Designing a Framework to Tackle the Multifaceted Intricacies of Insider Threats
摘要
Insider threats present a significant challenge to companies and organizations, resulting in severe repercussions such as asset loss, damaged reputation, and diminished shareholder trust. As long as there are human-operated tasks in a company, there is potential for abusing one’s privileges or jeopardizing processes due to carelessness. A multitude of approaches have been proposed to mitigate insider threats from access management to anomaly detection, but the rate of false negatives and positives hinders these efforts. One of the challenges in this regard is the complexity of the human factor. Existing frameworks primarily focus on recognising imminent threats. Our goal is to offer a deeper understanding of individuals long before they pose any danger. We aim to identify the states they can be in, the indicators that can be used to recognise their present state, and the factors that have led them to this point. This approach provides the opportunity to deescalate situations where an employee might transition into an insider threat and offers cybersecurity analysts early insights into problematic behaviour.