Services
What I work on
Insider risk is the one security problem no single tool or function can solve on its own.
The program needs one accountable owner, usually security, whether cyber, physical, or the two governed as one. The decisions it depends on sit elsewhere. The problem sits where risk, governance, information technology, human resources, operations, compliance, and privacy meet, and each of them holds a part of what the program needs in order to act. A program has to bring all of them inside its mandate, and has to read the organization as a whole to see where the risk actually is. Little else in security is built under that condition.
Making one means designing it, establishing what it may lawfully do in each place it runs, building it into the platform, and running it so that its cases are defensible. That is the work I do, inside the organization, with the functions that own its decisions.
What I offer
Five services, and what each one delivers.
Program design
I design the mandate and operating model of the program with the functions that share the risk: the charter, the lawful scope of observation in each jurisdiction, the allocation of decisions and escalation, and the service levels between functions.
Deliverables
- Program charter
- Scope statement
- Capability model and roadmap
- Decision and escalation matrix
- RACI, service levels and runbooks
Detection engineering
I engineer detection and prevention on the organization’s own risks: from a map of those risks to use cases, and from use cases to the policies, thresholds, and automations of the platform in place, such as Microsoft Purview, calibrated on its measured baseline.
Deliverables
- Insider risk map
- Use case catalogue
- Use case implementation
- Policy architecture
- Tuning record
Investigation and response
I build the procedure from alert to case closure: triage and enrichment, investigation within agreed limits, reversible containment, evidence to the standard of the proceedings it may reach, and the obligations an event triggers, to whom and by when.
Deliverables
- Triage and enrichment standard
- Investigation plan and playbooks
- Evidence and chain of custody standard
- Interview protocol
- Reporting obligations map and consequence framework
Operations and enablement
I run the function alongside the team that will take it over: capacity sized on measured volume, a stated cadence, case records, tuning in operation, and analysts trained on simulated cases, until the handover.
Deliverables
- Operating capacity and cadence
- Case records
- Analyst training and case simulations
- Operational handover
Program assessment
I assess a program in operation: what it covers against the measures an insider risk management program is built from, as INTRA™ sets them out, and against the organization’s scenarios, whether its controls operate as intended on evidence, how it performs, and the order in which its gaps close.
Deliverables
- Coverage analysis
- Control effectiveness testing
- Performance framework
- Program review and prioritized roadmap
How I work
End to end where it is required, and from wherever the function has reached.
From wherever the function has reached. Where an organization starts without a program, I take it from the mandate to operation and stay until it runs as designed. Where a function already exists, I take on what it lacks. A program is built in an order that holds wherever the work begins: the mandate and its lawful basis, the detection, the case, the operation. Many functions were built otherwise, with the platform years before the mandate; there the work closes the earliest gap in that order first.
Independent, inside, alongside. I work inside the organization, on the platform it owns and in the jurisdictions where it operates, alongside the multidisciplinary teams who will own the program, and I leave the record that supports each decision. The record the work stands on is open: INTRA™ and ITER™.
The decisions that remain with the organization. Legal advice, the lawfulness of each measure, risk appetite, and the decision about a person belong to Legal, to the organization as controller on the advice of its Data Protection Officer, to management, and to Human Resources. The work prepares each decision for the function that owns it, in a form it can answer, and records the answer.
The engagement. It begins with a conversation on what the organization needs, and then with a reading of its current state: the documents, the platforms, the cases, and the people who run them. The scope follows from it: the full program, or one or more of the five services. The head of security can commission the work, and I bring in Legal, Human Resources, the Data Protection Officer, and information technology as it needs them. I do the work personally, in every service, on site and remotely as it requires, in English or Italian, directly or through the consulting firm the organization already works with. Confidentiality and data processing terms are signed before any material is shared, and the work is covered by professional indemnity insurance. Design and assessment run on documents, configurations, and aggregate figures; case material is read only where a service requires it, under the organization’s access controls. For a full program, the first ninety days usually close with an agreed roadmap, and each service ends with documents the organization owns.
FAQ
What is an insider risk management program?
The mandate, the allocation of decisions, and the detection, investigation, response, measurement, and operations through which an organization addresses insider risk, under a documented lawful basis and within the safeguards owed to the people it observes. Insider risk is the possibility that a person with legitimate access, through action or omission, deliberately or by mistake, causes harm to the confidentiality, integrity, or availability of the organization’s information, or to its people and assets. The program is built on the organization’s own scenarios: who, with which access, could cause harm to which asset, and through which channel. Detection is designed for them, and coverage and gaps are measured against them.
The organization already owns Microsoft Purview. What is missing?
Usually what the licence does not contain. Insider Risk Management, Data Loss Prevention, and Information Protection ship with signals, policy templates, and default thresholds calibrated on nobody’s organization. What turns them into detection sits upstream of the tenant: a map of the insider risks the organization actually carries, use cases that state the behavior and the reason before any rule exists, thresholds set against the organization’s own baseline, and a triage standard for what comes out. Without them, the platform raises alerts at the rate of its templates, and the volume that reaches the function bears no relation to the organization’s risk.
