Insider Threat Analysis
A focused review of employee activity, data movement and unusual events to identify potential misuse, leakage or rogue behavior.
Know when to bring this work into the program.
Use this analysis when the firm is concerned about unusual employee activity, sensitive departures, data movement, or the adequacy of insider-risk monitoring.
A scope built around the risk.
A focused review of employee activity, data movement and unusual events to identify potential misuse, leakage or rogue behavior.
- Business context and authorized user behavior
- Email, endpoint, cloud and file activity
- Large transfers, unusual access and policy exceptions
- Legal, HR, privacy and escalation boundaries
Useful output for the people who must act.
- Scoped analysis of relevant activity and evidence
- Timeline of notable events and anomalies
- Risk-based conclusions with stated limitations
- Recommendations for monitoring, access and response
A process designed for insider threat analysis.
Define the concern
Begin with business context and authorized user behavior and confirm the systems, people and evidence needed to answer the client’s specific questions.
Preserve and analyze
Review email, endpoint, cloud and file activity. Then evaluate large transfers, unusual access and policy exceptions to determine whether the relevant controls operate as intended.
Build the timeline
Assess legal, HR, privacy and escalation boundaries and connect the result to credible security, operational and business impact.
Recommend the response
Provide scoped analysis of relevant activity and evidence and timeline of notable events and anomalies, then align responsible parties around the next actions.
Move from activity to clarity.
Is the activity unusual for the person’s role?
To answer this, Elteni analyzes business context and authorized user behavior together with email, endpoint, cloud and file activity. The client receives scoped analysis of relevant activity and evidence, with the evidence, context and next steps needed to act.
Was sensitive information accessed or moved without a clear need?
To answer this, Elteni analyzes email, endpoint, cloud and file activity together with large transfers, unusual access and policy exceptions. The client receives timeline of notable events and anomalies, with the evidence, context and next steps needed to act.
Do current controls provide sufficient evidence?
To answer this, Elteni analyzes large transfers, unusual access and policy exceptions together with legal, HR, privacy and escalation boundaries. The client receives risk-based conclusions with stated limitations, with the evidence, context and next steps needed to act.
The result does not have to live in another report.
Relevant findings, evidence, owners and remediation status can be centralized in the Elteni Platform as part of an ongoing relationship.
Explore the Elteni Platform →