6 min read

How to Build an Insider-Risk Programme That Actually Catches the Bad Cases

Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter

Insider Threat Detection Engineering Blue Team

Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. The metrics that the programme reports to the leadership are the metrics that the leadership does not use to make decisions.

Here is how to build a programme that finds the cases that actually matter.

The wrong target

The wrong target is the employee who is going to steal the data. The wrong target is the employee who is going to sabotage the system. The wrong target is the disgruntled employee who is going to take the customer list and walk out the door.

The reason the wrong target is wrong is that the cases that the programme is trying to find are very rare. The reason the cases are very rare is that the population that the programme is screening is very large. The population is the entire workforce. The cases are the employees who are going to do harm. The ratio of cases to population is small. The signal-to-noise ratio is very low. The detection engineering is trying to find a needle in a haystack with a magnet that is not very strong.

The right target is the population that is at elevated risk. The right target is the population that has a credible reason to be at elevated risk. The right target is the population that has a credible reason to be at elevated risk because the population is in a position to do harm, the population has the access, the population has the knowledge, and the population has the opportunity.

The right target is a much smaller population. The right target is the population that has privileged access. The right target is the population that has the access to do harm. The right target is the population that is going to be the cases in most of the real-world insider incidents.

The right inputs

The right inputs are the data sources that the programme can actually use. The right inputs are not the generic behavioural analytics. The right inputs are not the user-and-entity behaviour analytics that the vendor sells. The right inputs are the specific data sources that the programme can use to identify the population at elevated risk.

The right inputs include the access management system. The right inputs include the data loss prevention system. The right inputs include the endpoint detection system. The right inputs include the identity logs. The right inputs include the email system. The right inputs include the document management system.

The right inputs are the data sources that the programme can query. The right inputs are the data sources that the programme can join. The right inputs are the data sources that the programme can use to identify the population at elevated risk, the access the population has, the actions the population is taking, and the anomalies in the actions the population is taking.

The right detections

The right detections are not the generic behavioural analytics. The right detections are the specific detections that the programme has written for the specific data sources that the programme has. The right detections are the detections that are based on the access the population has, the actions the population is taking, and the anomalies in the actions the population is taking.

The right detections include the access anomalies. The right detections include the data access anomalies. The right detections include the data egress anomalies. The right detections include the endpoint behaviour anomalies. The right detections include the identity behaviour anomalies. The right detections include the document access anomalies.

The right detections are not the detections that the vendor sells. The right detections are the detections that the programme has written for the specific data sources that the programme has. The right detections are the detections that the detection engineering function has written, the detection engineering function has tested, the detection engineering function has tuned, the detection engineering function has documented, the detection engineering function has maintained.

The right investigation

The right investigation is the investigation that the case management function is going to do. The right investigation is not the automatic case management. The right investigation is not the "the system flagged it, the analyst closes it" pattern. The right investigation is the investigation that the analyst is going to do, the analyst is going to escalate, the analyst is going to investigate, the analyst is going to recommend the action.

The right investigation requires the analyst to have the context. The right investigation requires the analyst to have the access to the data sources. The right investigation requires the analyst to have the time. The right investigation requires the analyst to have the authority.

The right investigation is the work that is the most expensive part of the programme. The right investigation is the work that is the most under-resourced. The right investigation is the work that is the most likely to be cut when the budget is tight.

The right investigation is the work that the programme cannot afford to cut. The right investigation is the work that is the difference between a programme that finds the cases and a programme that does not find the cases.

The right metrics

The right metrics are not the number of alerts. The right metrics are not the number of cases. The right metrics are not the number of investigations. The right metrics are the number of cases that the programme has identified that turned out to be real.

The right metrics are the number of cases that the programme has identified that turned out to be real insider incidents. The right metrics are the number of cases that the programme has identified that turned out to be real and that the programme has been able to act on before the harm was done.

The right metrics are the only metrics that the leadership actually cares about. The right metrics are the only metrics that the leadership actually uses to make the decision about whether the programme is worth the money.

The right metrics are the metrics that the programme should be reporting. The right metrics are the metrics that the programme should be measuring. The right metrics are the metrics that the programme should be improving.

The honest scope

The honest scope of an insider-risk programme that actually catches the bad cases is a programme that has the right target, the right inputs, the right detections, the right investigation, and the right metrics. The honest scope is a programme that is small, focused, and well-resourced.

The honest scope is not a programme that has the generic behavioural analytics, the automatic case management, and the metrics that the leadership does not use. The honest scope is not a programme that is the vendor's product with the programme's name on it.

The honest scope is the work. The honest scope is the work that the programme has to do to find the cases that actually matter. The honest scope is the work that the programme has to do to be worth the money.

If you are building an insider-risk programme, build the right programme. If you are building an insider-risk programme, build the programme that finds the cases. If you are building an insider-risk programme, build the programme that is worth the money.