Alessandro AleddaInsider Threat and Risk

INTRA/BA/BA001Risk indicator catalogue

The defined set of observable circumstances the program treats as bearing on the likelihood of harm.

Pillar
BA  |  Behavioral assessment
Sources cited
4
Added
30 AUGUST 2026
Updated
30 AUGUST 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
RecommendedBelgiumwhere writtenCyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch.Behavioral signs are named as things training should teach people to recognize, and three are given: unusual access patterns, the hoarding of data, and sudden changes in behavior.
RecommendedUnited Kingdomwhere writtenInsider Data Collection Study: Report of Main FindingsNPSA, published as CPNI · read 11 Aug 2026How real insider acts occurred and what preceded them, from a review of United Kingdom cases.Real cases have been reviewed and what preceded the acts described, which is where an indicator can be taken from rather than supposed.
ReportedDenmarkwhere writtenSoK: The Psychology of Insider ThreatsSaddiqa and Ruohonen · read 11 Aug 2026What has been published on traits, states, and situational factors, and that the foundations are thin and hard to compare across studies.An indicator taken from this literature carries thin foundations with it, and findings that cannot readily be compared between studies.
ReportedUnited Kingdomwhere writtenUnderstanding Insider Threat: A Framework for Characterising AttacksNurse, Buckley, Legg, Goldsmith, Creese, Wright, and Whitty · read 11 Aug 2026A vocabulary for describing an insider attack in four parts: catalyst, actor, attack, and organization.A published vocabulary is available to build the catalogue on: catalyst, actor, attack, and organization, grounded in case studies rather than telemetry.