Early warning signals, with a person in the loop
Most insider incidents leave small signs first: a large copy to a USB drive, a visit to a personal file-sharing site, a burst of after-hours work. CyberWall Insights surfaces those signals so a manager can look at the context and decide what, if anything, needs to happen.
What Insights can flag
Each of these is a reason to look, never a conclusion. People copy files, browse job sites and work late for ordinary reasons.
USB file copies
Copying files to a removable drive is often harmless. It's also one of the simplest ways data walks out the door.
File-sharing sites
Personal cloud storage and file-transfer sites can move company files outside your control.
Job-search activity
Looking for a job isn't wrongdoing. Combined with other signals, it can be useful context when you review an alert.
After-hours activity
Late-night work can be dedication. It can also be someone working when nobody else is around.
Turn on the rules that matter to your business
Insights includes presets for USB file copy, file-sharing sites, job search sites and after-hours activity over 30 minutes. You can also write rules for specific sites or apps. Each rule has a severity level, and alerts go to email, Microsoft Teams, Slack or a generic webhook.
- Presets for USB copy, file-sharing and job-search sites
- Custom rules for specific sites and apps
- Checked every five minutes, one alert per person per day per rule
Every alert lands in a log for someone to review
Alerts aren't actions. Each one goes into the alarm log as new, and stays there until a person marks it reviewed or dismissed. Alarm analysis shows patterns over time, so one-off events don't get the same weight as a repeated pattern.
- New, reviewed and dismissed states
- Alarm analysis across people and rules
- A clear record of what was reviewed and when
| Time | Productivity | Computer | App | Window | Site |
|---|---|---|---|---|---|
| 10:42:10 | Productive | DESKTOP-14 | Excel | Q3 forecast.xlsx | — |
| 10:39:52 | Neutral | DESKTOP-14 | Chrome | — | google.com |
| 10:31:04 | Productive | DESKTOP-14 | Chrome | — | salesforce.com |
| 10:12:40 | System | DESKTOP-14 | — | Screen locked | — |
| 10:02:18 | Unproductive | DESKTOP-14 | Chrome | — | youtube.com |
| 09:58:01 | Productive | DESKTOP-14 | Outlook | Inbox | — |
Look at what was happening around the alert
When an alert needs a closer look, the activity log shows the surrounding events: which applications were in use, which sites by name, and when the screen was locked. If your company has requested the screenshots add-on, those are available too, kept for 7, 14 or 30 days and then deleted.
- Per-event activity log with lock and unlock events
- Website usage by site name
- Optional screenshots, off by default
Insights watches behavior. Shield watches for attacks.
Security is our number one priority, and insider signals are only one piece of it. CyberWall Shield adds 24x7 threat detection and response, Microsoft 365 sign-in and account monitoring, and backup and recovery. Both live in the same console, so a risky sign-in and a large USB copy on the same day show up side by side.
- 24x7 managed detection and response
- Microsoft 365 sign-in and account monitoring
- Backup and recovery if the worst happens
An honest description of what you're buying
What Insights is
- An early warning system for behavior worth a second look
- A record of alerts and who reviewed them
- A website blocking list for sites you don't want used at work
- One part of a security program run by a security-first team
What Insights is not
- A data loss prevention (DLP) system. It doesn't inspect or stop file transfers.
- A reader of email, documents or file contents
- A full-URL tracker. It records site names only.
- A verdict. A person reviews every alert before anything happens.
A responsible way to use insider signals
Write it down
Put your monitoring and acceptable-use rules in a policy and share it. Turn on the employee notice in Insights.
Choose a small set of rules
Start with USB copy and file-sharing sites. Add others only if you know what you'll do when they fire.
Name a reviewer
Pick who reviews alerts, and who is involved (often HR) before any conversation with an employee.
Look for patterns
One alert is a data point. Use alarm analysis and the activity log to see if it's part of something larger.
Questions we hear
Is Insights a DLP tool?
No. Insights alerts on signals like USB file copy activity and visits to file-sharing sites. It doesn't inspect file contents or block transfers. If you need data loss prevention, talk with us about the right tools alongside Insights and CyberWall Shield.
Can Insights see what files were copied or uploaded?
Insights doesn't open or read files, and it records websites by site name only. It tells you that a USB copy or a visit to a file-sharing site happened, and when.
Should we alert on job-search sites?
That's a decision for your business and your counsel. Many companies choose not to, or use it only as context during the review of other alerts. Looking for a job is not misconduct. This isn't legal advice.
Who gets the alerts?
You choose. Alerts can go to specific email addresses, a Microsoft Teams or Slack channel, or a webhook. Keep the list small and limited to people who will review fairly.
How does this connect to CyberWall Shield?
Shield and Insights share one console and one login. Shield handles threat detection, Microsoft 365 account monitoring and backup. Insights adds behavior signals. Together they give a fuller picture than either alone.
Do employees need to be told?
We strongly recommend it, and some states require notice. Insights can show a monitoring notice on each computer. See our monitoring laws guide.
Add early warning signals to your security program.
Try Insights free for 14 days, or talk with our security team about pairing it with CyberWall Shield.
