Inside
Careless costs the same as malicious
Within one per cent, per incident. The question everybody asks first turns out not to predict the thing everybody is worried about.
Last reviewed August 30, 2026
- Intent predicts the remedy, not the bill. And organisations buy for the rare half.
- The leaving starts weeks before the resignation. Every control aimed at the notice period is already late.
- Offboarding misses what was never central. Departmental services and shared passwords survive it.
- Narrowing access helps against all three. Carelessness, malice and the stolen session alike.
The day the access goes
10 events around one departure — 3 extractions, 4 pieces of ordinary work and 3 that could be either. Move the line and watch both counts move together. A model of the shape rather than anybody's case.
- Accepts an offer elsewhere; tells nobody at work45 days before
Nothing observable happens and the relationship has already changed. Every control discussed below is aimed at a period that begins here and that the employer cannot see.
- Downloads the full customer list to a laptop38 days before
Genuinely ambiguous. It is also what somebody preparing a quarterly review does, which is why blocking it outright is harder than it sounds.
- Emails four presentations to a personal address30 days before
The commonest single act in this whole subject, and the one most often described afterwards as taking my own work with me.
- Resigns; four weeks' notice begins28 days before
The first moment the organisation knows anything. Everything above already happened, which is the entire difficulty with a control that starts here.
- Documents processes and trains a replacement21 days before
The work the notice period exists for, and the reason cutting access at resignation is not the obvious answer it appears to be.
- Copies a project folder to a personal drive14 days before
Could be the handover, could be the portfolio. The distinction lives in the person's intention and nowhere in the logs.
- Shares a document library with a personal cloud account9 days before
Sharing outward rather than copying is the version most monitoring misses, because nothing leaves the building in a way a file transfer would show.
- Last day. Laptop returned, main account disabledthe last day
The date personnel records treat as the end of the relationship, and the only date most access reviews are built around.
- Still signed in to two services bought by their own team6 days after
Bought on a departmental card, never in the central directory, and therefore not on the list anybody works through on the last day.
- Uses a shared account whose password has not changed22 days after
Shared credentials survive every leaver process ever designed, because disabling a person does not disable a password four people know.
| Access removed | Extractions stopped | Ordinary work broken | Ambiguous stopped |
|---|---|---|---|
| 28 days before | 3 of 3 | 3 of 4 | 1 of 3 |
| the last day | 2 of 3 | 1 of 4 | 0 of 3 |
| 7 days after | 1 of 3 | 0 of 4 | 0 of 3 |
There is no position to recommend, and the reason is visible in the sequence: the handover and the extraction occupy the same fortnight. What good practice actually does is stop treating this as one switch. Reduce what the account can reach on the day of the resignation, keep the things the handover needs, and remove the rest — which is more work than a single date and is the only version that survives contact with an actual notice period.
Does it matter whether they meant it?
The first question asked about any internal incident is whether the person did it on purpose, and the answer determines everything that follows: whether it becomes a disciplinary matter, whether lawyers are involved, how it is described internally, and whether anybody sleeps. It is a reasonable question and it is the wrong one to organise a programme around.
The costs are nearly identical. A careless incident averages $747,107 and a deliberate one $742,125, which is a difference of about 0.7% — well inside the noise of any study that produces such figures. The customer records are equally exposed whether they were emailed to a competitor or attached to the wrong recipient, and the regulator asks the same questions either way.
Where the two diverge is frequency, and it diverges hard: roughly 13.8 careless incidents a year against 6.3 malicious, about 2.2 times as many. Multiply that out and negligence dominates the annual total, at around $10.3m of a roughly $19.5m bill, and it is growing faster than the rest.
The spending goes the other way. Monitoring products, behavioural analytics and vetting are aimed at catching the deliberate actor, who is rare, while the systemic changes that would prevent the common case — narrower access, fewer places data can be copied to, defaults that make the safe path the easy one — get argued about for years. Intent is the right question for what to do about a person and the wrong question for what to do about a risk.
The employee who was never an employee
A category arrived in the last two years that the vocabulary does not accommodate. Somebody applies for a remote technology role, interviews well, provides references that check out, signs a contract, receives a laptop and is paid a salary. They are also working on behalf of somebody else, and the salary is a secondary objective rather than the point.
The scale is no longer marginal. Fraudulent remote technology workers reached around 5% of investigated incidents in one large body of casework, and activity of that kind rose roughly 220% year on year in another. The economics are obvious once stated: hiring is cheaper than intrusion, produces better access than any exploit, and is entirely legal until the moment it is not.
It dissolves the distinction the whole subject is named after. An insider is supposed to be somebody who was trusted and then betrayed that trust; this is somebody who obtained the trust in order to use it, which is an outsider by motivation and an insider by every technical measure your controls can see. Nothing in an access review distinguishes them, because their access is correct.
