Innentäter

Insider Threat

Innentäter / Innentäterin

An insider threat is a person with legitimate access — employees, service providers, partners — who uses this access to the organisation's detriment or negligently enables damage. The threat is especially tricky because it comes from within, enjoys trust and bypasses regular protective measures. It encompasses malicious as well as unintentional cases.

History & facts. Three types are roughly distinguished: the malicious insider (for instance out of revenge or enrichment), the negligent one (who opens a gap through carelessness) and the compromised one (whose access an external attacker has taken over). Common to all is that legitimate authorisations are used — which is why classic perimeter defences help little. Departing employees in particular, or far-reaching administrator rights, are sensitive points by experience. Outlook & recommendation. Against insider threats, principles rather than individual tools take effect: minimal granting of rights (need-to-know), separation of duties, seamless and tamper-proof logging and a clean process for revoking access on departure. Detection starts with behaviour — unusual access, atypical data volumes. The balance is important: monitoring must be proportionate and legally (data protection, co-determination) cleanly designed, otherwise it damages the trust it is meant to protect.
Innentäter — Insider Threat