Alessandro AleddaInsider Threat and Risk

INTRA/GBUnited Kingdom

What the record establishes for the United Kingdom, measure by measure, and what each source requires of the measure it governs.

Binding
11
Recommended
27
Reported
8
Measures touched
39 of 110
Sources cited
19
ControlSourceWhat it establishesPrerequisite or recommendation
11Mandatory
AW002/GBTransparency notice on what is observedMandatoryInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.The system controller has to have made all reasonable efforts to inform every person who may use the system that communications transmitted by it may be intercepted. Everyone who may use it, not everyone employed, and reasonable efforts rather than acknowledgement.
BA007/GBAutomated decision-making about a workerMandatoryRegulation (EU) 2016/679 as it has effect in domestic law, articles 6, 9, 22A to 22D, and 35Retained under the European Union (Withdrawal) Act 2018 · read 30 Aug 2026The grounds, the closed categories, when an assessment is owed, and a rule on deciding about someone by machine that is not the Union’s.The rule here is not the Union’s. A decision is based solely on automated processing where there is no meaningful human involvement in taking it, and how far it was reached by profiling is among the things to be weighed in judging whether the involvement was meaningful. A decision is significant where it produces a legal effect or a similarly significant one. The prohibition on taking such a decision by machine alone bites only where it rests entirely or partly on the closed categories, or where the processing relies on the recognized legitimate interests ground. Outside those it may be taken by machine alone, provided the safeguards are in place: the person is informed of the decision, can make representations about it, can obtain human intervention, and can contest it.
DP012/GBRetention and disposal of program recordsMandatoryData Protection Act 2018, section 10 and Schedule 1Parliament of the United Kingdom · read 30 Aug 2026The condition on which an employer may process a closed category at all, and the document that condition requires to exist before the processing starts.The appropriate policy document has to explain the policies on retention and erasure of the data processed under the condition, and to give an indication of how long they are likely to be kept. An indication is what is asked for, not a period.
GV002/GBDeclared perimeterMandatoryData Protection Act 2018, section 10 and Schedule 1Parliament of the United Kingdom · read 30 Aug 2026The condition on which an employer may process a closed category at all, and the document that condition requires to exist before the processing starts.Where an employer processes a closed category under the employment condition, an appropriate policy document has to be in place when the processing is carried out, and it has to have been produced: a document explaining the procedures for securing compliance with the principles for that processing, and the policies on retention and erasure with an indication of how long the data are likely to be kept. It is a condition of the processing being lawful and not a record made afterwards.
MD001/GBThreat modelling and detection scopingMandatoryInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.What may be looked for is a closed list. Interception on the employer’s own system is authorized to establish the existence of facts, to ascertain compliance with regulatory or self-regulatory practices, to ascertain or demonstrate the standards achieved by the people using the system, in the interests of national security, to prevent or detect crime, to investigate or detect the unauthorized use of that or any other telecommunication system, or to secure the effective operation of the system. A purpose outside the list is not authorized by these regulations.
MD003/GBDetection use case developmentMandatoryInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.Investigating or detecting the unauthorized use of that or any other telecommunication system is named in the list of purposes in its own right, so the misuse of the employer’s own system is a purpose the regulations authorize interception for rather than one that has to be brought under another.
MD005/GBNetwork and egress monitoringMandatoryInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.Inspection that amounts to interception in the course of transmission is authorized only on the express consent of the system controller, only for a purpose in the list, and only where it is effected solely to monitor or record communications relevant to the activities carried on and the system is provided wholly or partly in connection with them.
MD006/GBElectronic mail and collaboration monitoringMandatoryInvestigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026The closed list of purposes for which an employer may intercept communications on its own system, and the four conditions on doing it, of which one is telling everyone who may use the system.Recording what passes through the employer’s own messaging system is interception in the course of transmission. It is authorized on the express consent of the system controller, for a purpose in the closed list, and on four conditions, of which the third is that the system controller has made all reasonable efforts to inform every person who may use the system that communications transmitted by it may be intercepted.
