00:00:02 The IIA
The Institute of Internal Auditors presents All Things Internal Audit.
00:00:05 The IIA
In this episode, Sanjay Vadlamani talks with Yvette Adams about how insider threats extend beyond malicious employees.
00:00:13 The IIA
They discuss negligent, malicious, and compromised insiders, along with ways AI, remote work, cloud applications, and expanding access have increased organizational risk.
00:00:25 The IIA
The conversation also covers monitoring, employee privacy, access management, and the importance of connecting information across organizational silos before a threat becomes an incident.
00:00:39 Sanjay Vadlamani
Hi, Yvette.
00:00:39 Sanjay Vadlamani
Thanks so much for joining.
00:00:41 Sanjay Vadlamani
Looking forward to this discussion on insider threat management.
00:00:45 Yvette Adams
Pleasure to be here, Sanjay.
00:00:46 Yvette Adams
I've been looking forward to this.
00:00:48 Sanjay Vadlamani
When people hear the term insider threat,
00:00:51 Sanjay Vadlamani
They often think of a malicious employee stealing data, but in practice, what types of insider threats are organizations dealing with from your perspective most frequently today?
00:01:04 Yvette Adams
I do think it's common that people will usually picture a disgruntled employee who is intentionally stealing data before walking out the door.
00:01:12 Yvette Adams
And while that does happen, while it is something that does occur, it's actually not the most common.
00:01:18 Yvette Adams
The most common would be the negligent insider.
00:01:21 Yvette Adams
There are three classes of insiders.
00:01:24 Yvette Adams
The first is the negligent insider, which is the most common, as I said.
00:01:28 Yvette Adams
Then you've got the malicious insider, and then you've got the compromised insider.
00:01:32 Yvette Adams
So to give you some definition around that, a negligent insider is somebody who accidentally emails sensitive information to the wrong person or they accidentally misconfigure a cloud environment or they upload confidential information to an unauthorized AI tool.
00:01:50 Yvette Adams
So it's not intentional, it's accidental.
00:01:54 Yvette Adams
The malicious insider, which is where most of our brains will go,
00:01:59 Yvette Adams
is the individual who intentionally steals information.
00:02:02 Yvette Adams
They're out there to commit fraud.
00:02:04 Yvette Adams
They sabotage systems.
00:02:06 Yvette Adams
They misuse the access that they've been granted.
00:02:09 Yvette Adams
And then the third is the compromised insider.
00:02:12 Yvette Adams
So that's when an external attacker gains access through stolen credentials and they essentially operate within the environment using a legitimate employee's identity.
00:02:23 Sanjay Vadlamani
And so just following up on the compromised, that would be a great example would be within cyber of like a phishing attack.
00:02:30 Yvette Adams
That's right.
00:02:31 Yvette Adams
They've gained access through phishing, getting credentials.
00:02:34 Yvette Adams
Sometimes they even call it spear phishing because they've got some information about you and they'll ask you pointed questions that will get you to answer things that you wouldn't normally respond.
00:02:43 Yvette Adams
And now they have information where they can access information using additional information that it wouldn't normally have.
00:02:50 Sanjay Vadlamani
It's so funny you say that at payjoy.
00:02:53 Sanjay Vadlamani
there was a audio of our CEO having his voice sent to people in AP saying this invoice is 90 days past due and it should be paid or 180.
00:03:06 Sanjay Vadlamani
It was something that was really big and the person could have freaked out, but thank God didn't.
00:03:12 Sanjay Vadlamani
The sophistication is going
00:03:14 Sanjay Vadlamani
areas that I had never imagined.
00:03:16 Sanjay Vadlamani
So I totally agree.
00:03:18 Yvette Adams
Absolutely.
00:03:20 Sanjay Vadlamani
From your perspective, why are insider threats becoming a bigger concern for organizations?
00:03:27 Sanjay Vadlamani
And then what changes have you specifically seen in the workplace in your professional career?
00:03:36 Sanjay Vadlamani
And as technology has evolved, how is this contributing to the risk?
00:03:42 Yvette Adams
The first thing that has elevated it, you just hit on, AI.
00:03:48 Yvette Adams
AI has introduced new risk paths.
00:03:50 Yvette Adams
So employees can, first of all, unintentionally expose information or proprietary data to artificial intelligence that's not protected.
