Security is our number one priority. ContactClient loginCyberWall Shield
Blog

Early warning signs of insider risk, and what to do about them

Most insider incidents leave signals before they happen. The skill is noticing them and responding with care.

When people hear "insider risk," they picture a disgruntled employee stealing trade secrets. That happens, but most insider risk is quieter. It's a departing salesperson copying the client list "just in case," a well-meaning employee uploading files to a personal cloud account to work from home, or a shared password that never got changed. Many of these situations give off signals beforehand.

This post covers the common signals, the alerts that help you notice them, and how to respond without turning a warning sign into an accusation.

A word on fairness first

Every signal below has innocent explanations. People look at job sites because a friend sent them a posting. People copy files to USB drives for presentations. People work late because they're busy. A signal is a reason to look more closely. It is never proof of anything.

That's why every alert should go to a person who reviews it in context, and why your monitoring policy should tell employees which alerts exist. Transparency also deters a lot of risky behavior on its own.

Signals worth watching

1. Large or unusual USB file copies

Copying files to a removable drive is one of the simplest ways for data to leave a company. A single copy of a few documents is usually routine. A copy of several gigabytes, or a copy right before someone's last day, deserves a look. CyberWall Insights can raise an alarm on USB file copies, so the right person hears about it quickly.

2. File-sharing and personal cloud sites

Visits to file-sharing sites can be legitimate, such as a client sending a large file. They can also be how data is moved to a personal account. Insights records site names only, so you'll see that someone used a file-sharing site and for how long, not what they uploaded. That's enough to prompt a question.

3. A sudden spike in job search activity

Looking for a new job is not misconduct, and you should never treat it that way. But a departing employee does carry more risk of taking data with them, often without thinking it through. Noticing a change early gives you a chance to have a retention conversation, and to make sure access is handled properly if they do leave. A preset alarm for job search sites is available, and many businesses choose to leave it off. That's a reasonable choice.

4. Unusual after-hours activity

Someone who never works evenings suddenly active at 11 p.m. may be catching up on a deadline. It may also mean someone else is using their account. After-hours alarms help in both cases.

5. Activity that doesn't fit the role

A receptionist spending hours in accounting software, or anyone suddenly using unfamiliar remote-access tools, is worth checking. Application usage reports make these changes visible.

6. Account and sign-in anomalies

Some of the strongest signals come from the account side: sign-ins from unusual locations, failed multi-factor prompts, or new mailbox forwarding rules. These are security monitoring signals. For CyberWall Shield clients, Microsoft 365 sign-in and account monitoring covers this side, in the same console as Insights.

How to set up alerts without drowning in them

  • Start small. Turn on two or three alarms that match real risks for your business, such as USB copies and file-sharing sites.
  • Set sensible severity. A large USB copy may be high severity. A short visit to a job site may be low, or off.
  • Send alerts to the right person. Usually a manager or owner, not a whole channel. Insights can notify by email, Microsoft Teams, Slack or a webhook.
  • Review and close alerts. Mark each one reviewed or dismissed in the alarm log. This keeps a record and shows whether a rule is producing useful signals.

Insights checks rules every five minutes and sends at most one alert per person, per rule, per day, so a single event doesn't produce a flood.

What to do when an alert fires

Step 1: Look at context before anything else

Check the activity log for that person and that time. What else were they doing? Is there a meeting, a project or a client deadline that explains it? Many alerts resolve here.

Step 2: Ask, privately and neutrally

If context doesn't explain it, ask. "I saw a large file copy to a USB drive this afternoon. What was that for?" is a fair question. Most people will have a simple answer, and the conversation reinforces that the policy is real.

Step 3: Escalate only when needed

If the answer doesn't add up, or you have evidence of a real problem, bring in the right people: HR, your attorney, and your IT or security provider. Don't confront someone alone with a theory. Preserve the relevant records, and let professionals advise on next steps.

Step 4: Fix the process

Many incidents happen because something was easy that shouldn't have been. Consider blocking USB storage for roles that don't need it, using company-approved file sharing, and tightening access to sensitive folders.

Departures deserve a checklist

A lot of insider risk concentrates around the time someone leaves. Good practice includes:

  • Reviewing recent activity and alerts during the notice period.
  • Disabling accounts promptly at departure.
  • Recovering company devices.
  • Changing shared passwords the person knew.
  • Checking for mailbox forwarding rules.

Keep the balance

The goal is to protect the company and the people in it, including the employee whose account might be misused by someone else. Clear policy, a short list of meaningful alerts, human review and private conversations will catch most problems early. Treating every signal as guilt will cost you your best people long before it catches a real threat.

See your team's day clearly in under an hour.

Start a 14-day free trial with full access. Deploy through Microsoft Intune, set your goals, and your first reports fill in the same day.