Insider threats in cybersecurity.
Insider Threats in Cybersecurity
1. Meaning
An insider threat is a cybersecurity risk arising from a person who has legitimate or authorised access to an organisation's systems, networks, applications, devices, or confidential information but uses that access improperly.
An insider threat may involve:
- an employee;
- former employee;
- contractor;
- consultant;
- temporary worker;
- vendor personnel; or
- another person with authorised access.
The threat may be intentional, such as stealing data, or unintentional, such as accidentally sending confidential information to the wrong recipient.
2. Types of Insider Threats
A. Malicious Insider
A malicious insider deliberately abuses legitimate access.
Examples include:
- stealing customer databases;
- copying trade secrets;
- deleting company files;
- selling confidential information;
- manipulating financial records;
- installing unauthorised software; or
- deliberately disabling security controls.
B. Negligent Insider
The employee does not intend to cause harm but violates security requirements through carelessness.
Examples:
- clicking a phishing link;
- using weak passwords;
- leaving a laptop unlocked;
- sending confidential documents to a personal email account;
- using unauthorised cloud storage; or
- losing an unencrypted device.
C. Compromised Insider
An employee's legitimate credentials are stolen by an external attacker.
The attacker then uses those credentials to appear to be an authorised employee.
This is sometimes called credential-based insider compromise.
D. Collusive Insider
An employee cooperates with an external person to obtain or misuse organisational information.
For example, an employee may provide database credentials to an outside criminal.
3. Why Insider Threats Are Difficult to Detect
Traditional cybersecurity systems concentrate heavily on external attacks.
Insider threats are more difficult because the person may already have:
- a legitimate username;
- password;
- security token;
- VPN access;
- database permissions;
- physical access; or
- knowledge of internal systems.
Therefore, simply asking whether an access attempt was authorised may not reveal whether the underlying activity was legitimate.
4. Common Insider-Threat Scenarios
Data Theft
An employee downloads customer or company information before leaving employment.
Intellectual-Property Theft
An employee copies:
- source code;
- designs;
- algorithms;
- business plans;
- customer lists; or
- technical documentation.
Destruction of Data
A disgruntled employee deletes files, databases or backups.
Unauthorised Disclosure
Confidential information is provided to competitors or other third parties.
Privilege Abuse
An employee uses administrative privileges for purposes unrelated to their job.
Security-Control Circumvention
An employee deliberately bypasses access controls, monitoring systems or authentication requirements.
5. Insider Threats and Employment Law
Insider-threat incidents frequently create an overlap between cybersecurity law and employment law.
An employer may need to determine:
- What information did the employee access?
- Was the access authorised?
- Was the information confidential?
- Did the employee copy or transfer it?
- Was there an applicable confidentiality obligation?
- Was the employee's access appropriate for the job?
- Were cybersecurity policies communicated to the employee?
- Was monitoring lawfully conducted?
- Was disciplinary procedure followed?
- What evidence establishes the employee's conduct?
These questions become particularly important where termination or disciplinary proceedings follow a cyber incident.
6. Data Protection and Privacy
Insider-threat monitoring can itself create privacy concerns.
Employers may monitor:
- login records;
- access logs;
- email systems;
- file downloads;
- network activity;
- company devices;
- privileged-account activity; and
- security alerts.
However, organisations should consider lawful authority, purpose limitation, proportionality, transparency, security and retention when implementing employee monitoring.
Monitoring should not automatically become unlimited surveillance of employees.
7. Principle of Least Privilege
A major cybersecurity measure against insider threats is least privilege.
Under this principle, an employee receives only the access necessary to perform their job.
For example:
An HR employee may need access to employee records but normally does not require unrestricted access to source-code repositories.
Similarly:
A software developer may need source-code access but may not need access to the entire payroll database.
Least privilege reduces the potential damage if an account is misused or compromised.
8. Access Reviews
Organisations should periodically review:
- user accounts;
- administrator privileges;
- database access;
- remote-access permissions;
- dormant accounts;
- shared accounts; and
- contractor access.
Particular attention should be given to employees who:
- change departments;
- receive promotions;
- take extended leave;
- resign; or
- are terminated.
9. Employee Exit Procedures
A significant insider-threat risk occurs when an employee leaves an organisation.
A proper offboarding process should consider:
- disabling accounts;
- revoking VPN access;
- recovering company devices;
- changing relevant credentials;
- terminating application access;
- reviewing privileged access;
- preserving relevant evidence where legally appropriate;
- reminding the employee of continuing confidentiality obligations; and
- documenting completion of the process.
Immediate revocation of access may be particularly important for employees with privileged or sensitive-system access.
10. Case Laws
1. American Express Bank Ltd. v. Priya Puri, 2006 (110) DLT 506
The Delhi High Court considered disputes involving confidential information and employee movement.
The Court distinguished between legitimate employee mobility and protection of confidential business information.
Principle: Employers may protect genuine confidential information, but ordinary knowledge, skill and experience acquired by an employee cannot simply be treated as proprietary information.
Cybersecurity relevance: A company cannot automatically classify everything an employee knows or accesses as a trade secret. It should identify the genuinely confidential information and establish appropriate safeguards.
2. Emergent Genetics India Pvt. Ltd. v. Shailendra Shivam, 2011 (125) DRJ 173
The Delhi High Court dealt with alleged misuse of confidential information and trade secrets by former employees.
The case illustrates the importance of establishing the confidential character of information and the circumstances surrounding its alleged misuse.
Cybersecurity relevance: When an employee downloads or transfers digital information, an organisation should be able to identify what information was confidential and establish evidence concerning access or misuse.