00:04:00 Yvette Adams
And artificial intelligence can be used for voice mimicking and that kind of thing.
00:04:06 Yvette Adams
So that has absolutely changed it.
00:04:08 Yvette Adams
We also have
00:04:10 Yvette Adams
a bigger attack surface than we have had historically.
00:04:13 Yvette Adams
You've got hybrid and remote workers who have expanded their organizational boundaries in which they work.
00:04:21 Yvette Adams
So people are no longer accessing data within the confines of a
00:04:26 Yvette Adams
building that they work in, corporate offices on company-owned devices, they might be accessing information from homes, airports, personal devices, cloud environments.
00:04:37 Yvette Adams
So that creates an additional layer of challenge.
00:04:41 Yvette Adams
And then you have, like I said, the enormous amount of cloud applications and collaboration tools.
00:04:48 Yvette Adams
So
00:04:49 Yvette Adams
Information will move much more freely now, which is great for productivity.
00:04:54 Yvette Adams
However, it also makes data exfiltration easier than ever.
00:04:58 Yvette Adams
So I would say leading organizations manage this threat alongside how the threat has changed.
00:05:08 Yvette Adams
So historically, you would have seen
00:05:11 Yvette Adams
programs that are heavily security led and reactive.
00:05:15 Yvette Adams
Whereas today, I would say mature organizations are taking a multidisciplinary approach and coordinating insider risk programs.
00:05:26 Yvette Adams
So you're bringing together programs in areas such as security, HR, legal,
00:05:34 Yvette Adams
compliance, privacy, physical security, risk management to handle it from a lot of different angles.
00:05:42 Yvette Adams
They'll broaden the scope from just malicious intent because as we said, it's the negligent insider that is more common.
00:05:52 Yvette Adams
And instead of saying, you know, who's trying to steal our data, they'll say who has elevated risk conditions and access that could lead to loss.
00:06:01 Yvette Adams
So this might include people with excessive permissions.
00:06:05 Yvette Adams
Do you see unusual data movement?
00:06:08 Yvette Adams
Are employees stressed?
00:06:09 Yvette Adams
Are there contracts or contractors that are nearing offboarding?
00:06:14 Yvette Adams
Could we have compromised credentials or policy exceptions?
00:06:17 Yvette Adams
I would say another shift is that people are starting to use more behavior analytics.
00:06:24 Yvette Adams
So organizations are looking for unusual patterns.
00:06:27 Yvette Adams
That could include large downloads, abnormal access times to information, attempts to access systems that they don't have a responsibility, their job wouldn't require them to access that information.
00:06:40 Yvette Adams
And then you have a system that is monitoring for these things and then you layer on the human person to review those signals and see if there's areas of concern where maybe they should dive deeper.
00:06:53 The IIA
Yvette just described insider risk as a coordination problem.
00:06:57 The IIA
Security, HR, legal, privacy, and audit reading the same signals and judging together what they mean.
00:07:04 The IIA
That capability sits across a function, not one person.
00:07:08 The IIA
Building that judgment across a whole team is a leadership job.
00:07:12 The IIA
IA membership helps you build that capability across your team.
00:07:16 The IIA
with trusted standards, practical expertise, and a global community helping your people stay ready as AI and expanding access reshape the work.
00:07:25 The IIA
Explore everything now included with IA membership at theia.org.
00:07:29 The IIA
Lead what's next.
00:07:31 The IIA
Now back to Sanjay and Yvette on monitoring, privacy, and where the line sits.
00:07:39 Sanjay Vadlamani
I agree with everything you said.
00:07:43 Sanjay Vadlamani
I'll just ask two questions.
00:07:45 Sanjay Vadlamani
One, do you think in everything you said and with AI and elevated access roles, compromised people, behavioral tendencies with workers?
00:07:57 Sanjay Vadlamani
that a tools like maybe a Netscope should be used.
00:08:02 Sanjay Vadlamani
And the second part of the question is, or any kind of third-party tool.
00:08:06 Sanjay Vadlamani
And the second part of the question to me is this is something that I'm always worried about is, yes, I understand companies will be looking at monitoring your downloads for exactly like you said, but it could be a slippery slope, meaning that they then go to keyboard.
00:08:27 Sanjay Vadlamani
type of, the big brother, I totally am on board.
