Insider Threats: Protecting Your Business from Within

The Enemy Within

Insider threats represent one of the most dangerous yet overlooked risks facing South African businesses. While headlines focus on external hackers and sophisticated malware, the reality is sobering: 95% of cyber incidents in South Africa are linked to human error according to research compiled by Corbado. Whether through negligence, malice, or compromised credentials, the people inside your organisation often pose the greatest risk to your security.

Globally, 83% of organisations experienced at least one insider attack in the past year according to the Ponemon Institute. The average annual cost has reached $17.4 million (approximately R313 million), with a single malicious insider incident costing an average of $4.92 million (R88.5 million). For South African SMBs already facing R53.1 million average breach costs, insider threats demand serious attention.


The Hidden Threat Landscape

External attackers make noise. They probe your perimeter, trigger alerts, and leave traces. Insider threats are different—they already have legitimate access, know your systems, and understand how to avoid detection.

Consider the South African context:

Insider Risk IndicatorSouth Africa
Cyber incidents linked to human error95%
Organisations targeted by phishing/impersonation84%
Impersonation fraud increase (2023-2024)356%
Employees who reuse credentials across work apps49%
Digital banking fraud increase (YoY)24%
Banking application fraud increase (YoY)36%

The SA Fraud Prevention Service reported a 26% year-on-year increase in overall fraud cases, with impersonation fraud spiking an alarming 356%. These aren't external hackers—they're attacks that exploit human vulnerabilities and insider access.


Three Types of Insider Threats

Not all insider threats are created equal. Understanding the different types helps you implement appropriate controls for each.

1. The Negligent Insider

The most common type, negligent insiders cause harm through carelessness rather than malicious intent. Globally, organisations experience an average of 13.5 negligent insider incidents per year.

Common negligent behaviours:

  • Clicking phishing links or opening malicious attachments
  • Using weak or reused passwords
  • Sending sensitive data to wrong recipients
  • Leaving devices unlocked or unattended
  • Connecting to unsecured public WiFi
  • Sharing credentials with colleagues for "convenience"
  • Bypassing security controls to "get work done"

In South Africa, 36.7% of African employees fall for phishing schemes according to KnowBe4. With 84% of local organisations targeted by phishing attacks, negligent clicks translate directly to breaches.

Real-world example: The Passenger Rail Agency of South Africa (PRASA) lost approximately R30.6 million to phishing and impersonation attacks. These weren't sophisticated nation-state hackers—they were social engineering attacks that exploited human trust and negligence.

2. The Malicious Insider

Malicious insiders deliberately abuse their access for personal gain, revenge, or sabotage. While less common than negligent insiders, their impact is typically far more severe.

Motivations for malicious insider activity:

  • Financial gain (47% of cases)
  • Revenge against the organisation
  • Competitive advantage (stealing data for new employer)
  • Ideological reasons
  • Coercion by external parties

Concern about malicious insiders has grown from 60% in 2019 to 74% in 2024. Organisations with 11-20 insider attacks increased fivefold, from 4% to 21%.

Warning signs of malicious insiders:

  • Accessing data outside job requirements
  • Working unusual hours without clear reason
  • Expressing grievances about the organisation
  • Financial difficulties or lifestyle changes
  • Resignation followed by unusual data access
  • Attempts to bypass security controls
  • Reluctance to take leave (maintaining control)

3. The Compromised Insider

Compromised insiders are legitimate users whose credentials have been stolen through phishing, malware, or social engineering. The employee may be completely unaware their account is being used by attackers.

In South Africa, compromised credentials accounted for 26% of ransomware attacks—the second most common vector after malicious email. Once attackers have valid credentials, they operate with the user's legitimate access rights, making detection extremely difficult.

How credentials get compromised:

  • Phishing emails harvesting login details
  • Infostealer malware capturing keystrokes
  • Credential stuffing from breached password databases
  • Social engineering via phone or messaging
  • Man-in-the-middle attacks on public networks

ESET's 2024 Threat Report reveals that 35% of all infostealer attacks in Africa targeted South Africa. These attacks exist specifically to harvest credentials for later misuse.


Why Insider Threats Are So Difficult to Detect

Insider threats pose unique detection challenges that external attacks don't:

ChallengeWhy It's Difficult
Legitimate accessInsiders already have authorised access to systems and data
Knowledge of controlsThey know what's monitored and how to avoid detection
Trusted positionSecurity teams focus outward, not on colleagues
Gradual escalationMalicious activity often builds slowly over time
Normal behaviour baselineHard to distinguish malicious from legitimate access
Encrypted channelsCan exfiltrate via approved tools (email, cloud storage)

The numbers confirm the challenge: the average time to identify and contain an insider incident is 81 days according to Ponemon Institute research. A staggering 90% of security professionals report that insider threats are equally or more difficult to detect than external attacks.

During those 81 days, a malicious insider can exfiltrate massive amounts of data, plant backdoors, or cause extensive damage—all while appearing to work normally.


