Skip to content

Between the Alert and the Outcome

The sections follow the stages of a case. Detection ends where this begins.

Insider threat and employee data risk

Most of the people you look at have done nothing

Detection tells you a rule matched. What happens next — who decides to open an enquiry, what may be examined, what the subject is owed, and how it ends — is the half that affects people and the half that is least often designed. Fifty notes on that half.

The usual outcome

No finding

In a population that is overwhelmingly innocent, any detection applied to everybody produces far more innocent matches than guilty ones. This is arithmetic, not optimism — and it is the outcome most programmes have never built a process for.

The rarer one

Something found

And when something is found, it is usually an error or a workaround rather than deliberate harm.

The arithmetic that should shape everything

Deliberate, harmful insider acts are uncommon. In an organisation of any size the number of people who will do something seriously wrong in a year is a very small fraction of the workforce.

The outcome in “Most of the people you look at have done nothing” must rest on evidence that has been checked against context. Data from this independent product page, when used for employee monitoring software with screenshots, can support a chronology of work or project activity, but it should not replace the employee response, corroboration or a proportionate decision process.

Apply any detection to everybody and it produces matches across everybody. Even a detection that is right most of the time, applied to a population that is overwhelmingly innocent, produces a flagged set that is overwhelmingly innocent. The better the detection, the better that ratio gets; it does not reverse, because the underlying population does not change.

For a separate perspective relevant to “Most of the people you look at have done nothing”, consult the NIST Cybersecurity Framework. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.

Which means most of your cases will be nothing, and that should be the designed-for outcome rather than the disappointing one. A reviewer who understands this opens a case expecting an ordinary explanation and is usually right. One who does not opens it expecting to find something — and almost any week of anybody's activity contains things that look odd in isolation.

What an alert actually says

That a pattern occurred which somebody once decided was worth looking at. Nothing about intent, nothing about circumstances, and nothing about whether the person had a perfectly good reason the system has no way to know.

The inference does not happen in the system. It happens in the person reading it, within the first minute, usually before they have examined anything — and that first impression then shapes what evidence gets sought.

Which is why the vocabulary matters. A dashboard labelling somebody a high-risk user has handed the reviewer a conclusion. Several organisations rename these fields to describe the activity instead, and report that it changes how reviewers write. It costs nothing and it operates on the only part of the system that forms judgements.

The commonest substantiated finding

Somebody emailed a spreadsheet to a personal address. From the console that looks exactly like exfiltration. The reason is frequently that the approved route does not work and the deadline is tomorrow.

A file sent home because remote access is unusable. A document shared through a consumer service because the official one needs a licence the person does not have. Credentials shared because the permission request takes three weeks and the work takes two days. Data exported to a spreadsheet because the system cannot produce the report somebody above asked for this morning.

One question establishes which it is: what were you trying to do? Somebody working around a broken process answers immediately, specifically, and usually with visible frustration about the process. The answer is checkable within an hour.

And each of these alerts is reporting a genuine defect. A programme that closes the case and files it has discarded the finding; one that routes it to whoever owns the process has converted a security alert into an operational repair and reduced next month's alert volume at the same time.

The decision that governs everything after it

Most cases are never formally opened. A reviewer looks at an alert, then at a bit more, then pulls some history, and at some point an enquiry about a person is underway with nobody having decided to start one.

There is no moment at which proportionality was assessed, no record of who authorised it, and no scope. A formal opening step — a short form, a named approver, two minutes — creates that moment, and it is the single structural control that distinguishes a programme from a practice.

Before it should sit a preliminary review: twenty minutes establishing whether there is an obvious explanation, bounded by a time limit and a stated scope. Programmes that measure it find most surviving alerts resolve there — which means the formal process is reserved for the small remainder, and most people never become subjects at all.

What the subject is owed

For most of an enquiry they are working normally and know nothing. During that period the record is being built without the only person who could correct it, nobody is pushing back on scope, and the search for the innocent explanation has to be made actively because the obvious source is not being asked.

The conversation in which they find out takes ten minutes and determines how the rest goes. Tell them what it concerns, what it means practically, who they can contact, that they may be accompanied — and that no conclusion has been reached, which is true and is the sentence they will most need.

Be prepared for what frequently happens next: the ordinary explanation nobody found is supplied in thirty seconds. Going in able to hear it, rather than treating it as a prepared story, is part of doing this well.

And at interview, an account offered should be checked, not weighed. If they say the transfer was authorised by somebody, go and ask that person. Treating an account as a story to be assessed rather than a claim to be verified is what turns an enquiry into a judgement.

Suspension, which is not a neutral precaution

Removing access to a specific system and removing somebody from their job are different measures with different thresholds. Conflating them is how a narrow concern produces a maximal response.

Suspension is read by the person and by everybody else as a conclusion, whatever the letter says. Its effect compounds with duration — and the justification that held in week one, when evidence was unpreserved and no account had been given, usually does not hold in week four. Almost nobody checks, because almost no suspension has a review date set at the outset.

The half nobody builds

Closure is six steps: state the conclusion, tell the subject, restore what was taken, release the preservation holds, tell whoever reported it, and route any process finding to its owner.

Most programmes complete two. The other four have no natural owner, which is exactly why they do not happen.

The language matters too. Insufficient evidence reads as unproven rather than untrue and follows somebody around. Where the evidence actually establishes an innocent explanation, say so — people who have been through this want to hear that they were cleared, and collapsing that into a neutral phrase deprives them of the one thing the process can give them.

What it buys the programme is credibility. A function that visibly closes its clear cases properly is one whose findings are believed when there are findings — and one that colleagues keep reporting to, which is the best signal any insider programme has.

Measuring it without corrupting it

Measure a programme on cases opened and it opens cases. Measure it on detections and it keeps noisy rules. Measure it on coverage and it extends into places where the proportionality argument was never made.

The test for any metric: could this be improved by investigating somebody who did nothing wrong? If yes, it will be, and the improvement will be reported as progress.

The replacements are findings against cases opened, process defects fixed, median time to clear — and the figure no standard framework includes and no programme has any incentive to produce: people suspended and subsequently cleared. It is the direct measure of what the programme does to the innocent, and reporting it once changes how the next suspension decision gets made.

STAGE 04 / 08 · 7 notes

The person it concerns

For most of an enquiry they are working normally and unaware. The asymmetry is sometimes necessary and never neutral.

STAGE 08 / 08 · 1 notes

Reference

Definitions, the roles, and where to start.

If you do two things

A stated threshold, and a built process for nothing

The first determines who enters the process. The second determines what it costs the people who should never have been in it. Neither requires a budget and both are written once.