Incident Response

Insider Threat

English

Overview

The risk of data leaks or misconduct from employees or contractors who already hold legitimate access, rather than from an outside attacker.

Details

This includes not just deliberate malicious insiders, but also unintentional mistakes such as misconfiguration or careless handling of information. Because insiders use legitimate credentials, these threats are harder to detect than external attacks, making least-privilege access and access log monitoring important countermeasures.

More Security terms