequences for deliberate non-disclosure, false declarations, failure to follow an agreed management plan, and retaliation against individuals who report suspected conflicts.
Organizations should maintain a formal policy requiring subjects to disclose actual, potential, or perceived conflicts between their personal, financial, professional, or external business interests a...
An individual’s prior employment history may be verified through formal reference checks conducted prior to their onboarding with the organization. This process aims to validate key aspects of the subject’s professional background, including dates of employment, job titles, responsibilities, and performance, as well as behavioral or conduct-related concerns. Reference checks serve as a critical layer in assessing an individual’s suitability for a given role, particularly where access to sensitive systems, data, or personnel is involved. When conducted thoroughly, this process can help identify discrepancies in a candidate’s reported history, uncover patterns of misconduct, or reveal concerns related to trustworthiness, reliability, or alignment with organizational values. Employment reference checks are particularly relevant to insider threat prevention when evaluating candidates for positions involving privileged access, managerial authority, or handling of confidential information. These checks may also uncover warning signs such as unexplained departures, disciplinary actions, or documented integrity issues that elevate the risk profile of the individual. Organizations may perform this function internally or engage trusted third-party screening providers who specialize in pre-employment due diligence. When combined with other vetting measures—such as criminal background checks and social media screening—reference checks contribute to a layered approach to workforce risk management and help mitigate the likelihood of malicious insiders gaining access through misrepresentation or concealment.
An individual’s prior employment history may be verified through formal reference checks conducted prior to their onboarding with the organization. This process aims to validate key aspects of the sub...
An Acceptable Use Policy (AUP) is a set of rules outlining acceptable and unacceptable uses of an organization's computer systems and network resources. It acts as a deterrent to prevent employees from conducting illegitimate activities by clearly defining expectations, reinforcing legal and ethical standards, establishing accountability, specifying consequences for violations, and promoting education and awareness about security risks.
An Acceptable Use Policy (AUP) is a set of rules outlining acceptable and unacceptable uses of an organization's computer systems and network resources. It acts as a deterrent to prevent employees fro...
Organizations should include a clear exclusivity clause in employment contracts, contractor agreements, or related policy documents stating that a subject must not perform work for another employer, client, commercial entity, or personal business during contracted working hours without prior authorization. The clause should focus on working-time availability, conflict of interest, and protection of organizational information. It should require disclosure and approval of any secondary employment or commercial activity that may overlap with contracted hours, reduce the subject’s availability, involve a competitor, supplier, customer, or other sensitive third party, or create a risk that organizational systems, information, contacts, materials, or work product could be misused. The clause should also prohibit the use of organization-owned devices, accounts, credentials, networks, collaboration platforms, documents, customer information, intellectual property, or internal contacts for secondary employment or external commercial activity unless expressly authorized. To remain jurisdiction-neutral, the clause should not attempt to prohibit all outside work. It should instead establish a defensible requirement that the subject remain available during contracted working hours, disclose relevant external work, avoid conflicts of interest, and protect organizational assets and information.
Organizations should include a clear exclusivity clause in employment contracts, contractor agreements, or related policy documents stating that a subject must not perform work for another employer, c...
Implement a process whereby HR data and observations, including those from managers and colleagues, can be securely communicated in a timely manner to investigators, triggering proactive monitoring of potential insider threats early in their lifecycle. Collaboration between HR teams, managers, colleagues, and investigators is essential for detecting concerning behaviors or changes in an employee's personal circumstances that could indicate an increased risk of insider threat. Mental Health and Personal StrugglesTrigger Event: HR receives reports or observes a significant change in an employee's behavior or performance, which may indicate mental health issues or personal struggles that could elevate the likelihood of an insider threat. This information may come from managers, colleagues, or direct observations within HR.Indicator: Multiple reports from managers, direct supervisors, or colleagues highlighting behavior changes such as stress, depression, or erratic actions.Response: HR teams should notify investigators of high-risk employees with visible signs of distress or any reported instances that might indicate susceptibility to manipulation or exploitation. Negative Statements or Discontent with the CompanyTrigger Event: HR identifies instances of employees making negative statements about the company, its leadership, or its operations, potentially through personal social media channels, internal communications, or third-party reports. Additionally, such concerns might be raised by managers or colleagues.Indicator: Recorded incidents where employees voice dissatisfaction in forums or interactions that may expose vulnerabilities within the company, which may come from colleagues, managers, or HR’s internal channels.Response: Immediate referral to investigators for further investigation, including tracking if such sentiments are coupled with any increase in risky behaviors (e.g., accessing sensitive data or systems without authorization). Excessive Financial Purchases (Potential Embezzlement or Third-Party Influence)Trigger Event: HR or finance teams notice discrepancies in an employee's personal financial behavior—particularly excessive spending patterns that appear inconsistent with their known salary or financial profile. This could indicate embezzlement, financial mismanagement, or payments from third parties. Such concerns may also be raised by managers or colleagues.Indicator: Transactions that show a high degree of personal spending or financial behavior inconsistent with the employee’s compensation, possibly flagged by HR, finance, or colleagues who notice unusual behaviors.Response: Referral to investigators for correlation with employee access to financial or sensitive company systems, along with further scrutiny of potential illicit financial transactions. Third-party or whistleblower reports, including from colleagues or managers, may also be investigated as part of a broader risk assessment. Hearsay and Indirect ReportsTrigger Event: Anonymous or informal reports—such as rumors or gossip circulating in the workplace—that hint at potential insider threat behaviors. These reports, often from colleagues or managers, may be unsubstantiated, but they still warrant an alert if the volume or credibility of the information increases.Indicator: Reports or concerns raised by employees, colleagues, or external parties suggesting that an employee may be engaging in unusual behaviors, such as excessive contact with external vendors, financial irregularities, or internal dissatisfaction.Response: Investigators work with HR to assess the situation by cross-referencing any concerns, including those from colleagues or managers, with the employee's activity patterns, communication, and access to sensitive systems. Implementation ConsiderationsCollaboration Framework: A clear and secure protocol for HR, managers, colleagues, and investigators to share critical information regarding employees at risk. This should maintain employee privacy and legal protections, while still enabling timely alerts.Confidentiality and Privacy: All information related to personal behavior, health, or financial matters must be handled with sensitivity and in accordance with legal and regulatory frameworks, such as GDPR or local privacy laws.Continuous Monitoring: Once flagged, employees should be monitored for any other risk indicators, including changes in data access patterns, unapproved system access, or behavior that correlates with identified risks.
