Alessandro AleddaInsider Threat and Risk

The Work

What the work is

Insider risk is the one security problem every function in the organization owns a piece of.

It sits where governance, technology, investigation, compliance and privacy meet, and each of them has a claim on the same decision. A program has to answer all of those claims at once. Nothing else in security is built under that condition.

Making one means designing it, establishing what it may lawfully do in each place it runs, building it into the platform, and running it so that a case still holds a year later, when someone contests it.

What the work requires

Ten areas, and what each one delivers.

Program architecture

The mandate, the declared perimeter, and the order in which the parts are built.

Deliverables

  • Program charter
  • Scope statement
  • Capability model
  • Roadmap

In the record  GV001 GV002 GV003

Governance

Who decides what, at which threshold, and which document establishes it.

Deliverables

  • Decision rights and escalation matrices
  • Accountability evidence
  • Review cycle

In the record  GV004 GV005 GV006 GV009

Compliance

What may be collected in each place the program runs, on what basis, and with whose agreement. The design puts the questions where Legal, the data protection officer and the works council can answer them.

Deliverables

  • Lawful basis register
  • Impact assessment question set
  • Worker representation pack
  • Jurisdiction differences

In the record  GV007 GV008 GV010 GV011 GV014

Detection

What the program watches for, and why. A use case states the behavior and the reason for watching it before any rule exists.

Deliverables

  • Use case catalogue
  • Signal inventory
  • Indicator and threshold design

In the record  MD001 MD003 MD012 MD021 BA001

Technology

How a use case becomes something that runs: Microsoft Purview, SIEM, UEBA, XDR, EDR, DLP, IAM, and the automation between them.

Deliverables

  • Policy architecture
  • Tuning record
  • Integration design
  • SOAR workflows

In the record  MD002 MD004 MD005 DP007 DP008

Investigation

How an alert becomes a case, and how the case is built so that it holds when it is contested.

Deliverables

  • Triage standard
  • Case opening criteria
  • Investigation plan
  • Evidence and chain of custody

In the record  IV002 IV003 IV004 IV005 IV006 IV010

Response

What may be done while an event is open, who authorizes it, and what is owed to whom.

Deliverables

  • Playbooks
  • Containment and access decisions
  • Escalation paths
  • Notification obligations

In the record  IR001 IR002 IR003 IR006 IR007

Consequence

What may follow for a person, agreed with HR and Legal before any case exists.

Deliverables

  • Consequence framework
  • Disciplinary interface
  • Formal warnings
  • Findings that stand in proceedings

In the record  CP001 CP002 CP003 CP007

Operating model

Roles, workflows, service levels, handovers, and how much a team can carry.

Deliverables

  • RACI
  • Runbooks
  • Service levels
  • Operational handover

In the record  GV004 MD020 IV013 AW003

Measurement and assurance

Whether the program works, and whether it can prove it.

Deliverables

  • Metrics framework
  • Control effectiveness testing
  • Program review

In the record  GV012 GV013 MD021 AW006

How its parts hold together

A program answers five questions at once, and each answer fails in a different way.

The mandate says what the organization is trying to do and who decides. The controls are what each European jurisdiction lets it do, and INTRA™ holds the sources. An event is what happens when the controls are not enough, and ITER™ holds what that obliges, to whom, and by when. The technology carries the part that can be automated. The operations are the rest.

A program with no mandate cannot authorize a control. A control with no lawful basis cannot be operated. An event with no fixed moment of knowledge has no deadline anyone can meet. Technology with nobody behind it produces alerts nobody reaches. And operations that keep no record cannot be defended when they are questioned.

This is the work. Applying it inside one organization is what I do.

What this does not solve

The work puts decisions in front of the people who own them. It does not take them.

Legal advice. The design puts the questions to Legal in a form they can answer. It does not answer them, and it is not advice on the law of any jurisdiction.

Lawfulness. The data protection officer decides it. The program’s part is to put the decision before collection begins, not after an incident.

Risk appetite. Management sets it. A program can say what a control costs and what it leaves uncovered. It cannot say how much of that is acceptable.

The decision about a person. HR and management make it, on their mandate. What the work owes them is a record made while the outcome was still unknown.