Key Takeaways:
- Insider threats come in three main forms, malicious, negligent and compromised, and contractors or vendors with standing access count as insiders too.
- Malicious insider breaches cost USD 4.92 million on average in IBM's 2025 report, the highest of any attack vector, and took 260 days to identify and contain.
- Human error, not malice, was the root cause of 26% of breaches in the same study.
- Detection works by comparing identity, device and data activity against each user's normal behavior, using signals from several tools rather than one.
- Microsoft Purview Insider Risk Management is not included in Microsoft 365 Business Premium or E3 by itself, and needs E5 or a Purview add-on.
Most security spending keeps attackers out, but firewalls, email filtering and multifactor authentication (MFA) do little against someone who already has a valid login. This guide explains what an insider threat is, the main types and warning signs, and how detection and prevention work in a Microsoft 365 environment. The stakes are high: IBM's 2025 Cost of a Data Breach Report found malicious insiders were the costliest attack vector it measured.
What Is an Insider Threat?
An insider threat is the risk that someone with authorized access to your systems, such as an employee, contractor or vendor, uses that access to harm the organization, either on purpose or by accident. The Cybersecurity and Infrastructure Security Agency (CISA) defines an insider as any person who has or had authorized access to, or knowledge of, an organization's people, facilities, information, equipment, networks or systems.
That covers more people than most teams expect. Current staff count, and so do former employees, especially if their accounts were never fully shut down. Contractors, vendors and your IT provider's administrators count too. Anyone you have given credentials, a laptop or a building badge is an insider.
What makes someone an insider is access, not where they sit. A stolen employee login belongs in this category. The attacker may be on the other side of the world, but every action they take looks like the employee doing their job.
Insider Threats vs External Threats
The core difference is where the threat starts: an insider begins inside your trust boundary, while an external attacker has to break in first.
The line blurs the moment an external attacker steals a working password. From then on, they operate as an insider. This is why perimeter tools rarely catch insider activity: a firewall has nothing to block when the login is real.
Types of Insider Threats
There are three main types of insider threat: malicious insiders who cause harm on purpose, negligent insiders who cause it through carelessness or mistakes, and compromised insiders whose accounts have been taken over by an attacker.
Malicious insiders act deliberately, usually for money or out of a grievance such as a demotion, missed promotion or dismissal. They know where the valuable data sits and how to reach it.
Negligent insiders don't intend harm. They send a file to the wrong person, ignore a patch prompt, or store sensitive files where too many people can open them. One CyberQuell investigation showed how misconfigured permissions exposed HR files in Microsoft 365 after a file migration, with no attacker involved. A newer version of the same mistake is pasting company data into unapproved AI tools. Verizon's 2026 Data Breach Investigations Report (DBIR) found this is now the third most common non-malicious insider action in its data loss prevention dataset, four times more common than a year earlier. The controls that limit these mistakes are covered in our guide to protecting sensitive data across Microsoft 365.
Compromised insiders are real employee accounts under an attacker's control, usually after a phishing email or a leaked password. The employee may have done nothing wrong, but every action on their account looks like theirs.
Contractors, Vendors and Collusion
Contractors and vendors are insiders too, and they often sit outside the HR processes that remove access when someone leaves. Verizon's 2026 DBIR found a third party was involved in 48% of breaches, up 60% on the previous year. That figure includes suppliers' software as well as people, but it shows how much risk now sits with partners. If you use a managed service provider, its admin accounts in your tenant are third-party access from your side.
Collusion is the other risk here: outside criminals recruit or pay insiders to hand over data. One recent case appears in the examples section below.
Common Insider Threat Indicators
The most reliable insider threat indicators are changes in how someone uses their access, especially when they show up alongside a change in that person's work situation.
Technical indicators:
- Downloading or copying far more files than usual, particularly during a notice period.
- Forwarding work files to a personal email address or uploading them to personal cloud storage.
- Opening systems or records that have nothing to do with the person's role.
- Trying to raise their own permissions, or turning off security software on their device.
- Pasting company data, such as source code or customer details, into unapproved AI tools.
- Signing in at unusual hours or from locations they have never used before.
Behavioral indicators:
- A resignation, or a dismissal that has been discussed but not yet carried out.
- A demotion, a restructure that removes responsibilities, or reduced system access.
- A performance improvement plan or a poor review.
- An open grievance with a manager or the company.
Microsoft builds these same employment events into Microsoft Purview Insider Risk Management, which can raise a person's risk score after events such as a resignation or a performance plan.
A single indicator is rarely proof. People download files and work late for ordinary reasons. What matters is a pattern, such as a resignation followed by a large download to a personal account. Our guide to what happens after a threat alert fires walks through how those signals get investigated.
Not sure who can reach your most sensitive files? CyberQuell's team can run a security assessment of who can reach your sensitive data in your Microsoft 365 environment and show you which permissions to tighten first.
How Insider Threat Detection Works
Insider threat detection works by learning what normal activity looks like for each user and their peers, then flagging behavior that breaks that pattern. Because insiders use real credentials, the question is never "is this login valid?" but "is this normal for this person?"
Detection draws on three layers of signal:
- Identity: who signed in, from where, at what time, and whether the sign-in looked risky.
- Endpoint: what happened on the device, such as USB copies, disabled security tools or new admin rights.
- Data: which files were opened, shared, downloaded or sent outside the company.
