Harm from within.
WHAT IT MOSTLY IS
Accidents.
A file shared broadly, an email to the wrong person, data taken home for convenience.
WHAT REDUCES ACCIDENTAL HARM
Minimum access necessary Clear procedures Making the safe route the easy one
THAT LAST POINT
If the secure way is difficult, people find another way.
WHAT DELIBERATE INSIDER RISK LOOKS LIKE
Data taken before departure Access retained after leaving Misuse of legitimate access
WHAT REDUCES IT
Access limited to what each role needs Access removed promptly on departure Monitoring of unusual activity, such as bulk exports
WHAT TO DO ON DEPARTURE
Remove every access the same day Change shared credentials Recover devices
WHAT TO AVOID
Treating everyone as a suspect Monitoring that damages trust for little benefit
WHAT TO BALANCE
Proportion. Most people are honest, and controls should reflect that while limiting damage.
WHAT TO DOCUMENT
Who has access to what, so removal is complete.