Skip to content

SIDE QUESTSecurity Leadership

Understanding insider risk: behaviour, context, and intent

An alert tells you something happened. It does not tell you whether it mattered, or what the person doing it meant by it. That gap is where insider risk lives.

Samantha Swift / Exabeam /

ORIGINAL SOURCE

WATCH / Exabeam

A talk about insider risk and insider threat detection and response, including the importance of context and why security alerts alone are insufficient.

WATCH THE ORIGINAL (opens on an external site)

Originally published by Exabeam. Cyber Increment did not host or publish this source.

WHY WE'RE SHARING IT

Insider risk is difficult to detect because the activity involved usually looks like work. The account is legitimate, the access is granted, and the individual actions are unremarkable on their own.

Across these two talks, Samantha works through insider risk from three angles: behaviour, context, and intent.

What they get into

  • Why security alerts in isolation may not carry enough context to explain what actually happened.
  • What normal user behaviour looks like, and why you need a picture of it before anything can be called abnormal.
  • Why understanding intent matters when the activity itself is technically permitted.
  • The practical difficulty of detecting and responding to insider activity rather than external intrusion.

The second talk, given with Richard Cassidy, covers similar ground with a closer focus on intent in insider threat hunting.

COMPANION SOURCES

  • WATCH / Exabeam

    Understanding Intent to Tackle Insider Threat Hunting

    A presentation with Richard Cassidy exploring normal user behaviour, the limitations of standard cybersecurity alerts for identifying insider risk, and why context is needed to understand user intent.

    GO TO SOURCE (opens on an external site)

RELATED INSIGHTS

CONTINUE?

Want to talk it through?

If any of this is live in your business right now, a short conversation is usually the fastest way to work out what to do next.