Skip to content
Calcrivo

Insider Threat Risk Calculator

Score insider risk from access breadth, privilege, monitoring, behavioural indicators, departure status and data value.

Inputs

indicators

Off-hours bulk access, policy disputes, unusual copying, disciplinary events

records

Insider Risk Band

Critical — act now

Insider Risk Score

9.07/ 10

Opportunity

6.00/ 10

Impact

9.00/ 10

Motivation Multiplier

1.68×

Highest-Value Control

Turn on activity logging and review for this access — you currently cannot tell what was taken

Step by step

  1. Values used

    Systems the individual can reach = A whole business unit — 6; Privilege level = System or database administrator — 8; Sensitivity of reachable data = Regulated personal data — 8; Monitoring of that activity = Logged, never reviewed — 5; Behavioural indicators observed = 2 indicators; Employment status = Serving notice or resigned — 1.5×; Egress and DLP controls = Monitor-only DLP — 5; Records reachable = 500,000 records

  2. Insider Threat Risk

    risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift.

  3. Insider Risk Band

    = Critical — act now

  4. Insider Risk Score

    = 9.07 / 10

  5. Opportunity

    = 6.00 / 10

  6. Impact

    = 9.00 / 10

  7. Motivation Multiplier

    = 1.68 ×

  8. Highest-Value Control

    = Turn on activity logging and review for this access — you currently cannot tell what was taken

How it works

Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual. The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.

Formula

Insider Threat Risk

risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift.

opportunity
How much the person can reach and how unobserved they are
impact
What the reachable data is worth if taken
motivationMultiplier
Employment status scaled by observed behavioural indicators

Frequently Asked Questions

How is Insider Threat Risk calculated?

risk = (opportunity × impact ÷ 10) × motivationMultiplier, where opportunity = mean(access breadth, privilege, monitoring gap, DLP gap) and impact = data sensitivity plus a record-volume uplift. Insider risk is opportunity multiplied by impact, adjusted by motivation. Opportunity deliberately combines what the person can reach with how poorly it is observed, because unmonitored access is what turns capability into unattributable loss. Motivation uses only objective, defensible signals — employment status and observed behavioural indicators — and is capped at 3×. This is a prioritisation estimate for where to apply monitoring, not a judgement about any individual.

Why does Insider Threat Risk matter?

The single biggest insider variable is not privilege, it is whether anyone would notice: unmonitored administrative access to a customer database is a loss you discover from a news article.

What values do I need to enter?

This calculator takes 8 inputs: Systems the individual can reach, Privilege level, Sensitivity of reachable data, Monitoring of that activity, Behavioural indicators observed, Employment status, Egress and DLP controls, Records reachable. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is this a way to profile employees?

No, and it should not be used that way. It is designed to score access paths and control gaps, which is why the highest-weight factors are monitoring and DLP. Use it to decide where to instrument, and handle any individual concern through HR and legal process.

Why does serving notice raise the score?

Because the observed pattern in insider data-theft cases is bulk copying in the final weeks of employment, usually of material the person legitimately used. It is a control trigger — tighten bulk export and review access — not an accusation.

You might also need