MD008/GBAccess to the content of communicationsMandatoryInvestigatory Powers Act 2016, sections 3 and 46Parliament of the United Kingdom · read 30 Aug 2026Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-Keeping Purposes) Regulations 2018Secretary of State · read 30 Aug 2026That intercepting a communication in transmission without lawful authority is a criminal offence, and that a person with a right to control a private system is outside it.Intercepting a communication in the course of its transmission without lawful authority is a criminal offence. A person with a right to control the operation or use of a private system, or who has that person’s express or implied consent, is outside the offence, so an employer reading on its own system does not commit it by that route. What the offence does is put the question of authority before the question of proportionality. As to that authority, opening the content in transmission is what these regulations authorize, and they authorize it only for a purpose in the closed list and only where the interception is effected solely to monitor or record communications relevant to the activities carried on.
PS011/GBRecords concerning trade union activityMandatoryRegulation (EU) 2016/679 as it has effect in domestic law, articles 6, 9, 22A to 22D, and 35Retained under the European Union (Withdrawal) Act 2018 · read 30 Aug 2026Data Protection Act 2018, section 10 and Schedule 1Parliament of the United Kingdom · read 30 Aug 2026The grounds, the closed categories, when an assessment is owed, and a rule on deciding about someone by machine that is not the Union’s.Trade union membership is one of the categories the processing of which is prohibited, and in domestic law the prohibition lifts only where the processing also rests on a ground in article 6(1) and one of the article 9 grounds applies. The employment ground requires domestic law or a collective agreement, which is the Schedule 1 condition and the document it carries. In turn, the employment condition is met only where the processing is necessary to perform or exercise an obligation or a right imposed by law in connection with employment, and where the appropriate policy document is in place at the time.
PS012/GBRecords concerning health held for security purposesMandatoryRegulation (EU) 2016/679 as it has effect in domestic law, articles 6, 9, 22A to 22D, and 35Retained under the European Union (Withdrawal) Act 2018 · read 30 Aug 2026Data Protection Act 2018, section 10 and Schedule 1Parliament of the United Kingdom · read 30 Aug 2026The grounds, the closed categories, when an assessment is owed, and a rule on deciding about someone by machine that is not the Union’s.Data concerning health are one of the prohibited categories, and the prohibition lifts only where the processing also rests on a ground in article 6(1) and one of the article 9 grounds applies. A security purpose is not among them. In turn, holding such a record for the program runs through the employment condition, which asks whether the processing is necessary to perform an obligation or a right imposed by law, and which requires the appropriate policy document to be in place when it is carried out.
27Recommended
AW001Workforce awareness on insider riskwhere writtenRecommendedInsider Risk Mitigation Digital LearningNPSA · read 12 Aug 2026The mitigation framework taught in nine modules, with governance and leadership set as the foundation of personnel security.Awareness is delivered as a course rather than a notice, in modules of ten to twenty minutes, with governance and leadership taught before the controls.
AW002Transparency notice on what is observedwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.Workers must be made aware of how and what personal information is collected. A system could be set up so that they remain aware that monitoring is taking place, through an intranet or signage in the areas it reaches. The privacy information must be kept up to date, and workers must be told when a change is introduced.
AW003Role-specific trainingwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.The people who handle what monitoring produces should be trained to handle it, and they are to be identified as the appropriate people for that rather than reached by default.
BA001Risk indicator cataloguewhere writtenRecommendedInsider Data Collection Study: Report of Main FindingsNPSA, published as CPNI · read 11 Aug 2026How real insider acts occurred and what preceded them, from a review of United Kingdom cases.Real cases have been reviewed and what preceded the acts described, which is where an indicator can be taken from rather than supposed.
DP012Retention and disposal of program recordswhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.What monitoring produces must not be kept longer than is necessary for the purpose. The period should rest on business need and be reviewed regularly, and it should not be kept in case a purpose is found for it later. A retention schedule must exist and what is collected must be deleted in line with it.
DP013Separation of program datawhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.Access to what monitoring produces should be restricted to the people who need it, the most appropriate people to hold it should be identified rather than assumed, and they should be trained to handle it. The security risks of the monitoring itself should be assessed and the measures decided from that assessment.
GV001Program charter and mandatewhere writtenRecommendedInsider Risk Mitigation FrameworkNPSA · read 11 Aug 2026A structure for an insider risk management program that an organization reviews itself against, with governance and culture as foundations rather than adjuncts.The charter is written to be reviewed against rather than filed: governance and culture are set out as things a program is measured on, not as preamble to the controls.
