Insider risk · 3.2

What detection can and cannot establish

What detection can and cannot establish. What the requirement says, what it means in practice, and what an assessor will ask.

For an independent reference point, see ICO guidance on monitoring workers.

What a record establishes

Four facts and no more

That an event occurred. When. Which account performed it. On which system.

Everything beyond those four is inference, and the distance between the four and a conclusion is where investigations go wrong.

What it does not establish

Three things people read into it

Who. A record identifies an account. Whether the person it belongs to was at the keyboard is a separate question, particularly where credentials are shared, which on a shop floor they frequently are.

Why. A file copied at two in the morning may be theft, may be somebody finishing a job before a deadline, and the record looks identical.

Whether it mattered. Whether the file was covered, whether the destination was authorised, and whether any harm followed are business questions answered by people who know the work.

Baselines

Unusual is not wrong

Detection compares behaviour against a baseline and reports departures. Departures are common and mostly benign: a new project, a different shift, an audit, a person covering for a colleague.

A system reporting anomalies reports change. Turning change into risk requires context the system does not have, which is why the output is a signal for a person rather than a finding.

The evidentiary question

Different decisions need different confidence

Asking somebody a question needs very little. Removing access pending an enquiry needs more. An employment decision needs a great deal and needs to withstand scrutiny in a forum with its own rules. A report to a customer or a regulator needs facts you can stand behind.

Deciding in advance which threshold applies to which action prevents the pattern where a single anomalous record produces a confrontation.

Investigation is human

What the tool hands over

A timeline and a set of records. What follows is asking the person's manager whether the activity fits the work, checking whether a project explains it, and, where appropriate, asking the person.

That work cannot be automated and organisations that buy detection without allocating it end up with a queue nobody processes, which the entry on false positives describes.

What it is good at

The cases where records are decisive

Establishing scope after something is known to have happened. Answering the question an assessor or a customer asks about which files were affected. Demonstrating that a control operated. And detecting bulk activity that no ordinary work explains.

Those are real and they justify the capability. Attributing intent is not among them.

The honest claim

What a vendor should say

That the system records file activity and identifies patterns worth a human look. Anything stronger, and particularly anything about identifying malicious insiders, is a claim about intent that no detection makes.

This site says so on the platform page, which is unusual and is the accurate description.

Correlating across systems

Where the clocks matter

Reconstructing a sequence across a file server, an identity system and a machine requires their timestamps to be comparable. The blog entry on forensic readiness makes the same point and it applies to routine investigation as much as to incidents.

Time synchronisation is unglamorous and it is the difference between a narrative and a pile of records.

Also

Elsewhere in insider risk