Attacks
Insider threat
What is an insider threat?
An insider threat comes from people who already have access: employees, former employees, service providers. The access does not have to be obtained first, it is already there.
The most common case is not betrayal, it is a mistake. A file ends up in the wrong attachment. A folder is shared too widely. An employee falls for a fraudulent email. The damage happens without any intent at all.
The second case is the departing employee who takes customer data or quotations along, often believing it to be their own work. The third and rarest case is deliberate harm.
The same foundation helps against all three. Every account receives only the rights its task requires. Access is revoked on the day someone leaves. Access to particularly sensitive data is logged. The purpose of that logging and the retention period belong in writing beforehand, with the staff representation involved.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.