# Insider threat

**What is an insider threat?**

An insider threat comes from people who already have access: employees, former employees, service providers. The access does not have to be obtained first, it is already there.

The most common case is not betrayal, it is a mistake. A file ends up in the wrong attachment. A folder is shared too widely. An employee falls for a fraudulent email. The damage happens without any intent at all.

The second case is the departing employee who takes customer data or quotations along, often believing it to be their own work. The third and rarest case is deliberate harm.

The same foundation helps against all three. Every account receives only the rights its task requires. Access is revoked on the day someone leaves. Access to particularly sensitive data is logged. The purpose of that logging and the retention period belong in writing beforehand, with the staff representation involved.

## Related terms
- [Permission model and least privilege](https://vetosec.at/en/it-security/berechtigungskonzept/)
- [Data breach](https://vetosec.at/en/it-security/datenleck/)
- [Monitoring and logging](https://vetosec.at/en/it-security/monitoring-logging/)
- [Shadow IT](https://vetosec.at/en/it-security/schatten-it/)

## Source
https://vetosec.at/en/it-security/insider-bedrohung/ (vetosec, angriffe)
