The Work
What the work is
Insider risk is the one security problem every function in the organization owns a piece of.
It sits where governance, technology, investigation, compliance and privacy meet, and each of them has a claim on the same decision. A program has to answer all of those claims at once. Nothing else in security is built under that condition.
Making one means designing it, establishing what it may lawfully do in each place it runs, building it into the platform, and running it so that a case still holds a year later, when someone contests it.
What the work requires
Ten areas, and what each one delivers.
Compliance
What may be collected in each place the program runs, on what basis, and with whose agreement. The design puts the questions where Legal, the data protection officer and the works council can answer them.
How its parts hold together
A program answers five questions at once, and each answer fails in a different way.
The mandate says what the organization is trying to do and who decides. The controls are what each European jurisdiction lets it do, and INTRA™ holds the sources. An event is what happens when the controls are not enough, and ITER™ holds what that obliges, to whom, and by when. The technology carries the part that can be automated. The operations are the rest.
A program with no mandate cannot authorize a control. A control with no lawful basis cannot be operated. An event with no fixed moment of knowledge has no deadline anyone can meet. Technology with nobody behind it produces alerts nobody reaches. And operations that keep no record cannot be defended when they are questioned.
This is the work. Applying it inside one organization is what I do.
What this does not solve
The work puts decisions in front of the people who own them. It does not take them.
Legal advice. The design puts the questions to Legal in a form they can answer. It does not answer them, and it is not advice on the law of any jurisdiction.
Lawfulness. The data protection officer decides it. The program’s part is to put the decision before collection begins, not after an incident.
Risk appetite. Management sets it. A program can say what a control costs and what it leaves uncovered. It cannot say how much of that is acceptable.
The decision about a person. HR and management make it, on their mandate. What the work owes them is a record made while the outcome was still unknown.

