Score insider risk from access breadth, privilege, monitoring, behavioural indicators, departure status and data value.
Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual. The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.
Insider Threat Risk
risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift.
risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift. Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual.
The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.
This calculator takes 8 inputs: Systems the individual can reach, Privilege level, Sensitivity of reachable data, Monitoring of that activity, Behavioural indicators observed, Employment status, Egress and DLP controls, Records reachable. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
No, and it should not be used that way. It is designed to score access paths and control gaps, which is why the highest-weight factors are monitoring and DLP. Use it to decide where to instrument, and handle any individual concern through HR and legal process.
Because the observed pattern in insider data-theft cases is bulk copying in the final weeks of employment, usually of material the person legitimately used. It is a control trigger — tighten bulk export and review access — not an accusation.