GV003Cross-functional governance bodywhere writtenRecommendedInsider Risk Practitioners and StakeholdersNPSA · read 29 Aug 2026That a program needs a senior stakeholder group drawn from named functions, and a director who carries the board’s strategy into policy.The group is named and its membership drawn: physical and information security, technology, human resources, vetting, facilities, contracts, procurement, finance, counter fraud, legal, training, communications, and a staff or trade union representative. What the group decides is not stated.
GV004Roles and decision rightswhere writtenRecommendedInsider Risk Practitioners and StakeholdersNPSA · read 29 Aug 2026Board Engagement and GovernanceNPSA · read 29 Aug 2026That a program needs a senior stakeholder group drawn from named functions, and a director who carries the board’s strategy into policy.One board member holds overall responsibility for protective security, and a non-executive director acts as an independent champion for it. Below them a director carries the strategy into policy, and senior staff in each business area answer for the risk assessment and for implementation in their own.
GV005Shared definitions and severity scalewhere writtenRecommendedNPSA Changes to Insider Risk DefinitionsNPSA · read 11 Aug 2026Revised definitions of insider, insider risk, insider threat, and insider event, organized around intent.The definitions of insider, insider risk, insider threat, and insider event were revised, and they are organized around intent.
GV005Shared definitions and severity scalewhere writtenRecommendedSetting the Foundations: Five Principles for a Shared Approach to Insider RiskNPSA · read 11 Aug 2026Five principles offered as a shared basis, with intentional and unintentional events placed on one spectrum of intent.The definitions are agreed to be used consistently, and intentional and unintentional events are held on one spectrum so that a severity scale does not have to choose between them.
GV008Impact assessment before deploymentwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.An assessment must be carried out before any processing likely to cause high risk, and the examples given reach an insider risk management program directly: the biometric data of workers, keystroke monitoring, monitoring that may result in financial loss, and the use of profiling or special category data to decide on access. Where there is a data protection officer, their independent advice must be sought and recorded. Anyone else the monitoring captures, a customer or a member of a worker’s household, is to be considered in it.
GV010Worker representative engagementwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.The views of the workforce or its representatives should be sought and documented before monitoring is introduced, unless there is a good reason not to, and where the decision is not to, that decision should be recorded with a clear explanation. It should be done early in the planning and as part of the impact assessment.
GV012Program metrics and reportingwhere writtenRecommendedBoard Engagement and GovernanceNPSA · read 29 Aug 2026That one board member holds overall responsibility for protective security and is regularly engaged with the program, with a non-executive director as an independent champion.The board member who holds the responsibility is to be regularly engaged with the people running the program and to hold a firm understanding of the risks it addresses. What is to be reported, and how often, is not stated.
GV013Periodic program reviewwhere writtenRecommendedInsider Risk Mitigation FrameworkNPSA · read 11 Aug 2026A structure for an insider risk management program that an organization reviews itself against, with governance and culture as foundations rather than adjuncts.The framework is offered as something an organization reviews itself against, which makes the review a recurring act rather than a one-off inspection.
GV014Answering a request from the personwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.What monitoring collects must be made available on a request unless an exemption applies, and the guidance turns that into a constraint on design: how easily information can be retrieved should bear on the choice of monitoring system in the first place, and that should be settled in the impact assessment. A system that cannot answer a request is a choice made earlier, not a difficulty met later.
IV001Internal reporting channelwhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Reporting routes are treated as a control in their own right, and their value as depending on whether they are trusted.
IV002Case intake and triagewhere writtenRecommendedInsider Data Collection Study: Report of Main FindingsNPSA, published as CPNI · read 11 Aug 2026How real insider acts occurred and what preceded them, from a review of United Kingdom cases.The threshold has real cases to be set against: how the acts occurred and what preceded them, in a national population now some years old.
MD004Endpoint activity monitoringwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.Keystroke monitoring is named as an example of processing likely to cause high risk, so an assessment is owed before the agent is put on the device rather than after.
MD016Measurement of pace and performancewhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.Monitoring that may result in financial loss, performance management given as the example, is named among the processing likely to cause high risk.
MD018Covert monitoring on prior suspicionwhere writtenRecommendedEmployment practices and data protection: monitoring workersInformation Commissioner's Office · read 30 Aug 2026What the British regulator expects of an employer that watches its workers, told apart as what an employer must do and what it should, and the conditions it sets on watching them without telling them.Watching without telling is unlikely to be justified in most circumstances, and where it is, the conditions are set out. It should be authorized only by senior management. An impact assessment must be carried out. There should be grounds for suspecting criminal activity or an equivalent such as gross misconduct, and a view that telling the workforce would prejudice detecting it. It should be strictly targeted at obtaining evidence within a set timeframe, kept to the shortest possible, and it should not continue once the investigation is complete. It should not reach places where a worker would reasonably expect privacy, and in most circumstances it should not capture communications a worker would reasonably expect to be private.
