Skip to content

Insider Risks Demand Strategic Management at Board Level

The point: Effective insider risk management requires close cross-departmental collaboration and a balance between necessary data collection and transparency with employees.

Companies systematically underestimate the threat posed by insider risks: approximately one-fifth to one-quarter of all data losses are attributable to internal causes, with a large portion intentional. An effective programme requires close collaboration between IT security, human resources, legal, and management.

The core problem is structural: Companies must grant employees, service providers and partners comprehensive access rights to systems and data in order to work productively. This necessary authorization simultaneously creates a vulnerability that classical, perimeter-focused security approaches do not address. Remote and hybrid work, personal devices and cloud-based services compound the problem further. Security professionals worldwide confirm: insider risks rank among the greatest cybersecurity threats.

Effective insider risk management (IRM) programmes must be technical, organisational and cultural in nature. At the centre is a person-focused approach: risky behaviours can be triggered by negligence, knowledge gaps, deliberate sabotage or compromised credentials. The goal is to identify such patterns early, correctly interpret the context and intervene before data breaches, data leakage or corporate espionage occur. At the same time, an IRM programme must not undermine employee privacy and must align with legal requirements and lived corporate culture.

Data collection requires careful judgment. An IRM programme needs information about user activities, access and data flows to identify patterns – but comprehensive monitoring is neither legally sustainable nor tenable. Instead, companies should define: which data for which purpose, how long it is stored, how it is used. HR systems provide indicators of resignations, transfers or activities in sensitive areas. Security systems capture login attempts, file access or unusual transfers. The art lies in deliberately combining these sources without resorting to blanket data collection.

Transparency is central: When employees understand why certain data is collected, what risks are being addressed and what it explicitly will not be used for – such as not for performance monitoring – acceptance increases. Additionally, clear rules are needed: expiration dates for data, access according to the need-to-know principle, regular review of whether data is still required. This foundation satisfies both legal requirements and the legitimate claim to privacy.


Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: