Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

Incident scenarios · Incident responders and SOC leads

Insider data theft

A legitimate user, legitimate access, and the wrong intent. Almost nothing here is technically anomalous.

Every action may be permitted. What makes it an incident is volume, timing and destination — not access control.

What this does not establish

  • Intent. Volume is not proof, and people do legitimate bulk work.
  • Whether it is really the account holder. Insider and compromise look identical at first.
  • Whether the data has left. Staged is not exfiltrated.

0 of 9 ticked

Selected step

DetectStep 1 of 9

Compare against this person's own baseline

  • Their normal, not the team's. Roles differ enormously.
  • Timing matters more than volume: same work at 03:00 is a different fact.
  • Start the timeline now: every action, who took it, when.