### Purpose

This procedure defines how the company should identify, escalate, investigate, and respond to suspected misuse of trusted access.

**Insider threat includes more than deliberate malicious behavior. It can involve:**

- Careless or negligent employees
- Compromised employee accounts
- Departing staff
- Contractors
- Vendors and MSP personnel
- Privileged administrators
- Shared accounts
- Service accounts
- Users with excessive permissions

The objective is to protect the company while treating sensitive employee matters carefully, fairly, and confidentially.

### 1. Situations That May Require Escalation

**Potential warning signs include:**

- Unusual access to sensitive information
- Large or unexpected downloads
- Mass copying or deletion of files
- Unexpected public or external sharing
- Access outside normal responsibilities
- Attempts to bypass approvals
- Creation of unauthorized administrator accounts
- Unexpected MFA or password changes
- Use of personal email or cloud storage for company data
- Vendor access outside expected scope
- Unusual access shortly before departure
- Attempts to disable logging or security controls
- Unauthorized changes to payments, payroll, customer information, or system configuration

A warning sign does not prove wrongdoing. Context must be considered.

### 2. Report the Concern

Concerns should be reported through an approved channel.

Reporter: ____________________

Date/time reported: ____________________

Concern reported: ____________________

System or data involved: ____________________

Immediate risk: ____________________

Do not encourage employees or managers to investigate suspected insiders themselves.

### 3. Assign Restricted Handling

Potential insider cases should be handled on a need-to-know basis.

**Depending on the situation, involve:**

- Cybersecurity or IT owner
- Leadership
- HR
- Legal counsel
- Compliance
- Incident response provider
- MSP
- Law enforcement where appropriate

The suspected person should not automatically be notified before access and evidence risks are considered.

### 4. Preserve Evidence

Before making unnecessary changes, preserve relevant evidence where practical.

**This may include:**

- Authentication logs
- Email logs
- File access records
- Download history
- Cloud audit logs
- Endpoint logs
- Administrator activity
- VPN and remote access records
- Security alerts
- Relevant communications
- Approval records
- Device information

Do not unnecessarily alter, delete, or overwrite evidence.

### 5. Assess Immediate Risk

**Determine:**

- Is activity still occurring?
- Can sensitive information still be accessed?
- Does the person or account have privileged access?
- Could evidence be deleted?
- Could backups be affected?
- Could payments or business processes be changed?
- Could other systems be affected?
- Is the account potentially compromised rather than deliberately misused?

### 6. Apply Proportionate Containment

**Possible actions may include:**

- Suspend an account
- Revoke active sessions
- Remove privileged access
- Restrict access to sensitive data
- Disable remote access
- Remove vendor access
- Restrict data exports
- Isolate a device
- Preserve a mailbox
- Increase monitoring

Containment should be approved by appropriate technical, management, HR, or legal owners based on the circumstances.

### 7. Investigate the Cause

**Determine whether the situation resulted from:**

- Malicious behavior
- Negligence
- Account compromise
- Excessive permissions
- Weak process controls
- Poor offboarding
- Unclear responsibilities
- Shared credentials
- Vendor misuse
- Misconfiguration
- Normal activity incorrectly interpreted as suspicious
- Avoid assuming intent before the facts are established

### 8. Record Decisions

**Record:**

- What was reported
- Who was informed
- Evidence preserved
- Actions taken
- Who approved actions
- Business impact
- Investigation findings
- Access changes
- Legal or HR involvement
- Final determination
- Follow-up actions

### 9. Correct the Control Failure

Following the investigation, review whether improvements are required.

**Examples:**

- Reduce excessive permissions
- Improve access reviews
- Eliminate shared accounts
- Strengthen offboarding
- Increase MFA coverage
- Improve logging
- Restrict data exports
- Introduce separation of duties
- Strengthen vendor access
- Improve manager training
- Improve secrets management

### 10. Maintain Confidentiality

Insider investigations can involve sensitive employee, legal, security, and business information.

Records should be restricted to people with a legitimate need to access them.

### Practical Rule

Treat unusual trusted-access activity seriously, but investigate facts before assuming intent.

Protect the company, preserve evidence, and involve HR, legal, leadership, and technical owners where appropriate.
