About the editorial position
These notes are published by the editors of this site. They are written as a single body of guidance rather than as personal opinion, and they are intended to be used.
The position
Most people who become the subject of an insider enquiry have done nothing wrong. That is arithmetic rather than charity, and a programme designed on the opposite assumption will harm innocent people routinely.
The costs of handling that badly fall twice: on somebody who was examined and frequently never told, and on the programme, which loses the reporting channel that is its best source.
Most of what looks like deliberate wrongdoing is somebody working around something broken. Establishing that takes one question.
What these notes cover
The stages of a case: the alert, the decision to open, the conduct of the enquiry, what is owed to the subject, and both outcomes.
What they do not cover
How detection works. Behavioural modelling, data loss prevention and alerting are substantial subjects with their own literature, and this collection begins where they end.
Product comparisons are kept in separate tool guides. The core notes remain focused on process rather than vendor rankings.
No figures for the prevalence of insider incidents, because those come from people selling the tooling.
And nothing about concealing conduct or frustrating an enquiry, which is not what this is for.
Nothing here is legal advice
Employment, investigatory and data protection rules differ substantially by jurisdiction. Everything here is orientation and the local answer requires local advice.
Corrections
If something here is wrong, we would rather know. The contact route is on the site.