BLOG ·INSIDER RISK

Insider-risk scoring, explained without the jargon

Most data loss comes from trusted insiders, not intruders. Risk scoring surfaces the few accounts drifting from normal before they turn into an incident.

The Cyfriq Team · · 6 min read

The term does more harm than good.

"Insider risk" sounds like suspicion. It suggests you are watching your own people, waiting to catch them out. That framing makes the topic hard to discuss and easy to avoid.

Strip the drama and it is simpler. Insider risk is the chance that access granted for a good reason gets used in a way that causes loss. Most of the time there is no malice at all — a rushed employee, a misconfigured share, a leaver taking "their" work. Scoring is just a way to notice the few situations that need a look, before they become incidents.

What a score is, and what it is not.

An insider-risk score is a running estimate of how far someone's behaviour sits from their own normal. It is not a verdict. It is not a performance rating. It is a number that says "this account is worth a human glance today."

Two properties make a score useful:

  • It is relative to the person, not the population. A developer touching source code all day is normal. The same developer suddenly pulling the customer database is not.
  • It decays. Yesterday's spike should fade if nothing follows it, so the list stays short and current.

A good score does not accuse. It prioritises attention.

What feeds a score.

The inputs are ordinary events, made meaningful by context:

  1. Data movement — large downloads, copies to personal cloud, pasting into AI tools.
  2. Access changes — new privileges, dormant accounts waking, logins from new locations.
  3. Timing — activity at hours the person never usually works.
  4. Sequence — a resignation, followed by a spike in file access, followed by an upload.

No single one of these is proof. A large download before a board meeting is expected. The same download by someone who resigned that morning is not. The signal lives in the combination, not the event.

Why single alerts mislead.

Most tools alert on thresholds — a download over a set size, a login from a new country. Thresholds fire constantly and mean little on their own, so teams learn to ignore them. The real insider incidents hide in patterns that no single threshold catches.

Scoring solves this by correlating weak signals into one picture of a person over time. Five small, individually-boring events in the right order say more than one loud alarm. We go deeper on this in Why weak signals beat big alerts.

Keeping it fair.

A score that people cannot trust gets switched off. Three principles keep it defensible:

  • Explainability. Every score should show the events that drove it, so a reviewer can judge for themselves.
  • Proportionality. A raised score should trigger a review, not an automatic punishment.
  • Privacy. You are watching behaviour signals, not reading private messages.

Handled this way, scoring protects employees too. When something does go wrong, the record shows what actually happened, which clears the honest majority quickly.

How Cyfriq approaches it.

Cyfriq's Insider Threat Scoring builds a per-person baseline from identity, data, and cloud activity, then raises a score when behaviour drifts from it. The Cross-signal Correlator ties those events together, so a resignation, an unusual download, and an AI paste read as one story rather than three unrelated alerts. Everything lands in the Risk Center, where a reviewer sees the score and the events behind it in one place.

Because the same platform also runs data loss prevention and cloud security, the score draws on the real movement of data rather than logs alone. One of the most common contributors is data heading into AI tools — the subject of Stop your team leaking data into ChatGPT.

Where to start.

Do not begin by scoring everyone. Begin by deciding what "loss" means for you — which data, which systems, which departures matter most. Then let the score surface the handful of accounts drifting from normal against that definition.

Read our behaviour analytics page for how baselines are built, or download the insider-risk guide.

Book a demo and start a 14-day pilot. First findings arrive in 7 days, and you keep them either way.

behaviour-analyticsinsider-threatrisk-scoringueba
KEEP READING
DETECTION
Why weak signals beat big alerts: correlation explained
6 MIN READ
COMPLIANCE
What a data-protection regulator actually asks a security team to show
7 MIN READ
CLOUD & SHADOW IT
The shadow-IT bill you're already paying
6 MIN READ

See what's already walking out the door.

Run Cyfriq on your own network for 14 days. First findings in 7 — yours to keep either way.

Book a demo Explore the platform