PS001Pre-employment screeningwhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Good practice treats screening at recruitment as the opening of a process rather than its completion.
PS004Screening during employmentwhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Contracting is covered alongside employment, so the standard is set for people the organization does not employ.
PS005Contractor and third-party personnel standardswhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Briefing at joining is treated as part of ongoing personnel security rather than as an administrative step.
PS008Leaver processwhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Exit is covered as a stage of personnel security, with what is withdrawn and what is restated set out together.
PS009Line management engagementwhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Line management is treated as the route by which concern reaches the program, which makes the manager part of the control.
PS013Self-declaration of changed circumstanceswhere writtenRecommendedOngoing Personnel Security: A Good Practice GuideNPSA · read 11 Aug 2026Good practice for personnel security through employment rather than at the door, holding that protective monitoring should be proportionate.Reporting routes are covered as good practice, including the route by which a person reports about themselves.
8Reported
BA001Risk indicator cataloguewhere writtenReportedUnderstanding Insider Threat: A Framework for Characterising AttacksNurse, Buckley, Legg, Goldsmith, Creese, Wright, and Whitty · read 11 Aug 2026A vocabulary for describing an insider attack in four parts: catalyst, actor, attack, and organization.A published vocabulary is available to build the catalogue on: catalyst, actor, attack, and organization, grounded in case studies rather than telemetry.
BA004Use of psychological and dispositional indicatorswhere writtenReportedIntegrating Human Factors into Insider Threat Detection: A Systematic ReviewPathirana, Roberts, Kalutarage, and McDermott · read 16 Aug 2026The models, data sources, and evaluation methods used where detection research has taken up human factors.Reviews of the detection literature map which human factors have been modelled and on what data, and test none of them.
BA005Use of linguistic indicatorswhere writtenReportedDeveloping an ‘Insider Language Index’ as a composite measure to detect insider threatMartlew, Ball, Dando, Ormerod, Taylor, Menacere, Sandham, and Richardson · read 11 Aug 2026That insiders differed measurably in interview language, by cognitive processing words, self-reference, and negative emotion.The differences were measured in interview language, so an index built on the ordinary flow of workplace communication is extrapolating beyond what was observed.
BA009Model validation and bias testingwhere writtenReportedIntegrating Human Factors into Insider Threat Detection: A Systematic ReviewPathirana, Roberts, Kalutarage, and McDermott · read 16 Aug 2026The models, data sources, and evaluation methods used where detection research has taken up human factors.The evaluation methods used across the published work have been mapped, which is the starting point for validating one.
GV013Periodic program reviewwhere writtenReportedSystematic analysis of security advice on the topic of insider threatsStewart and Hobbs · read 11 Aug 2026What the published guidance on insider threat actually instructs a reader to do, the advice literature being the object of study.The advice literature has itself been coded and characterised, so what guidance instructs can be examined rather than assumed.
MD003Detection use case developmentwhere writtenReportedCorporate Insider Threat Detection (CITD)University of Oxford · read 11 Aug 2026A research program combining security engineering with psychology and criminology, producing a characterization framework and a working tool.A characterization framework and a working tool came out of the research program, which is a starting point a use case can be derived from rather than invented.
MD003Detection use case developmentwhere writtenReportedInsider-threat detection: Lessons from deploying the CITD tool in three multinational organisationsErola, Agrafiotis, Goldsmith, and Creese · read 11 Aug 2026The operational constraints that emerged when a research detection tool ran inside three organizations for more than a year.Deploying a research tool inside three organizations for a year surfaced the operational constraints that the detection literature leaves out.
MD012User and entity behavior analyticswhere writtenReportedIntegrating Human Factors into Insider Threat Detection: A Systematic ReviewPathirana, Roberts, Kalutarage, and McDermott · read 16 Aug 2026The models, data sources, and evaluation methods used where detection research has taken up human factors.The models and data sources the research has used are catalogued and untested, so an engine built on them inherits an evidence base nobody has validated.