The Cost of Insider Threats

The financial impact of insider threats is severe and often underestimated:

Global Costs

MetricCost (USD)Cost (ZAR Approx.)
Average annual insider threat cost$17.4 millionR313 million
Single malicious insider breach$4.92 millionR88.5 million
Negligent insider incident$6.6 millionR119 million
Credential theft incident$4.6 millionR83 million
Cost increase since 2018109%—

South African Context

Incident TypeCost/Impact
Average data breach (SA)R53.1 million
Financial sector breach (SA)R70.2 million
PRASA phishing/impersonation lossesR30.6 million
Digital banking fraud (SA, 2022)R740 million
Phishing losses (SA, 2023)R200 million

Beyond direct financial losses, insider threats cause:

  • Intellectual property theft
  • Competitive disadvantage
  • Regulatory penalties (POPIA fines up to R10 million)
  • Reputational damage
  • Customer trust erosion
  • Operational disruption

Building an Insider Threat Programme

Addressing insider threats requires a balanced approach combining technology, processes, and culture. Here's how to build an effective programme:

1. Implement the Principle of Least Privilege

Users should have only the minimum access necessary to perform their job functions. This limits the damage any single insider can cause.

Implementation steps:

  • Audit current access levels across all systems
  • Define access requirements based on job roles, not individuals
  • Remove excessive permissions immediately
  • Implement just-in-time access for privileged operations
  • Review and adjust access when roles change
  • Conduct quarterly access reviews

When a compromised account can only access limited data, the breach impact shrinks proportionally. Identity access management forms the foundation of insider threat mitigation.

2. Deploy User Activity Monitoring

You cannot detect insider threats without visibility into user behaviour. Monitoring tools establish baselines and flag anomalies.

What to monitor:

ActivityWhy It Matters
File access patternsDetect unusual data access
Data transfersIdentify potential exfiltration
Login times and locationsSpot credential compromise
Privileged command usageTrack administrative actions
Email and messagingDetect policy violations
Cloud storage activityMonitor shadow IT and data movement
USB and removable mediaPrevent physical data theft

Important considerations:

  • Balance security with employee privacy
  • Comply with labour laws and POPIA
  • Communicate monitoring policies clearly
  • Focus on protecting data, not surveilling individuals
  • Use monitoring for security, not performance management

3. Implement Data Loss Prevention (DLP)

DLP tools prevent sensitive data from leaving your organisation through unauthorised channels.

DLP capabilities:

  • Block sensitive data in outbound emails
  • Prevent uploads to unauthorised cloud services
  • Restrict copying to USB devices
  • Watermark documents for traceability
  • Alert on policy violations
  • Encrypt sensitive data automatically

For Microsoft 365 environments, Microsoft Purview provides integrated DLP across email, SharePoint, Teams, and endpoints.

4. Conduct Security Awareness Training

With 95% of South African incidents linked to human error, training dramatically reduces insider threats from negligence.

Effective training programmes include:

  • Regular phishing simulations (monthly recommended)
  • Role-specific security training
  • Clear policies on data handling
  • Reporting procedures for suspicious activity
  • Consequences for policy violations
  • Recognition for security-conscious behaviour

Training should be ongoing, not annual. Threats evolve constantly, and awareness fades without reinforcement. With 36.7% of African employees vulnerable to phishing, consistent training delivers measurable risk reduction.

5. Establish Robust Offboarding Procedures

Many insider threats involve former employees whose access wasn't properly revoked. Immediate, comprehensive offboarding is essential.

Offboarding checklist:

  • Disable Active Directory / Entra ID account immediately
  • Revoke VPN and remote access
  • Remove from all cloud applications (Microsoft 365, SaaS tools)
  • Recover company devices (laptop, phone, tokens)
  • Change shared passwords the employee knew
  • Transfer ownership of files, mailboxes, and data
  • Remove from distribution lists and Teams
  • Review recent activity for anomalies
  • Conduct exit interview (gauge sentiment)
  • Archive mailbox for potential investigation

The moment an employee resigns or is terminated, access revocation should begin—not at the end of their notice period.

6. Create Safe Reporting Channels

Employees often notice warning signs before security teams. Make it easy to report concerns without fear of retaliation.

Effective reporting mechanisms:

  • Anonymous tip line or online form
  • Clear escalation procedures
  • Protection for whistleblowers
  • Timely acknowledgment and follow-up
  • Communication about how reports are handled (without specifics)

Peer reporting catches many malicious insiders before significant damage occurs. Culture matters: employees must trust that reporting is valued, not punished.


Insider Threat Indicators and Warning Signs

Train managers and security teams to recognise potential insider threats:

Behavioural Indicators

Warning SignPossible Concern
Sudden financial difficultiesMotivation for theft
Expressed grievances about organisationRevenge motivation
Working unusual hours without reasonHiding activity
Reluctance to take leaveMaintaining control over scheme
Lifestyle changes inconsistent with salaryUnexplained income
Excessive interest in areas outside job scopeReconnaissance
Resistance to security controlsAttempting to avoid detection
Social engineering colleagues for accessBuilding inappropriate access

Technical Indicators

Warning SignPossible Concern
Accessing data outside job requirementsData theft preparation
Large data downloads or transfersExfiltration
Access attempts outside normal hoursCompromised credentials or malicious activity
Failed access attempts to restricted areasProbing for weaknesses
Use of unauthorised storage devicesPhysical data theft
Attempts to disable security toolsCovering tracks
Email forwarding to personal accountsData exfiltration
Accessing systems after resignation noticeLast-minute theft

No single indicator confirms malicious intent. Look for patterns and combinations. Investigate sensitively—false accusations damage trust and morale.


