Malicious, negligent and compromised insiders: what differs between them, and what does not?
answer
- one word, three different problems
- intent is the only variable
- account and hours look normal in all three
- screening touches at most one
- the position, not the person
basics
~20 sOnly intent differs. The account, the device, the working hours and the operations performed can be identical across all three, so nothing about the actor separates them. That leaves one movable control in common: the scope the role may grant.
solid answer
~40 sThe malicious insider means to cause loss. The negligent one means nothing at all — a finance analyst exports a customer table into a personal spreadsheet service on a Friday to finish a report. The compromised one is not acting; someone holding their session is. In all three the same account makes the same permitted calls from the usual device during the usual hours, so the actor gives you nothing to separate them on. That collapse is the point: controls keyed to *who the person is* — screening, trust, culture — touch at most the malicious case, and only at a moment in time. Controls keyed to *what the role may reach* act on all three at once, without needing to know which one you have.
go deeper
Learn the three names and, more importantly, that they are three separate problems rather than three flavours of one villain. Be able to give a plausible everyday example of the negligent one.
Explain what varies and what is invariant across the three, and why that invariance rules out any control that must first classify the actor. This is the mechanics tier for this topic.
Show that you can pick the control class that acts on all three at once — the scope a role may grant — and say why screening and contractual clauses do not bound loss even though they have other value.
Own the framing when the category is being funded. Argue that money aimed at the malicious subtype leaves most of the actual loss untouched, and be prepared to say what you accept instead.
## Three problems that share a word "Insider threat" is usually spoken as if it named one kind of adversary. It names a **position** occupied in three quite different ways, and confusing them is the single most common wrong answer in this area. **Malicious.** A person with granted access who intends loss. A platform engineer holding standing administrative roles in a cloud account copies the customer data store a fortnight before resigning. Intent is present and the actions are deliberate. **Negligent.** A person who intends nothing and causes loss anyway. A finance analyst on a Friday afternoon exports a customer table out of the reporting system and into a personal spreadsheet service, because the sanctioned path is slow and the report is due. No exploit, no unusual account, no dishonesty — and the customer table is now in a place with different owners, different retention and a different account recovery story. **Compromised.** A person who is not acting at all. Their session or long-lived credential is held by someone else, and the calls arrive under their name. From the environment's point of view this is the account doing its job. ## What varies, and what is invariant | Subtype | What is different | What is identical | |---|---|---| | Malicious | Deliberate intent to cause loss | Account, device, hours, permitted operations | | Negligent | No intent; convenience under time pressure | Account, device, hours, permitted operations | | Compromised | The named person is not the one acting | Account, device, hours, permitted operations | The right-hand column is the whole lesson. Everything that would let you tell the three apart lives in the person's head or in someone else's hands; nothing about the position exposes it. A successful sign-in proves a credential was accepted, never that its owner was present or willing. ## Why that collapse is useful rather than depressing If the three are indistinguishable from the position, then any control that has to know *which one you are facing* is unbuildable. That immediately disqualifies a whole family of proposals: - **Screening.** Background checks are a point-in-time filter aimed at the malicious subset. They say nothing about a careless export and nothing at all about a stolen session, and a person's circumstances change after they are hired. - **Trust and culture.** Genuinely valuable for retention and for people reporting their own mistakes, but two of the three problems do not involve dishonesty, so trust cannot be the bound. - **Contractual clauses.** They allocate liability after the loss. They do not shorten the reach of a role. What survives is the class of control that acts on the position rather than the person: the **scope the role may grant**. Whether the analyst's role can export a whole table or only the rows a report needs; whether the platform role can read a customer data store at all or only manage the infrastructure around it; whether either role can grant itself or someone else more scope. Each of those bounds the loss identically in all three cases, which is exactly the property you want from a control aimed at an actor you cannot classify. ## The framing that wins the interview Asked "how do you handle insider threat", say first that it is three problems sharing a name, then that the three are indistinguishable from the position, then that the only movable knob is scope. If you are asked which of the three is most common, resist ranking them by drama: the negligent case dominates by volume in most organisations and produces real, reportable loss with nobody having done anything dishonest. ## The trap to avoid Do not answer that insider risk is a hiring or a trust problem. It is the answer interviewers are listening for, because it silently assumes the malicious case is the whole category — and it leaves the two subtypes that account for most of the actual loss completely unaddressed.
- Which of the three do background checks actually address?At most the malicious one, and only as it stood on the day of hiring. Circumstances change, so even for that subtype a check is a filter rather than a bound. It has no effect whatsoever on a careless export or on someone else holding the person's session.
- Is the negligent case really an insider threat, or just a mistake?It is both, and the label matters less than the loss. A customer table copied into an unsanctioned service is exposed to the same degree whether the person meant it or not, and the control that would have prevented it — bounding what the role can export — is identical. Calling it merely a mistake is how it goes unfunded.
- If the three look identical, is classifying them useless?It is useless for choosing preventive controls, which is the point. It matters afterwards, for what you owe people: a careless employee needs a better sanctioned path, a hijacked one needs their access re-established safely, and only the deliberate case is a conduct matter. Design against all three; respond to the one you actually had.
saying these in an interview costs you the question
- Treats insider threat as a single actor type
- Answers with hiring, screening or culture as the control
- Assumes intent can be inferred from the operations performed
- Dismisses the negligent case as not a security problem
- Says a legitimate credential means the owner was acting