Last updated: April 29, 2026
Why this module exists. External attackers get the headlines; insiders cause more breaches by volume. Verizon DBIR consistently shows ~20% of breaches are insider-driven (deliberate + accidental combined). Detecting them requires different signals from external-attack detection, and operating in the privacy-respecting envelope DPDP / labour law / cultural norms allow.
The insider-threat taxonomy
- Malicious insider — deliberate theft / sabotage. Most reported.
- Negligent insider — accidents: misdirected email, lost laptop, weak password reuse. Most common.
- Compromised insider — external attacker using legitimate insider credentials. Hardest to detect.
- Departing insider — leaving the company; high-risk window of 30-90 days.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.