Legitimate position, harmful outcome
An insider threat comes from a person or partner with authorized access, knowledge, proximity, or influence who can harm assets. The act can be malicious, coerced, careless, mistaken, or caused by a compromised account. Employees, contractors, vendors, administrators, developers, support staff, and former workers can be insiders to different boundaries.
Do not equate insider with employee or malicious intent. Model authority and opportunity.
High-risk paths
Inventory broad data reads, bulk export, impersonation, policy administration, identity-provider changes, authenticator reset, secret access, deployment, logging disablement, backup, deletion, and recovery. Include legitimate sequences that combine into harm.
Identify where one person can request, approve, execute, hide, and recover an action. Record standing access, dormant accounts, shared credentials, vendor access, and knowledge that enables social engineering after departure.
Prevention and detection
Use least privilege, time-bound elevation, separation of duties, named accounts, managed devices, workload separation, approval for high-impact changes, data minimization, egress controls, and fast lifecycle revocation. Make legitimate work practical so controls do not depend on informal bypass.
Detect unusual access by resource, action, volume, time, destination, role, and peer baseline. Protect audit integrity and privacy. Provide safe reporting and fair investigation that separates evidence from inference.
Failure and residual risk
An authorized person can use valid tools below alert thresholds. Behavior analytics can create false positives, surveillance harm, bias, and privacy exposure. Two-person controls can fail through collusion or one compromised workflow. Excessive restriction can move data to unmanaged systems.
Technical controls cannot resolve every employment, coercion, grievance, or safety issue. Coordinate responsible teams without turning vague concern into unsupported accusation.
Pomerium boundary
Pomerium can require named identity and policy for covered routes and can emit access evidence. It cannot see actions taken around the route, direct data copies, application-object changes, endpoint behavior, or collusion unless those systems provide evidence. Applications and operators own action-level authorization, export, separation, lifecycle, and investigation.
Evaluation checklist
- Which legitimate role can read, export, change, approve, deploy, erase, impersonate, or recover the protected asset?
- Can one person request, authorize, execute, and hide the same high-impact action?
- Do time-bound access, managed paths, and lifecycle controls still let legitimate work finish?
- Which evidence distinguishes authorized unusual work, account compromise, error, coercion, and deliberate abuse?
- Are investigation and monitoring proportionate, privacy-aware, attributable, and subject to review?