Which puts the detection where security teams cannot reach. The signals are in recruitment: reluctance to appear on camera, an address that does not match the tax record, equipment shipped somewhere other than the stated home, patterns of work that fit a different time zone, an unusual sequence of employers with no overlapping colleagues. Every one of those belongs to somebody in human resources, and in most organisations nobody has ever asked them to look.
What does watching people actually catch?
Products that monitor staff behaviour promise to spot the person before they act, and they do catch things. What they catch is the unsubtle version: a large volume of files copied at once, a device attached at an unusual hour, a download far outside somebody's normal pattern. Those are real detections and they are worth having.
The failure mode is that the modern version of taking data does not move any data. A folder shared outward with a personal account transfers nothing; a document opened and screenshotted leaves no trace in any file log; an export scheduled to a service the organisation already uses looks exactly like the reporting somebody set up last year. The tooling was designed against a picture of exfiltration that involved something visibly leaving.
There is also a cost that does not appear in the business case. Heavy surveillance produces compliance without candour: people stop reporting their own mistakes, because the mistake is now evidence. Since carelessness is the larger half of this problem and self-reporting is how carelessness gets caught early, a programme that deters the reporting can raise the cost of the thing it was bought to reduce.
The proportionate version is narrow and boring. Monitor the small number of accounts and systems where the consequence is severe, tell everybody exactly what is watched and why, and stay away from the general-purpose observation of ordinary staff. Organisations that do that keep the detections and avoid the atmosphere, and the second is worth more than most people budgeting for the first believe.
The leaver process everybody has and nobody finishes
Every organisation of any size has a documented offboarding procedure, and almost none of them are complete, for a reason that has nothing to do with diligence. The procedure works from a list, the list comes from the central directory, and a substantial part of the modern estate never entered the central directory. The extreme case is the credential that never had a joining date either, which is a problem of ownership rather than of departure.
The gaps are consistent enough to be predicted. Services bought by a department on a card, which nobody in technology knows exist. Access granted directly to a person rather than through a group, which disappears from view the moment the person who granted it moves on. Shared credentials known to four people, where disabling an account changes nothing because the password is the account. And whatever the person set up themselves to do their job, which is frequently the thing they were praised for.
The fix is unglamorous and it is a project rather than a policy: reconcile what is being paid for against what is in the directory, at least annually, and treat every service that appears on an invoice and not in the list as a finding. Most organisations that do this once discover between a tenth and a third of their software estate was invisible, and the discovery is worth more than the offboarding improvement that prompted it.
There is a second half nobody schedules. Somebody has to check afterwards — a fortnight later, from the outside — whether the departed account can still reach anything. It takes an hour, it is the only step that verifies rather than asserts, and in practice it is the step that gets dropped when the next leaver arrives.
The tired one makes a worse headline
630 entries here concern insiders, employees or human error. 124 use the word insider, 52 name error or negligence, and 481 discuss staff more broadly.
The solid portion is the share that names error or negligence rather than malice: about 6% across the first half of the period and roughly 10% across the second, and the smaller portion throughout. Coverage peaks in 2018 with 138. The imbalance is the point, and it is not a criticism of anybody: a deliberate act has a person, a motive and an ending, and a tired employee attaching the wrong file has none of those things. The earliest piece here using the word, To detect and manage the insider threat companies need to deploy advanced threat intelligence cso the resource for data security executives, is already framing it as a question of trust rather than of design.
What the imbalance produces downstream is a market. Products are built for the subject that gets written about, budgets are approved against the fear that gets described, and the larger, duller half of the problem is addressed by whoever has time left over. That is not a failure of the coverage; it is what coverage does, and it is worth knowing when reading any of it.
What about the one who was used?
The third category in the serious research is neither careless nor malicious, and it is the one most likely to be misfiled as either. Somebody's access is used against their employer without their agreement: a session stolen from their machine, a helpdesk deceived into resetting their factor, or the person themselves manipulated into performing an action they believed was legitimate.
From the logs it is indistinguishable from a deliberate act, which is why the investigation matters more here than anywhere else in this subject. An organisation that concludes too quickly will discipline somebody who was deceived, which is unjust and also expensive, because everybody else watching learns that reporting a suspicion is dangerous.
The remedies are the ones that do not depend on the person being reliable. Factors that cannot be relayed to somebody else. Sessions that expire rather than lasting a month. Limits on what a single account can reach, so that a compromised identity yields a department instead of an estate. Every one of those also helps against the other two categories, which makes them the best value in the entire subject.
And it argues for a particular tone. A workforce told that they are the last line of defence, and that vigilance is their responsibility, will conceal the moment they fail — and they will fail, because the deceptions are good. A workforce told that the systems are built to survive their mistakes reports faster, which is the single variable that most reliably reduces what an incident costs.