Implement a process whereby HR data and observations, including those from managers and colleagues, can be securely communicated in a timely manner to investigators, triggering proactive monitoring of...
Background checks should be conducted to ensure whether the information provided by the candidate during the interview process is truthful. This could include employment and educational reference checks, and a criminal background check. Background checks can highlight specific risks, such as a potential for extortion.
Background checks should be conducted to ensure whether the information provided by the candidate during the interview process is truthful. This could include employment and educational reference chec...
An agent capable of Endpoint Detection and Response (EDR) is a software agent installed on organization endpoints (such as laptops and servers) that (at a minimum) records the Operating System, application, and network activity on an endpoint. Typically EDR operates in an agent/server model, where agents automatically send logs to a server, where the server correlates those logs based on a rule set. This rule set is then used to surface potential security-related events, that can then be analyzed. An EDR agent typically also has some form of remote shell capability, where a user of the EDR platform can gain a remote shell session on a target endpoint, for incident response purposes. An EDR agent will typically have the ability to remotely isolate an endpoint, where all network activity is blocked on the target endpoint (other than the network activity required for the EDR platform to operate).
System logs
An agent capable of User Activity Monitoring (UAM) is a software agent installed on organization endpoints (such as laptops); typically, User Activity Monitoring agents are only deployed on endpoints where a human user Is expected to conduct the activity. The User Activity Monitoring agent will typically record Operating System, application, and network activity occurring on an endpoint, with a focus on activity that is or can be conducted by a human user. The purpose of this monitoring is to identify undesirable and/or malicious activity being conducted by a human user (in this context, an Insider Threat). Typical User Activity Monitoring platforms operate in an agent/server model where activity logs are sent to a server for automatic correlation against a rule set. This rule set is used to surface activity that may represent Insider Threat related activity such as capturing screenshots, copying data, compressing files or installing risky software. Other platforms providing related functionality are frequently referred to as User Behaviour Analytics (UBA) platforms.
System logs
An agent capable of User Behaviour Analytics (UBA) is a software agent installed on organizational endpoints (such as laptops). Typically, User Activity Monitoring agents are only deployed on endpoints where a human user is expected to conduct the activity. The User Behaviour Analytics agent will typically record Operating System, application, and network activity occurring on an endpoint, focusing on activity that is or can be conducted by a human user. Typically, User Behaviour Analytics platforms operate in an agent/server model where activity logs are sent to a server for automatic analysis. In the case of User Behaviour Analytics, this analysis will typically be conducted against a baseline that has previously been established. A User Behaviour Analytic platform will typically conduct a period of ‘baselining’ when the platform is first installed. This baselining period establishes the normal behavior parameters for an organization’s users, which are used to train a Machine Learning (ML) model. This ML model can then be later used to automatically identify activity that is predicted to be an anomaly, which is hoped to surface user behavior that is undesirable, risky, or malicious. Other platforms providing related functionality are frequently referred to as User Activity Monitoring (UAM) platforms.
System logs
Provide a process for all staff members to report concerning and/or suspicious behaviour to the organization's security team for review. An internal whistleblowing process should take into consideration the privacy of the reporter and the subject(s) of the report, with specific regard to safeguarding against reprisals against reporters.
Multiple sources
Social Media Monitoring refers to monitoring social media interactions to identify organizational risks, such as employees disclosing confidential information and making statements that could harm the organization (either directly or through an employment association).
Multiple sources
This technique is part of the Forscie® Insider Threat Matrix™. Copyright 2026 Forscie® Limited. Licensed under Apache License 2.0.
View on Forscie® Insider Threat Matrix™