00:08:32 Sanjay Vadlamani
I follow and I am on, using a USB stick, the OpenAI guys from Apple, right, downloaded, they said a TB of data to exactly like you said, it was a cloud-based application.
00:08:48 Sanjay Vadlamani
The guy left, he realized his credentials were still active, swapped in his
00:08:54 Sanjay Vadlamani
his USB, voila, he has it, goes to OpenAI and says, voila, here's our starting point for our product.
00:09:02 Sanjay Vadlamani
But I don't know what the solution is.
00:09:04 Sanjay Vadlamani
What's your thoughts?
00:09:05 Yvette Adams
So on your first question, tools.
00:09:09 Yvette Adams
I would say absolutely consider what tools you can use based on the complexity of your organization, the type of information you have.
00:09:16 Yvette Adams
you should absolutely be investigating what type of tools would work for you.
00:09:20 Yvette Adams
I think that it's a fair question to say, are we invading people's privacy?
00:09:24 Yvette Adams
And as a company, you have to determine where is that line?
00:09:28 Yvette Adams
I think it could vary depending on what company you have and what kind of information you have access to and how proprietary is it, how protected is it, that kind of thing.
00:09:40 Yvette Adams
But then also consider if you don't want to risk
00:09:45 Yvette Adams
not protecting information at the risk of offending somebody to say, we're employing you and we need to make sure that the data is protected and sorry, we have to do this sort of thing.
00:09:58 Yvette Adams
What I have seen is that companies will give a notice to their employees upon onboarding and then also regularly, whether that's annually, to
00:10:10 Yvette Adams
remind employees, this is what you can do with data, this is how it should be stored, and they're very transparent about how they would be monitoring appropriate use.
00:10:21 Yvette Adams
So it doesn't come as a surprise to employees that the way that they're using data is being monitored.
00:10:29 Yvette Adams
That could control the risk of people
00:10:32 Yvette Adams
wanting to download and having that pull to download data that they shouldn't be accessing anyway.
00:10:38 Sanjay Vadlamani
You summed that up, I think, perfectly.
00:10:41 Sanjay Vadlamani
And I'll say this, is from the enterprise risk management, which has the view of the macro view of the company.
00:10:48 Sanjay Vadlamani
Your response was exactly that.
00:10:51 Sanjay Vadlamani
I think what you just said could apply to, from your perspective, a bank, where I am, a fintech, insurance, to any kind of company.
00:11:02 Sanjay Vadlamani
company, it comes down to communication and alignment and being transparent.
00:11:08 Sanjay Vadlamani
You hit on everything.
00:11:10 Sanjay Vadlamani
So I really, really, really appreciate that.
00:11:12 Sanjay Vadlamani
It resonates with me.
00:11:14 Sanjay Vadlamani
Going on, just following up on this, organizations, I think, often have this focus on external attackers.
00:11:26 Sanjay Vadlamani
And we've talked about there's other types, but we're talking about insider threats.
00:11:33 Sanjay Vadlamani
And I think this is kind of not as a big focus, but in your perspective, in your experience, how do you think leading organizations, what would their approach be regarding insider threat management?
00:11:48 Sanjay Vadlamani
And have you seen a change in your experience from when you started to now on how companies are approaching this?
00:11:56 Yvette Adams
So I would say the best insider threat indicators don't necessarily attempt to predict bad people.
00:12:04 Yvette Adams
They look to identify areas of concentration of trust, access, and behavior that increases the likelihood of loss and what the impact would be of that insider threat.
00:12:17 Yvette Adams
So an organization should consider
00:12:20 Yvette Adams
indicators and monitoring things that would measure things like exposure, behavior, control effectiveness, outcome.
00:12:31 Yvette Adams
So some examples that go along with that, exposure.
00:12:34 Yvette Adams
Things that you could monitor would be the percent of users with privileged access, the number of dormant accounts you might have, the number of emergency access grants that are given.
00:12:47 Yvette Adams
In terms of behavior, you could monitor unusual large downloads that isn't commensurate with the person's job.
00:12:56 Yvette Adams
Access outside of normal work hours.
00:13:00 Yvette Adams
Repeated access failures
00:13:02 Yvette Adams
when somebody is trying to access information.
00:13:05 Yvette Adams
The use of unauthorized storage devices, like you said, a USB stick, or attempts to bypass any security controls.
00:13:11 Yvette Adams
So again, those are things that you can monitor behavior-wise.