Whose problem is this in the organisation?
Insider risk falls into the gap between two functions, and the gap is where most of the failure lives. Security owns the technical detection and has no view of the person; human resources owns the person and has no view of the systems. Both are certain the other has it in hand, and the meeting where that is discovered normally takes place after an incident.
The division that works is unfashionable in its simplicity. Security detects acts. Managers notice people. Human resources owns the process that connects the two, including the awkward part where a concern about somebody's behaviour has to be recorded and acted on rather than mentioned in a corridor. Almost every deliberate insider act follows a grievance that at least one colleague already knew about.
That places an uncomfortable obligation on managers, and it is worth stating plainly rather than dressing up. Noticing that somebody has been passed over, is unusually angry about a decision, or has stopped speaking to the team is management, not surveillance, and the organisations that treat it as surveillance end up with neither. The intervention that follows is usually a conversation rather than a control.
The same division answers the fake-employee problem from the other end. If recruitment holds the signals and security holds the consequences, then somebody has to carry the finding across, and the only durable version is a standing arrangement rather than an escalation. A quarterly half-hour between the two functions costs nothing and is the most consistently absent control in this whole area.
The controls that pay for themselves
Almost every large internal loss shares a precondition: somebody who needed one system could reach forty. Narrowing that is the highest-value work available here and the least likely to be funded, because it produces no artefact, appears in no report, and its success is measured by things that did not happen.
Start with the data rather than the people. Find where the material that would actually hurt lives, which is usually fewer places than expected and never only the places the policy names. Then establish who can reach it today, which will produce an unpleasant number, and reduce that number until somebody complains. The complaint is the signal that the exercise reached the useful part.
Second, make the safe path the easy one. People email files to themselves because the sanctioned way of working from home is slow; they use personal storage because the approved service will not open on a phone. Every one of those is a design decision presenting as a discipline problem, and fixing the design removes a whole class of incident without anybody being trained about anything.
One caveat belongs on all of it. Every figure quoted here comes from surveys of organisations that were willing to describe their own losses, which selects for the larger and better-instrumented — a company with no logging cannot report an incident it never detected. The likely direction of the bias is comforting in one respect and alarming in another: the averages are probably inflated by the presence of expensive estates, and the frequencies are almost certainly understated everywhere else, because an unnoticed disclosure is indistinguishable from an uneventful year. Both distortions argue the same way: treat the averages as an order of magnitude rather than a budget line, and treat the frequencies as a floor. The honest reading of any survey in this field is that it describes the organisations capable of noticing, and that capability is unevenly distributed by size, sector and regulatory obligation. A hospital, a haulage firm and a hedge fund do not appear in such research in proportion to how many of them exist, and the resulting portrait flatters whoever already had the instrumentation.
A fourth deserves mention because it costs an afternoon and is almost never done: rehearse a departure that has gone wrong. Take a real leaver from six months ago, pretend the organisation later suspects them, and try to answer the questions an investigation would ask. What did they reach in their final fortnight? Which subscriptions were in their name? Did anybody verify, afterwards, that the accounts closed? Most organisations discover within an hour that they cannot answer any of the three, and the exercise produces a specific list of gaps rather than the vague unease that a policy review generates.
Third, and last because it is the one everybody starts with: keep records that would let you answer the question afterwards. Not surveillance of individuals, but logs of who reached what, kept long enough to cover a departure that becomes interesting two months later. It is the cheapest thing on this list, the least contentious, and the one most consistently discovered to be missing at the exact moment it is needed.
Common questions
What does insider risk cost?
Around $19.5m a year for the average organisation studied, up roughly 20% in three years. Negligence is the largest share at about $10.3m, itself rising some 17% year on year, which makes carelessness both the commonest and the fastest-growing part of the problem.
Is a careless insider really as expensive as a malicious one?
Per incident, almost exactly. Careless incidents average about $747,107 and malicious ones $742,125 — a difference of roughly 0.7%. The gap is in frequency rather than severity: around 13.8 careless incidents a year against 6.3 malicious, about 2.2 times as many.
Then why does everyone focus on malice?
Because it is a better story and it has a villain. Investigating a deliberate act produces a narrative, a person and an outcome; addressing negligence means admitting that a system made a mistake easy, which implicates the people commissioning the investigation.
What is an exploited insider?
Somebody whose access is used against their employer without their consent — a stolen session, a deceived helpdesk, or a person manipulated into acting. They are counted separately because the remedy is different again: neither training nor vetting helps, and the answer is limiting what any single account can reach.
Are fake employees a real phenomenon?
Increasingly. Fraudulent remote technology workers accounted for around 5% of investigated incidents in one large body of casework, and activity of that kind rose about 220% year on year in another. They are hired through the front door, with references, and issued a laptop.