Is the work limited to Microsoft Purview?
No. The method is independent of the platform: the risk map, the use cases, and the thresholds are written before any rule exists, and are then implemented on the platform in place. Where that is Microsoft Purview, with Defender and Sentinel beside it, the work implements on it directly; on another platform I build it with the engineers who run that platform, and the implementation takes longer and is planned as such.
Can the Security Operations Center (SOC) handle insider cases?
It can host the function, which remains distinct from it. A SOC decides whether an event is a true or a false positive on technical telemetry. In an insider case, the same action by the same account is lawful or unlawful depending on the organizational context in which it occurs, and the telemetry does not contain the distinction. The insider threat function therefore needs a designated source of context in the business for every population it observes. The two share tooling, escalation paths, and the incident classification scheme. They differ in analytical approach, which adds contextual and behavioral indicators to telemetry, in the evidence that decides a case, in the functions a case involves, and in the legal constraints on observing a person.
Does insider risk include AI agents?
Yes. Several established definitions still name a person; in this practice an insider is defined by legitimate access to the organization’s systems, information, premises, or people: employees, contractors, suppliers, and the non-human identities that act on their behalf. Employment status, intent, and position qualify the insider; access defines it. An agent that acts under its own identity reaches the same information through the same channels as the person who deployed it, and harm caused through it travels through the same actions as daily work. It belongs in the same scenarios, the same detection, and the same case procedure.
Which functions have to be involved?
One function owns the program, usually security, where detection, investigation, and response converge. The decisions it depends on sit elsewhere, and the work reaches them where they are: Legal and the Data Protection Officer, who advise the organization as controller on the lawful basis of each measure; Human Resources for the consequence framework and the interface with discipline; the works council or the unions where the jurisdiction requires their involvement; information technology for the platform and its telemetry; Risk for the appetite; the business for what is actually at risk. A program that reaches operation without them runs on a mandate nobody agreed to, and the gap usually surfaces with the first case that reaches a works council or a court.
Is monitoring at work lawful in Europe?
Under conditions, and the conditions are national. Every European jurisdiction admits some monitoring of work and excludes some. What separates them is who has to be informed, consulted, or asked to agree before it starts, a works council, a union, or a labour authority; what has to exist in writing beforehand, an impact assessment, an information notice, a lawful basis stated per measure; and how long what is collected may be kept. Whether a given measure is lawful in a given organization is decided by the organization as controller, on the advice of its Data Protection Officer and of Legal. The work puts each measure in front of them in a form they can answer, before collection begins, and keeps the answer on record.
What do NIS2 and DORA require of an insider risk management program?
Both can reach an insider event, and neither turns on who caused it. Directive (EU) 2022/2555 (NIS2), as transposed in each Member State, lists among the measures essential and important entities have to take human resources security, access control policies, asset management, and training, and leaves their content to the state of the art; for digital infrastructure and service providers, its implementing regulation spells that content out, from background verification and the review of access on a change of role to logging, the triage of suspicious events, and a disciplinary process. Its reporting sequence applies to an incident that meets the criteria of a significant incident. Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), requires a financial entity to detect, manage, record, and classify ICT-related incidents under a defined process, and to report those classified as major. An event caused by an insider enters either regime on its effects and on the thresholds that apply to the entity.
Is the work limited to European organizations?
No. The work serves programs that have to hold under European regulatory constraint: a European subsidiary or workforce, data on European employees, or a group program that has to run in a European country without being rewritten there. A program designed for a permissive regime is usually rebuilt at its first works council in Europe; a program designed for the European constraint runs elsewhere with few changes.
How long does it take to build a program?
For a program at an early stage, in one jurisdiction, usually about a year until it is mature enough to run on its own and as designed: the mandate and the lawful scope first, the risk map and the use cases alongside them, the case procedure as detection reaches production, and the operation and handover in the second half. The calendar is usually set by the agreements, the measurement periods, and the approvals, more than by the writing. Each further jurisdiction adds the time of its agreement with workers’ representatives, and where a program already runs, the assessment of its current state sets where the work begins. A single service is scoped to its output and to the condition at which it is complete, rather than to a standard duration.
What services are not provided?
Three, by design. Legal advice: the work puts the questions to Legal and to the Data Protection Officer in a form they can answer, and the answers remain theirs. The decisions that belong to others: the risk appetite, which management sets, and the decision about a person, which Human Resources and management take on their mandate. And forensic analysis for proceedings: I build the case and the record around it to an evidential standard, chain of custody included, and hand it to a forensic examiner when the matter requires one.
Contact
If you are building this function, or you are responsible for protecting your organization’s information, people, and assets from the threat within, reach out to me.
The first step is to establish what your organization needs; the solution is designed around it. A short description of the organization, the function as it stands, and what the work should achieve is enough to begin. What you write stays between us: no form, no tracking, an email, a conversation on Teams, or a message on LinkedIn, and nothing else.