Insider Threats and POPIA Compliance

For South African businesses, managing insider threats directly supports POPIA compliance:

POPIA RequirementInsider Threat Control
Security safeguardsAccess controls, monitoring, DLP
Authorised access onlyLeast privilege, access reviews
Audit trailsUser activity logging
Breach notificationDetection and response capabilities
Data minimisationLimit who can access personal information

The Information Regulator expects organisations to protect personal information from internal threats, not just external hackers. Demonstrating an insider threat programme shows due diligence.


Technology Solutions for Insider Threat Detection

Several technology categories address insider threats:

User and Entity Behaviour Analytics (UEBA)

UEBA tools establish behavioural baselines and flag anomalies:

  • Unusual access patterns
  • Abnormal data movement
  • Credential misuse indicators
  • Deviation from peer group behaviour

Data Loss Prevention (DLP)

Prevents sensitive data exfiltration:

  • Email content inspection
  • Cloud upload controls
  • Endpoint data protection
  • Network traffic analysis

Privileged Access Management (PAM)

Controls and monitors privileged accounts:

  • Just-in-time access provisioning
  • Session recording
  • Password vaulting
  • Approval workflows

Security Information and Event Management (SIEM)

Correlates events across systems:

  • Centralised log collection
  • Anomaly detection
  • Incident investigation
  • Compliance reporting

For Microsoft environments, Microsoft Purview Insider Risk Management provides integrated insider threat detection across Microsoft 365.


Balancing Security and Trust

Insider threat programmes must balance security with workplace culture. Excessive surveillance damages trust, morale, and productivity. Consider these principles:

Do:

  • Communicate policies clearly and explain why they exist
  • Focus on protecting data, not monitoring individuals
  • Apply controls consistently across all levels
  • Investigate allegations fairly and confidentially
  • Recognise and reward security-conscious behaviour

Don't:

  • Implement covert surveillance without legal review
  • Use security tools for performance monitoring
  • Apply different standards to executives vs staff
  • Create a culture of suspicion and fear
  • Ignore employee privacy rights

The goal is protecting the organisation while maintaining a healthy workplace. Employees who feel trusted generally behave trustworthily. Those who feel surveilled may become resentful—potentially creating the insider threat you're trying to prevent.


Responding to Insider Threat Incidents

When insider threats are detected, response must be swift but measured:

Immediate Steps

  1. Preserve evidence — Do not alert the subject; capture logs and data
  2. Assess scope — Determine what data or systems are affected
  3. Contain the threat — Restrict access without tipping off the subject
  4. Engage stakeholders — HR, legal, and executive leadership
  5. Document everything — Maintain chain of custody for evidence

Investigation Phase

  • Work with HR and legal throughout
  • Conduct forensic analysis of systems and accounts
  • Interview witnesses confidentially
  • Determine intent (negligence vs malice)
  • Assess full impact and exposure

Resolution

  • Take appropriate disciplinary action
  • Report to law enforcement if criminal activity occurred
  • Notify regulators if personal data was compromised (POPIA requirement)
  • Implement controls to prevent recurrence
  • Conduct lessons-learned review

Never confront a suspected malicious insider without HR and legal involvement. Mishandled investigations create legal liability and may compromise evidence for prosecution.


The Human Element: Culture Matters

Technology alone cannot solve insider threats. Culture plays an equally important role:

  • Leadership example: Executives who bypass security undermine the entire programme
  • Open communication: Employees who feel heard are less likely to become disgruntled
  • Fair treatment: Perceived injustice is a common trigger for malicious insiders
  • Support systems: Employee assistance programmes help those facing personal difficulties
  • Recognition: Acknowledge employees who report concerns or demonstrate security awareness

Organisations with positive cultures experience fewer insider incidents. Invest in your people, not just your technology.


Next Steps for Your Organisation

Strengthen your insider threat defences today:

  1. Assess current state — Do you have visibility into user behaviour and data movement?
  2. Implement least privilege — Audit and reduce excessive access immediately
  3. Enable monitoring — Deploy user activity and data loss prevention tools
  4. Train your people — Reduce negligent incidents through awareness
  5. Establish offboarding — Create and enforce immediate access revocation
  6. Build reporting channels — Make it safe to report concerns

Need help building an insider threat programme? Contact RSAT.online for a security assessment tailored to South African businesses.


About RSAT.online

RSAT.online provides practical cybersecurity guidance for South African small and medium businesses. From insider risk assessments to Phishing simulations, we help local organizations protect against threats from within while maintaining positive workplace culture.

Contact us today →

Scroll to Top