Each layer on its own produces noise. A single odd sign-in means little. An odd sign-in, followed by a mass download, followed by an upload to personal cloud storage, is a case worth investigating. Tying those events together is the job of a security information and event management (SIEM) platform. In a Microsoft environment that means Microsoft Sentinel SIEM monitoring. Sentinel's User and Entity Behavior Analytics (UEBA) feature builds a behavioral profile for each user, compares each person with the colleagues they work most closely with, and scores how unusual each activity is.
Why Human Review Still Matters
An anomaly is a question, not a verdict. In one CyberQuell investigation, a suspicious Microsoft 365 login that turned out to be network routing triggered location alerts, but log and device checks confirmed the real user on an approved device. The client avoided forcing account resets on someone who had done nothing wrong.
Getting this right pays off. IBM's 2025 Cost of a Data Breach Report found that organizations using security analytics or a SIEM reduced average breach costs by about USD 212,000.
Detecting Insider Threats in Microsoft 365
In Microsoft 365, insider threat detection is split across four tools, and which ones you can use depends on your license. Each tool covers a different part of the problem, so a gap in licensing becomes a gap in coverage.
Insider Risk Management is the only tool on the list built specifically for insider risk. It pulls in signals from across Microsoft 365, including alerts from Microsoft Defender for Endpoint for its security policy violation checks. That makes endpoint detection with Microsoft Defender part of any insider threat setup, not only malware defense.
What Business Premium Covers on Its Own
Microsoft 365 Business Premium, Microsoft's security-focused plan for organizations with up to 300 users, covers only part of this list. It includes DLP for email and files, but not Insider Risk Management. Its Entra ID P1 license also shows only limited ID Protection reports and can't run risk-based sign-in policies. Microsoft's Purview service description and Entra licensing guide show the two ways to close the gap: add the Purview Suite and Defender Suite for Business Premium, or move to Microsoft 365 E5.
Building an Insider Threat Program
An insider threat program combines five things: a written policy, least-privilege access, monitoring, a tiered response and training. None of it needs a dedicated team, but each part needs a named owner.
- Policy. Set out acceptable use, including which AI tools staff may use with company data, and state what is monitored and why.
- Least-privilege access and offboarding. Give people only the access their role needs, review it regularly, and put end dates on contractor accounts. When someone leaves, disable their accounts that day and check for scripts or scheduled jobs they created, especially if they held admin rights.
- Monitoring. Use the Microsoft 365 tools covered above, with a person reviewing the alerts every day. If nobody in-house has that time, 24/7 managed SOC monitoring and response can cover it.
- Tiered response. Match the response to the likely intent. Send a reminder notice for accidental policy breaches, investigate repeated patterns, and bring in HR and legal only where intent is likely. Our guide to building an incident response plan covers how to write these steps down.
- Training. Show staff what a mistake looks like in practice, such as oversharing a folder or pasting data into an unapproved AI tool. IBM's 2025 Cost of a Data Breach Report found employee training reduced average breach costs by about USD 192,000.
Monitoring Employees Without Breaking Trust
Insider monitoring works best when staff know it exists. Keep it proportionate, disclose it in your policy, and check it against local employment and privacy law before switching it on. Microsoft Purview Insider Risk Management pseudonymizes users by default, so analysts see the activity before they see a name. Microsoft also states that its insights should not be the only basis for action against an employee, so a full investigation comes first.
Real-World Insider Threat Examples and Statistics
Three documented cases show how each type of insider threat plays out in practice: one deliberate, one paid for by outsiders, and one caused by a mistake.
Malicious: sabotage after a demotion. A software developer at an Ohio-based company began sabotaging its systems after a 2018 restructure reduced his responsibilities and access. He planted code that crashed servers and a "kill switch" set to lock out all users if his account was ever disabled. When the company disabled it in September 2019, the kill switch fired and affected thousands of users. The U.S. Department of Justice reports he was convicted in March 2025 and sentenced to four years in prison.
Collusive: insiders paid by criminals. In a May 2025 SEC filing, Coinbase disclosed that a threat actor paid support contractors and employees outside the US to collect customer data from systems they could legitimately access. The company's own security monitoring had flagged the access without a business need in the months before. Coinbase estimated the cost at USD 180 million to 400 million.
Negligent: exposure with no attacker. In the CyberQuell HR case covered earlier, confidential pay documents surfaced in employee search results after a file migration. The cause was inherited permissions and old sharing links. Nobody broke in.
The numbers behind these cases:
- Malicious insider breaches cost an average of USD 4.92 million, the highest of any attack vector (IBM, 2025).
- They took 260 days to identify and contain, against a 241-day average (IBM, 2025).
- A third party was involved in 48% of breaches (Verizon DBIR, 2026).
In each case, the early signals were there for anyone watching. That is the argument for continuous threat monitoring rather than periodic reviews.
Insider threat detection comes down to two questions: do you have the Microsoft licenses to see the signals, and does someone review the alerts every day? If either answer is no, 24/7 managed SOC monitoring and response from CyberQuell covers both.
Final Thoughts
Insider threats rarely look like attacks, because every action comes from a real account. Stopping them depends on two things: the Microsoft licences that let you see identity, device and data activity, and a person who reviews those alerts every day. Most 50 to 500 person businesses have one of the two, not both.
Book a call with CyberQuell to check what your current Microsoft licences cover for insider threat detection and where the gaps are. For round-the-clock alert review, see our 24/7 managed SOC monitoring and response service.

%20for%20Microsoft%20365%20(1).png)
.png)
.png)