Cybersecurity Glossary
Insider Threat
Damage caused by someone who already has legitimate access, whether deliberately or by accident.
What Insider Threat means
Insider incidents fall into three groups: the careless, who mail a file to the wrong address; the departing, who take client lists with them; and the malicious, who act with intent. In practice the careless group causes the most incidents and the departing group causes the most disputes.
Why Insider Threat matters for small businesses and nonprofits
Small organisations rarely revoke access properly when someone leaves, and often share one login for a critical system. That combination means a former colleague may still have access months later, which is difficult to explain to a client or a regulator.
What to do about Insider Threat
- Make access removal part of the leaving checklist, with a named owner
- Give each person their own account, never a shared one
- Log access to sensitive data so unusual downloads are visible
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.