00:13:14 Yvette Adams
In terms of control effectiveness, how many times are we overriding data loss prevention policies?
00:13:21 Yvette Adams
Or what is the meantime to deprovision access to information once somebody leaves the company?
00:13:28 Yvette Adams
How many exceptions do we have?
00:13:30 Yvette Adams
In terms of outcomes,
00:13:32 Yvette Adams
How many confirmed insider incidents do we have?
00:13:35 Yvette Adams
How many near misses?
00:13:37 Yvette Adams
What kind of near misses?
00:13:38 Yvette Adams
What are some of the data loss events that have occurred?
00:13:41 Yvette Adams
Are there repeat policy violations?
00:13:44 Yvette Adams
Those are some of the things that you can monitor that would indicate whether you have a problem.
00:13:48 Yvette Adams
Does that answer your question?
00:13:50 Sanjay Vadlamani
It does, and it sparks so much from me.
00:13:53 Sanjay Vadlamani
One, I think of it like a house.
00:13:55 Sanjay Vadlamani
And I think of the way that you just framed this was
00:13:59 Sanjay Vadlamani
you have the policy that governs this whole, the do's and don'ts, right?
00:14:04 Sanjay Vadlamani
More like a golf course, like a fairway.
00:14:07 Sanjay Vadlamani
There's, your fairway and out of bounds.
00:14:10 Sanjay Vadlamani
But more importantly, very succinctly stated, you know, it's access, the types of access, privileged access, emergency, and then the de-provisioning.
00:14:22 Sanjay Vadlamani
That is the door.
00:14:23 Sanjay Vadlamani
the door, if you don't, if you're able to then have kind of like good, to your point, controls the policy on the door itself to the application to whatever the data, right, to then whatever tool mechanism you have for your user access governance, your monitoring should, and your exceptions that you highlighted should be manageable.
00:14:47 Sanjay Vadlamani
It should be expected.
00:14:49 Sanjay Vadlamani
You shouldn't have all of this.
00:14:50 Sanjay Vadlamani
So I simply love it.
00:14:52 Sanjay Vadlamani
We have Deloitte as our external auditor.
00:14:55 Sanjay Vadlamani
And I feel like you were in the room when the Deloitte partners gave us their feedback of what they said to us, hey, Pajoy, when you're planning 12, 24 months out, 6, 12, 24 months out, these are the kind of the things to plan for.
00:15:14 Sanjay Vadlamani
And you kind of just spelled it out again for us.
00:15:16 Sanjay Vadlamani
So thank you.
00:15:17 Yvette Adams
And we can talk about these things generically.
00:15:20 Yvette Adams
I actually read an article recently that talked about some of the things that I just hit on here.
00:15:26 Yvette Adams
It was in Info Security Magazine.
00:15:29 Yvette Adams
They published an article and it hit close to home because I'm from Utah.
00:15:33 Yvette Adams
But Info Security Magazine had an article that was published last September 2025.
00:15:39 Yvette Adams
They said that according to breach notifications and subsequent reporting, FinWise Bank, which is a community bank in Utah,
00:15:47 Yvette Adams
partners with FinTech companies identified a data security incident that involved a former employee who accessed FinWise data after their employment had ended.
00:15:58 Yvette Adams
So the exact scenario that you had talked about.
00:16:01 Yvette Adams
Some of the affected data belonged to American First Finance, which also partners with FinWise to offer installment loan production.
00:16:10 Yvette Adams
With this incident, about 689,000 customers were potentially affected.
00:16:17 Yvette Adams
So the public reports indicate that exposed information included things like names, dates of birth, social security numbers, financial information such as account numbers, that kind of thing.
00:16:30 Yvette Adams
And the reason I think where this hit so poignantly for this topic is there's three major issues of note that we've talked about and the alleged unauthorized access.
00:16:41 Yvette Adams
One, it was conducted by a former employee.
00:16:44 Yvette Adams
So that's exactly an insider threat scenario, right?
00:16:47 Yvette Adams
It apparently occurred after termination.
00:16:51 Yvette Adams
So that raises questions about offboarding process and how to cancel access controls.
00:16:58 Yvette Adams
And then the third,
00:17:00 Yvette Adams
They learned that it went.
00:17:02 Yvette Adams
undetected for more than a year.
00:17:04 Yvette Adams
So that highlights the potential monitoring and data loss detection weaknesses that existed there.