3. John Richard Brady v. Chemical Process Equipments P. Ltd., AIR 1987 Delhi 372
The Delhi High Court considered protection of confidential information and technical know-how.
Principle: Courts can protect genuinely confidential business and technical information against misuse in appropriate circumstances.
Cybersecurity relevance: Digital technical information, designs and proprietary processes can require protection through contractual, technical and legal measures.
4. Diljeet Titus v. Alfred A. Adebare, 2006 (32) PTC 609 (Delhi)
The Delhi High Court considered allegations concerning misuse of confidential information and copyright-related materials by former employees.
The case demonstrates the importance of distinguishing proprietary organisational material from information that an employee is legitimately entitled to use.
Cybersecurity relevance: Organisations dealing with digital files should maintain access controls, confidentiality arrangements and evidence showing ownership and authorised use.
5. American Express Bank Ltd. v. Ms. Priya Puri, 2006 (110) DLT 566
The Delhi High Court's reasoning in the American Express litigation is frequently cited in disputes involving confidential information and employees.
Principle: Confidential information receives legal protection where its confidential character and the circumstances supporting protection can be established.
Cybersecurity relevance: Merely labelling a database "confidential" may not be enough. Organisations should implement actual technical and contractual controls around sensitive information.
6. Niranjan Shankar Golikari v. Century Spinning & Manufacturing Co. Ltd., (1967) 2 SCR 378
The Supreme Court considered contractual restrictions imposed during the period of employment.
The Court recognised that certain negative covenants operating during the subsistence of employment can be enforceable when appropriately framed.
Cybersecurity relevance: Employment agreements can contain appropriate confidentiality and information-security obligations while employment continues.
7. Superintendence Company of India (P) Ltd. v. Krishan Murgai, (1981) 2 SCC 246
The Supreme Court examined post-employment restrictions and the operation of Section 27 of the Indian Contract Act, 1872.
Principle: Restrictions on an employee's activities after employment must be carefully assessed because Indian law generally treats agreements restraining lawful trade or profession with significant strictness.
Cybersecurity relevance: An organisation should distinguish a lawful confidentiality obligation from an excessively broad attempt to prevent a former employee from using general knowledge or pursuing employment.
8. Wipro Ltd. v. Beckman Coulter International S.A., 2006 (3) CHN 215
The Delhi High Court considered confidentiality and restrictive-covenant issues in a commercial context.
Relevance: The case illustrates the importance of properly defining confidential information and contractual obligations rather than relying on vague restrictions.
11. Evidence in Insider-Threat Investigations
Digital evidence may include:
- authentication logs;
- access-control logs;
- database queries;
- file-access records;
- download records;
- email records;
- endpoint logs;
- USB/device activity;
- VPN records;
- cloud-access logs;
- CCTV where lawfully maintained; and
- forensic images.
The organisation should preserve evidence carefully because its reliability and chain of custody may become important in subsequent litigation or disciplinary proceedings.
12. Disciplinary Action
Where an employee is suspected of an insider attack, the employer should generally distinguish suspicion from established misconduct.
A fair investigation may involve:
- identifying the suspected activity;
- securing relevant systems;
- preserving evidence;
- determining the employee's authorised access;
- obtaining relevant logs;
- giving the employee an opportunity to respond;
- conducting an enquiry where required;
- determining whether company policy/service rules were violated; and
- imposing an appropriate consequence under the applicable employment framework.
A cybersecurity alert alone should not automatically be treated as conclusive proof of intentional wrongdoing.
13. Preventive Compliance Framework
An organisation can establish an insider-threat program consisting of:
Technical controls
- multi-factor authentication;
- least-privilege access;
- privileged-access management;
- encryption;
- data-loss prevention;
- endpoint detection;
- network monitoring;
- access logging; and
- automated alerts.
Administrative controls
- confidentiality agreements;
- information-security policies;
- employee training;
- background verification where lawful;
- periodic access reviews;
- incident-response procedures; and
- documented disciplinary rules.
Offboarding controls
- immediate account review;
- access revocation;
- device recovery;
- credential changes;
- preservation of relevant evidence;
- confirmation of return/deletion of organisational information where legally appropriate.
14. Key Legal Issues
| Issue | Legal concern |
|---|---|
| Employee downloads confidential files | Confidentiality/trade-secret issues |
| Employee sends data outside organisation | Data-security and confidentiality issues |
| Former employee uses company information | Post-employment confidentiality |
| Monitoring employee activity | Privacy and proportionality |
| Administrator abuses privileges | Disciplinary and contractual liability |
| Employee shares password | Security-policy violation |
| Employee takes customer database | Confidentiality/IP issues |
| Employer terminates employee | Natural justice and service rules |
| Excessive post-employment restrictions | Section 27, Contract Act |
| Digital evidence | Authenticity and evidentiary requirements |
Conclusion
Insider threats in cybersecurity arise when authorised access is misused, negligently handled, or compromised. The legal problem is therefore broader than simply identifying a cyberattack: it can involve employment contracts, confidentiality, intellectual property, privacy, disciplinary procedure, evidence and data protection.
Indian decisions such as American Express Bank v. Priya Puri, Emergent Genetics v. Shailendra Shivam, John Richard Brady v. Chemical Process Equipments, Diljeet Titus v. Alfred A. Adebare, Niranjan Shankar Golikari v. Century Spinning and Superintendence Company v. Krishan Murgai demonstrate important principles concerning confidential information, employee obligations and post-employment restrictions.
A sound insider-threat framework therefore combines least-privilege access, appropriate monitoring, confidentiality obligations, employee awareness, access reviews, strong offboarding procedures and fair disciplinary processes.

comments