The risk
Insider threats are as old as mythology and as fast-evolving as Artificial Intelligence.
Troy fell to an enemy it had unwittingly allowed inside its walls. Loki sat among the gods of Asgard, knew their weaknesses, and turned that knowledge against them. Pandora opened the jar entrusted to her, unleashing harm without intending to. What keeps changing is the surface. Modern organizations rest on technology that grants immediate and pervasive access the moment an account is opened or a permission is granted, and even a proportionate share of it reaches far enough to do serious damage. What almost none of it records is intent, which leaves security functions struggling to understand and contain harmful events, let alone prevent them. On top of that, there is no unified guidance, and each program is worked out from scratch, with the gaps and inconsistencies that follow.
Why this exists
In Europe scattered pieces exist. The whole does not.
The law has codified privacy and data protection, and held the line on the rights and freedoms of the person. The national cybersecurity authorities have written down what an organization has to have in place, and graded it. The research has begun on the technical side of the work. Nobody has consistently tried to put the pieces together. That is what this site is for.
What is here
Written from inside the work.
Resources gathered and synthesized for the practitioners who have to be custodians of the organization and of the person at once. Neither a GRC tool nor a purely technical repository, but an attempt to hold the whole picture in one place and make it something a program can act on, whether it is being built for the first time or reworked. Insider Threat and Risk Architecture (INTRA™) holds what each European jurisdiction has established on the measures a program is built from. Insider Threat Event Requirements (ITER™) holds what an insider event obliges, and from when.