00:17:11 Yvette Adams
So not only did they have to disclose to the 689,000 affected people, but after the public disclosure, then FinWise and American First Finance were named in multiple class action lawsuits.
00:17:24 Yvette Adams
Plaintiffs alleged, among other claims, that customer information was not adequately protected and the organization failed to safeguard sensitive data.
00:17:33 Yvette Adams
This is a real issue with real potential loss that could occur.
00:17:38 Sanjay Vadlamani
Just think about that, right?
00:17:39 Sanjay Vadlamani
One year.
00:17:41 Sanjay Vadlamani
And today, we all know of different tools that can do a point in time monitoring.
00:17:48 Sanjay Vadlamani
You can build.
00:17:49 Sanjay Vadlamani
I personally have built my own, and it's janky.
00:17:53 Sanjay Vadlamani
It gets the job done.
00:17:54 Sanjay Vadlamani
It's not that fantastic.
00:17:56 Sanjay Vadlamani
But you're exactly right.
00:17:57 Sanjay Vadlamani
There's 2 pieces.
00:17:58 Sanjay Vadlamani
Just the monitoring of the in-truck quarter
00:18:02 Sanjay Vadlamani
And then the last piece is when the employee leaves.
00:18:06 Sanjay Vadlamani
sure, you take the badge and all that stuff, and then checking the box, just checking the boxes and saying all the systems, there's no closed the loop of validation to say, yes, all the systems for this person, access has been revoked.
00:18:21 Sanjay Vadlamani
does it really require the OCC and the Federal Reserve to come in and say, hey guys, really?
00:18:27 Sanjay Vadlamani
And then you have fines to your point, and then you have other things, and then they're in the news, right?
00:18:33 Sanjay Vadlamani
And then public sentiment.
00:18:34 Yvette Adams
And then the lawsuits that come.
00:18:37 Sanjay Vadlamani
Yes.
00:18:38 Sanjay Vadlamani
Exactly, from something that is so, it's not something that's new.
00:18:42 Sanjay Vadlamani
I'm just floored.
00:18:43 Sanjay Vadlamani
I can't believe that companies still trip on themselves constantly over this.
00:18:48 Sanjay Vadlamani
So thank you.
00:18:49 Yvette Adams
Yeah, and that's why when I
00:18:50 Yvette Adams
talked about that interdisciplinary approach where you involve more than just people monitoring data.
00:18:57 Yvette Adams
You have to layer on top of HR, the other areas, compliance that would need to have awareness of situations that could cause increased risk for this type of thing.
00:19:11 Yvette Adams
You hit on the malicious insider where, and this is a common one,
00:19:16 Yvette Adams
somebody's departing the company that they work for.
00:19:19 Yvette Adams
And this is one of the most common insider threat scenarios where you have somebody that's preparing to join a competitor.
00:19:27 Yvette Adams
So imagine that the employee gives their notice and they submit their resignation.
00:19:32 Yvette Adams
So let's say they gave their two weeks notice and they were allowed to continue working on their device with access to information.
00:19:41 Yvette Adams
So they begin downloading customer lists, they look at pricing information, they pull strategic plans, they do some proprietary research.
00:19:51 Yvette Adams
So in organizations that
00:19:54 Yvette Adams
usually detect this threat, it's that coordinated effort that will be most effective.
00:20:01 Yvette Adams
You have HR who notifies the insider risk team about the resignation.
00:20:05 Yvette Adams
You've got system monitoring who identifies unusual downloads.
00:20:10 Yvette Adams
And those two data points intersect and are reviewed together so that the company can intervene before the information actually leaves the environment.
00:20:20 Yvette Adams
And organizations that
00:20:22 Yvette Adams
miss it, it's because some of these things might exist, but they're siloed.
00:20:28 Yvette Adams
And HR might know an employee is leaving, security might see unusual activity, but neither side realizes there's a connection until it's too late.
00:20:38 Yvette Adams
That's why that interdisciplinary approach is so important.
00:20:42 Sanjay Vadlamani
I think that example just made me think of what we talked about previously, what you highlighted, which was
00:20:49 Sanjay Vadlamani
the behavioral or technical, right?
00:20:53 Sanjay Vadlamani
And from what you just said, if you're a company and that exactly happened, would you say the indicator, like the red flag would be the behavioral of the person or would it be the after the fact of, oh, the person did this and therefore it's the technical?
