Three types
Malicious insiders deliberately steal data, sabotage systems or commit fraud, often around a resignation or a dispute. Negligent insiders cause incidents by mistake: sending a file to the wrong person, falling for phishing or using unapproved tools. Compromised insiders are legitimate accounts taken over by an attacker, who then acts with that person's access.
Why it is hard to detect
Insiders already have legitimate access, so their activity looks normal to most controls. The warning signs are usually unusual behaviour: downloading large volumes of data, accessing systems unrelated to the role, activity at odd hours or copying files to personal storage shortly before leaving.
How to reduce the risk
Most measures are about limiting what any single person can do: least privilege and regular access reviews through IAM, removing access on the day someone leaves, segregation of duties for payments and critical changes, DLP on sensitive data, logging and monitoring, and awareness training. Background checks and confidentiality agreements cover the hiring side.
Where it shows up in compliance
ISO 27001 includes screening, terms of employment, disciplinary process, responsibilities after termination and segregation of duties (Annex A 6.1 to 6.6 and 5.3). Monitoring employees must respect the GDPR and, in Spain, workers' digital rights.




