All playbooks
Incident scenarios · Incident responders and SOC leads
Insider data theft
A legitimate user, legitimate access, and the wrong intent. Almost nothing here is technically anomalous.
Every action may be permitted. What makes it an incident is volume, timing and destination — not access control.
What this does not establish
- Intent. Volume is not proof, and people do legitimate bulk work.
- Whether it is really the account holder. Insider and compromise look identical at first.
- Whether the data has left. Staged is not exfiltrated.
0 of 9 ticked
Selected step
DetectStep 1 of 9
Compare against this person's own baseline
- Their normal, not the team's. Roles differ enormously.
- Timing matters more than volume: same work at 03:00 is a different fact.
- Start the timeline now: every action, who took it, when.