Insider Threat Risk Calculator
Score insider risk from access breadth, privilege, monitoring, behavioural indicators, departure status and data value.
Inputs
Off-hours bulk access, policy disputes, unusual copying, disciplinary events
Insider Risk Band
Critical — act now
Insider Risk Score
9.07/ 10
Opportunity
6.00/ 10
Impact
9.00/ 10
Motivation Multiplier
1.68×
Highest-Value Control
Turn on activity logging and review for this access — you currently cannot tell what was taken
Step by step
Values used
Systems the individual can reach = A whole business unit — 6; Privilege level = System or database administrator — 8; Sensitivity of reachable data = Regulated personal data — 8; Monitoring of that activity = Logged, never reviewed — 5; Behavioural indicators observed = 2 indicators; Employment status = Serving notice or resigned — 1.5×; Egress and DLP controls = Monitor-only DLP — 5; Records reachable = 500,000 records
Insider Threat Risk
risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift.
Insider Risk Band
= Critical — act now
Insider Risk Score
= 9.07 / 10
Opportunity
= 6.00 / 10
Impact
= 9.00 / 10
Motivation Multiplier
= 1.68 ×
Highest-Value Control
= Turn on activity logging and review for this access — you currently cannot tell what was taken
How it works
Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual. The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.
Formula
Insider Threat Risk
risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift.
- opportunity
- How much the person can reach and how unobserved they are
- impact
- What the reachable data is worth if taken
- motivationMultiplier
- Employment status scaled by observed behavioural indicators
Frequently Asked Questions
How is Insider Threat Risk calculated?
risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift. Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual.
Why does Insider Threat Risk matter?
The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.
What values do I need to enter?
This calculator takes 8 inputs: Systems the individual can reach, Privilege level, Sensitivity of reachable data, Monitoring of that activity, Behavioural indicators observed, Employment status, Egress and DLP controls, Records reachable. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is this a way to profile employees?
No, and it should not be used that way. It is designed to score access paths and control gaps, which is why the highest-weight factors are monitoring and DLP. Use it to decide where to instrument, and handle any individual concern through HR and legal process.
Why does serving notice raise the score?
Because the observed pattern in insider data-theft cases is bulk copying in the final weeks of employment, usually of material the person legitimately used. It is a control trigger — tighten bulk export and review access — not an accusation.
You might also need
- Data Loss Prevention Coverage CalculatorCommonly used together
- Phishing Risk CalculatorCommonly used together
- Zero Trust Maturity CalculatorCommonly used together
- PII Exposure CalculatorCommonly used together
- Security Awareness Coverage CalculatorCommonly used together
- Synthetic Identity Risk CalculatorCommonly used together