How would you notice one?
Through recruitment rather than security tooling. Repeated reluctance to appear on camera, an address that does not match the tax record, equipment shipped somewhere other than the stated home, and a working pattern that fits a different time zone are the signals, and every one of them belongs to somebody in human resources rather than in a security operations centre.
When should a leaver's access be removed?
Earlier than the last day and later than the resignation, which is to say there is no correct answer. Access that ends at resignation prevents the handover the notice period exists for; access that survives to the last day covers a period in which the person has been leaving for weeks.
What gets missed in offboarding?
The systems nobody central knows about. Services bought on a departmental card, shared accounts whose password four people know, and access granted directly rather than through a group all survive a leaver process built around a directory, because they were never in the directory.
Does monitoring staff work?
It catches the obvious and costs more than the obvious is worth. Copying a large volume of files is detectable; sharing a folder outward with a personal account frequently is not, because nothing leaves. The deeper cost is cultural, and organisations that surveil heavily report the deterioration before they report a catch.
Is this security's problem or the manager's?
Both, and the split matters. Detecting the act belongs to security; noticing the person belongs to whoever they report to. Most deliberate insider acts follow a grievance that somebody was already aware of, and no technical control substitutes for a manager who has noticed.
What is the cheapest thing that helps?
Reducing what an ordinary account can reach. Most large insider losses were possible because somebody who needed one system could reach forty, and narrowing that helps against carelessness, malice and the stolen session equally — which is unusual, because most controls help against one of the three.
Does trusting people less actually work?
Not as a policy. Organisations that treat staff as suspects get compliance without candour, which means mistakes are hidden rather than reported, and a hidden mistake is the expensive kind. What works is designing systems where an ordinary error cannot become an incident.
Insiders in the archive
630 entries, peaking in 2018 with 138.
- Ctos see human error ransomware and phishing as biggest security threats
November 25, 2021
- Businesses are underestimating risk in the digital age
November 17, 2021 · itproportal.com
- Most Employees Want Stronger Enforcement of Cybersecurity Protocols in the Workplace, Survey Finds
November 16, 2021 · nextgov.com
- 4 ways companies can increase their cybersecurity
November 12, 2021 · techrepublic.com
- How Can Pensions Best Protect Against Cybersecurity Threats?
November 9, 2021 · ai-cio.com
- Navigating the cybersecurity implications of remote work
November 1, 2021 · crainscleveland.com
- Suspected REvil Gang Insider Identified
October 29, 2021 · threatpost.com
- Most firms think remote employees pose more risk than office workers
October 28, 2021 · itproportal.com
- WFH is here to stay: Five tactics to improve security for remote teams
October 19, 2021 · helpnetsecurity.com
- Why the hybrid work era keeps IT and cybersecurity professionals up at night
October 13, 2021 · hartfordbusiness.com
- Why Buying Unneeded Tools Is Fueling The Cybersecurity Problem For Businesses
October 12, 2021 · forbes.com
- Cybersecurity: A growing risk each day
October 11, 2021 · indicanews.com
- BYOD security warning: You can't do everything securely with just personal devices
October 8, 2021 · zdnet.com
- 6 Ways to Maintain Cybersecurity for Remote Workers: A Quick Guide for HR Professionals
October 7, 2021 · techfunnel.com
- Ransomware grows 1070%, organisations struggle to secure operations
October 6, 2021 · securitybrief.asia
- On app tracking, both Android and iOS have to do better
September 29, 2021 · computerworld.com
- 3 ways any company can guard against insider threats this October
September 27, 2021 · helpnetsecurity.com
- 2 million malicious emails bypassed secure email gateways in 12 months
September 22, 2021 · helpnetsecurity.com
- South Africa’s Department of Justice Network Under Ransomware Attack
September 17, 2021 · cisomag.eccouncil.org
- Phishing attempts: Employees can be the first line of defense
September 10, 2021 · helpnetsecurity.com
- Compliance failures caused by lack of embedded controls into employee processes
September 9, 2021
- Why should enterprises invest in machine identity management tools?
September 3, 2021 · helpnetsecurity.com
- Previous employees with access to corporate data remain a threat to businesses
September 2, 2021 · helpnetsecurity.com
- How ransomware runs the underground economy
September 1, 2021 · csoonline.com
- Data Backup – More Important Than Ever
August 26, 2021 · which-50.com
- Remote working business owners dont trust employees
August 25, 2021
- Protecting citizen facing staff from phishing starts with a people first approach
August 25, 2021
- Govt hackers impersonate hr employees to hit israeli targets
August 18, 2021
- Most employees reusing personal passwords to protect corporate data
August 16, 2021 · helpnetsecurity.com
- Despite cybersecurity training 85 of employees still reuse passwords report
August 11, 2021