00:21:11 Yvette Adams
Yeah, so you have the preventive where you actually
00:21:17 Yvette Adams
know the employee has given notice.
00:21:19 Yvette Adams
So your preventive activity would be, and you could still be transparent to say, we appreciate the time that you've given to the company.
00:21:29 Yvette Adams
We realize that there's gonna be some offboarding.
00:21:31 Yvette Adams
Please be reminded at this time we'll be monitoring your activity a little bit more closely to make sure that no proprietary information is leaving the company.
00:21:38 Yvette Adams
So you can be transparent, right?
00:21:40 Yvette Adams
So I would say that is your point where you're preventing.
00:21:44 Yvette Adams
you're preventing the control, the action.
00:21:47 Yvette Adams
Then you've got the detective where you start to see the downloading patterns.
00:21:52 Yvette Adams
Now, ideally, if you've got someone, you've got, you see the downloading patterns, you've got work group, somebody that looks for these things that you have people who work together, who coordinate with each other.
00:22:05 Yvette Adams
I'm seeing this on this employee.
00:22:07 Yvette Adams
Like you've got controls in place that actually notify the people monitoring the data to detect
00:22:14 Yvette Adams
that something is happening so that they know who they're monitoring and what they're monitoring for to circle back with HR.
00:22:21 Yvette Adams
Now, again, it could be very innocent.
00:22:24 Yvette Adams
So you just do what you normally do.
00:22:25 Yvette Adams
You have an interview, don't even have to call it an interview to make it sound official and scary.
00:22:30 Yvette Adams
But you have a conversation to say, hey, this is what we noted.
00:22:35 Yvette Adams
Don't say, is there an explanation for this?
00:22:36 Yvette Adams
That sounds like you're interrogating.
00:22:38 Yvette Adams
But hey, we've noticed this activity.
00:22:42 Yvette Adams
Can you describe what it is that is going on here?
00:22:45 Yvette Adams
Can you give me a little bit more information about that?
00:22:48 Sanjay Vadlamani
So how do you think organizations actually balance this monitoring and surveillance of employees and still being able to maintain trust and the employee's privacy while they're trying to
00:23:06 Sanjay Vadlamani
monitor insider threats and kind of make certain that there's no, not no blind spots, but most of the blinds, right?
00:23:13 Sanjay Vadlamani
Okay, you got it.
00:23:13 Sanjay Vadlamani
Absolutely.
00:23:14 Yvette Adams
I would say most mature organizations have five things.
00:23:19 Yvette Adams
First, they have clear governance with defined ownership.
00:23:23 Yvette Adams
Second, as previously discussed, they have a multidisciplinary insider risk team that might involve HR compliance.
00:23:33 Yvette Adams
legal, security, risk management.
00:23:35 Yvette Adams
And then they have the capability to monitor for unusual behavior.
00:23:41 Yvette Adams
And 4th, they have strong identity and access management practices where people only have access to the amount of information that they need in order to do their job and not more.
00:23:53 Yvette Adams
And then they have formal processes around onboarding employees,
00:24:00 Yvette Adams
transferring employees from one department to another because their information needs might change, and then certainly departures.
00:24:09 Yvette Adams
What I think is often missed is this coordination, that you have all the individual controls, but they don't have the mechanism to bring the information together to identify the emerging risks.
00:24:22 Yvette Adams
So that's why I think that in a perfect world, you would have a multidisciplinary team
00:24:28 Yvette Adams
that comes together, whether it be regularly or they know their partners that are part of this multidisciplinary insider risk team that has a way to communicate on the fly, ongoing, real time, that kind of thing.
00:24:43 Sanjay Vadlamani
So kind of just following up on that, this interdisciplinary concept of a team,
00:24:50 Sanjay Vadlamani
I totally agree.
00:24:51 Sanjay Vadlamani
But if we want to have a quick win for a company, and I agree, creating a group and everyone's time is valuable, everyone's schedule is packed.
00:25:03 Sanjay Vadlamani
Do you think it's possible to add to a, maybe if there's a risk committee, right?
00:25:10 Sanjay Vadlamani
And adding this topic to making certain it's a standing topic, insider threats to your point, whatever, you know, if it's data loss,
00:25:20 Sanjay Vadlamani
privileged roles, emergency roles, whatever the key indicators that we've talked about, you've highlighted are mentioned, maybe that could be something.
