Insider Threats: How to Protect Your Business From Within
The Verizon Data Breach Investigations Report documents that a significant share of breaches involve someone inside the organization (error or malice). Learn how to detect and prevent insider threats without creating a culture of distrust.
Not all attacks come from outside
When we think about cybersecurity, we picture hackers in hoodies attacking from another country. But the statistics tell a different story: according to the Ponemon Institute, 60% of data breaches involve someone inside the organization — whether through malice, negligence, or compromised credentials.
For companies operating in Mexico, the problem is amplified by specific labor and cultural factors: high employee turnover (especially in manufacturing and retail), employment relationships that end in conflict, and a culture where sharing passwords with "trusted" colleagues is normalized.
The 3 types of insider threats
1. The negligent employee (70% of cases)
No malicious intent, but causes damage through lack of training or carelessness:
- Sends a confidential file to the wrong recipient
- Reuses the same password across corporate and personal accounts
- Falls for phishing and unknowingly hands over credentials
- Shares SharePoint files with "anyone with the link"
2. The malicious insider (25% of cases)
Deliberate intent to cause harm, usually motivated by resentment, financial gain, or external pressure:
- Copies client databases before resigning
- Forwards competitive information to a future employer
- Sabotages systems as retaliation for a workplace conflict
- Sells data access to competitors or criminals
3. The infiltrator (5% of cases)
An external actor using legitimate credentials — whether compromised through phishing, purchased on the dark web, or borrowed from an internal accomplice:
- Uses an employee's credentials to access systems
- Exploits shared accounts without monitoring
- Takes advantage of former employees' accounts that were never deactivated
Warning signs you should be monitoring
You can't prevent what you can't see. These are the most common warning signs:
Out-of-pattern access:
- Sign-in at 3am when the employee always works 9-to-6
- Access from an unusual geographic location
- Access to resources outside their normal job function
Anomalous data volume:
- Mass downloads from SharePoint or OneDrive
- Unusual exports from CRM or internal systems
- File copying to USB drives (if you have endpoint visibility)
Suspicious account behavior:
- Multiple failed access attempts followed by a success
- Email forwarding rule changes (forwarding everything to an external account)
- Accessing other users' mailboxes without justification
How to prevent insider threats with Microsoft 365
Step 1: Least-privilege principle
Every user should only have access to what they need for their job. Review permissions quarterly. If someone changed roles 6 months ago, they probably still have permissions from their old role on top of their new one.
Step 2: Audit logging enabled and monitored
Logs are useless if nobody reviews them. Enable Microsoft 365 unified auditing and configure alerts for high-risk events: external email forwarding, mass downloads, admin permission changes.
Step 3: Active DLP
Configure DLP (Data Loss Prevention) policies that detect when sensitive data (tax IDs, account numbers, client data) is shared via email, Teams, or SharePoint outside the organization.
Step 4: Rigorous offboarding process
When an employee leaves — especially involuntarily — their account should be deactivated before they leave the building. Not the next day. Not when "HR processes it." Immediately.
Step 5: Ongoing training
Most negligence incidents are preventable with training. Monthly simulated phishing, data policy reminders, and clear consequences for violations.
What our scan detects
Our free scan with the 155 Microsoft Graph rules of the 201-rule library includes detection of:
- Accounts with automatic forwarding to external addresses
- Former employee accounts that are still active
- Shared mailboxes without audit trails
- External sharing configurations without restrictions
- Absence of DLP policies
In 90 seconds you have visibility into the most common insider threat vectors in your tenant.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.