00:25:30 Yvette Adams
Absolutely.
00:25:31 Yvette Adams
I think that a more real-time working group situation is more effective than a committee.
00:25:37 Yvette Adams
However, your organization complexity, structure, size, information that one has access to, it might not make sense to have that kind of
00:25:49 Yvette Adams
structure where you can come together quickly.
00:25:52 Yvette Adams
And then a committee certainly would work.
00:25:55 Yvette Adams
It depends on how often that committee comes together in order to talk about things.
00:25:59 Yvette Adams
But even just having this on the front of people's minds to talk about and to learn from and to monitor and discuss solutions and preventions goes miles to start towards that path to maturity.
00:26:14 Yvette Adams
When you think about the insider threat life cycle, that includes
00:26:20 Yvette Adams
that element of learning, which I absolutely think that some element of coming together and talking about the risks, maybe events that have happened, the way the company has responded, can talk about it in a committee scenario where you discuss learning and how we can improve our process going forward.
00:26:41 Sanjay Vadlamani
Have you ever dealt with an insider threat successfully?
00:26:46 Sanjay Vadlamani
were able to not prevent it, but you had a process in place that you were able to detect it.
00:26:53 Yvette Adams
I would say I've seen elements of this occur successfully.
00:26:57 Yvette Adams
I'm going to share with you the most common public case that is available and actually has to do with Tesla.
00:27:03 Yvette Adams
It's an oldie but goodie.
00:27:05 Yvette Adams
It happened back in 2018.
00:27:08 Yvette Adams
A Tesla employee reportedly became disgruntled after they didn't receive a promotion and they used
00:27:16 Yvette Adams
their unauthorized access to make unauthorized changes to manufacturing system code and export company data.
00:27:25 Yvette Adams
So what makes this case interesting isn't that the employee attempted the activity because we've talked about that can happen.
00:27:32 Yvette Adams
It's that Tesla detected it relatively quickly through their monitoring investigation.
00:27:39 Yvette Adams
And then according to Elon Musk,
00:27:41 Yvette Adams
At the time, the company identified the individual, investigated the activity, and contained the threat before it could become a much larger event.
00:27:50 Yvette Adams
So the lesson for auditors is that trusted access doesn't eliminate the risk.
00:27:56 Yvette Adams
What mattered is that Tesla had visibility into the user's activity.
00:28:01 Yvette Adams
They investigated those anomalies.
00:28:03 Yvette Adams
They responded quickly once the warning signs appeared.
00:28:07 Yvette Adams
So the Tesla case reminds us that insider threat programs
00:28:11 Yvette Adams
aren't about distrusting employees.
00:28:14 Yvette Adams
They're about recognizing that even highly trusted employees can have moments where personal circumstances, grievances, opportunities create risk.
00:28:23 Yvette Adams
So that comes back to the fraud triangle.
00:28:26 Yvette Adams
Organizations that perform best are the ones that can detect the unusual behavior early and intervene quickly.
00:28:34 Sanjay Vadlamani
I like how you brought in the fraud triangle.
00:28:37 Sanjay Vadlamani
That's important.
00:28:38 Sanjay Vadlamani
And I do recall that Tesla headline from back in 2018.
00:28:43 Sanjay Vadlamani
I forgot that it was a disgruntled and didn't get the promotion, but you're exactly right.
00:28:47 Sanjay Vadlamani
It can happen to little things can spark of someone who is otherwise right and do things that you wouldn't have expected.
00:28:55 Yvette Adams
Exactly.
00:28:55 Sanjay Vadlamani
You're right.
00:28:56 Sanjay Vadlamani
You're spot on.
00:28:57 Yvette Adams
So when you think about it, let's go full circle with the threat life cycle.
00:29:02 Yvette Adams
You have
00:29:04 Yvette Adams
conditions that might increase risk.
00:29:07 Yvette Adams
So in this case, it was a disgruntled employee.
00:29:10 Yvette Adams
In another case that we talked about, it was somebody departing the company.
00:29:15 Yvette Adams
That leads to a behavior, which then leads to an event that happens, which then could potentially lead to an impact.
00:29:23 Yvette Adams
Is it an impact that is negative?
00:29:27 Yvette Adams
Did it occur or was it a near miss?
00:29:30 Yvette Adams
That then leads to how is the company going to respond?
00:29:34 Yvette Adams
Do they have an open risk in the system that needs to be addressed?
00:29:38 Yvette Adams
Do they need to put in another control, something else that they're monitoring?
00:29:43 Yvette Adams
And then additional learning.
00:29:45 Yvette Adams
What can we learn from this?
00:29:46 Yvette Adams
How do we need to change our processes?
00:29:49 Sanjay Vadlamani
I think when you mentioned impact, for public companies, you have reputational risk and then the public market.
00:29:59 Sanjay Vadlamani
For any company, you have your customer risk, supplier risk.
00:30:05 Sanjay Vadlamani
So yeah, it becomes real in a hurry.
00:30:08 Sanjay Vadlamani
Is there anything else that you may wanna just highlight here?
00:30:12 Yvette Adams
I would say that the most common assumption that people make when it comes to insiders is that we trust our people.
00:30:20 Sanjay Vadlamani
That's right.
00:30:21 Yvette Adams
So because people trust people and they know that they're hiring trusted people, they could
00:30:28 Yvette Adams
not have the right types of monitoring that should exist for the types of information that they have and that they're stewards of.
00:30:37 Yvette Adams
So I would say most threats originate from ordinary people operating under normal conditions and they could have compromised credentials.
00:30:51 Yvette Adams
They fall for the phishing.
00:30:53 Yvette Adams
They give information that they shouldn't have given.
00:30:58 Yvette Adams
I think that in terms of falling for a phishing attack or falling for somebody that is trying to get credentials, especially with the use of AI and some of the sophistication that comes with that, an employee could give information or give their credentials and immediately think, I just did what I've been trained not to do.
00:31:26 Yvette Adams
The question is, have you given employees permission to be able to elevate that situation and be able to self-report to say, this just happened, I think I made a mistake without a consequence?
00:31:42 Yvette Adams
Can the employee self-report and not be given a negative consequence?
00:31:48 Yvette Adams
Instead, it's thank you so much for
00:31:52 Yvette Adams
acknowledging that happened and coming so quickly to self-report.
00:31:57 Yvette Adams
What can a company do?
00:31:59 Yvette Adams
Where could an organization start?
00:32:01 Yvette Adams
I would say your first starting point is identify who owns the insider risk.
00:32:09 Yvette Adams
so that they can apply what type of approach and who should have a seat at the table when you're looking at these sorts of things.
00:32:17 Yvette Adams
Then assess where the highest risk exists for that organization.
00:32:23 Yvette Adams
What's the highest data risk?
00:32:26 Yvette Adams
What's the highest systems?
00:32:28 Yvette Adams
What are the processes with the highest risk for insider threat?
00:32:32 Yvette Adams
And then evaluate your access management practices
00:32:36 Yvette Adams
to any of those processes, whether it be data systems or processes, right?
00:32:42 Yvette Adams
Especially around the privileged user and departing employees.
00:32:47 Yvette Adams
Those are the two biggest risks.
00:32:49 Yvette Adams
If you're gonna start somewhere, start with privileged users and departing employees.
00:32:55 Yvette Adams
And then the 4th is where you can create that multidisciplinary team who can share information across silos
00:33:04 Yvette Adams
HR, security, compliance.
00:33:07 Yvette Adams
If I had to leave auditors with one thought, it's this.
00:33:10 Yvette Adams
Insider threat management is ultimately about connecting those dots.
00:33:15 Yvette Adams
Most organizations have controls that operate maybe in silos.
00:33:21 Yvette Adams
The challenge is to bring together the people, processes, and information early enough to recognize the risk before it becomes an incident.
00:33:30 Sanjay Vadlamani
Yvette, I really have enjoyed this conversation about insider threat management.
00:33:34 Sanjay Vadlamani
I personally have learned A lot.
00:33:35 Sanjay Vadlamani
Thank you so much.
00:33:37 Yvette Adams
It's been a pleasure talking to you today.
00:33:39 Yvette Adams
Thank you so much.
00:33:41 The IIA
If you like this podcast, please subscribe and rate us.
00:33:44 The IIA
You can subscribe wherever you get your podcasts.
00:33:47 The IIA
You can also catch other episodes on YouTube or at the IIA.org.
00:33:51 The IIA
That's T-H-E-I-A.org.