Insider threat behavioural indicators

INSIDER THREAT BEHAVIOURAL INDICATORS

1. Meaning and Legal Context

An insider threat arises where an employee, contractor, officer, consultant, or other authorised person misuses legitimate access to an organisation’s systems, information, property, or facilities. The threat may involve fraud, data theft, sabotage, espionage, disclosure of confidential information, manipulation of records, or unauthorised system activity.

Behavioural indicators are warning signs rather than proof of misconduct. Examples include unusual downloading, repeated attempts to access restricted files, bypassing security controls, copying confidential material before resignation, unexplained use of removable media, abnormal working hours, concealment of activities, or persistent requests for access outside job responsibilities. Employers must distinguish legitimate security monitoring from unjustified surveillance or discriminatory profiling.

2. Unauthorised Access as an Indicator

Case 1: R v Bow Street Metropolitan Stipendiary Magistrate, ex p Government of the United States (Allison) (No 2) [2000] 2 AC 216

Facts: An employee allegedly accessed computer systems and obtained financial information for fraudulent purposes.

Legal Issue: Whether misuse of authorised computer access could amount to unauthorised access.

Judgment: The House of Lords recognised that an employee may exceed the limits of authority attached to system access.

Legal Principle/Ratio: Possessing technical access does not necessarily provide legal authority to access every category of information.

Significance: Attempts to enter systems or records outside an employee’s authorised role may constitute an important insider-threat indicator.

3. Confidential Information Removal

Case 2: Faccenda Chicken Ltd v Fowler [1987] Ch 117

Facts: Former employees used information acquired during employment after leaving the business.

Legal Issue: What confidential information employees remain prohibited from using after termination.

Judgment: The court distinguished ordinary skills and knowledge from genuine trade secrets.

Legal Principle/Ratio: Employees owe duties relating to confidential information, particularly information having the character of trade secrets.

Significance: Large-scale copying of sensitive information before departure can justify investigation where confidentiality obligations exist.

4. Duty of Fidelity

Case 3: Hivac Ltd v Park Royal Scientific Instruments Ltd [1946] Ch 169

Facts: Employees worked for a competing organisation outside their normal employment.

Legal Issue: Whether their conduct breached employment obligations.

Judgment: The employees were found to have breached their duty of fidelity.

Legal Principle/Ratio: Employees must not knowingly act in a manner materially damaging their employer’s legitimate business interests.

Significance: Secret competitive activity, diversion of opportunities, or concealed conflicting interests may represent behavioural warning signs.

5. Secret Preparations and Data Misuse

Case 4: Lancashire Fires Ltd v S A Lyons & Co Ltd [1996] IRLR 113

Facts: Employees made preparations connected with competing business activities while still employed.

Legal Issue: Whether preparatory conduct could breach employment duties.

Judgment: The court examined whether conduct crossed the line from permissible preparation into disloyal activity.

Legal Principle/Ratio: Employees may prepare to compete after leaving, but active misuse of employer resources, customers, or confidential information may breach duty.

Significance: Insider-threat assessment must distinguish innocent career planning from actual misconduct.

6. Dishonesty and Trust

Case 5: Neary v Dean of Westminster [1999] IRLR 288

Facts: Employees occupying positions of responsibility were dismissed following allegations involving serious misconduct.

Legal Issue: Whether conduct undermining trust could justify termination.

Judgment: The court recognised the importance of trust and confidence in employment relationships.

Legal Principle/Ratio: Serious dishonest conduct may fundamentally destroy the employment relationship.

Significance: Concealment, falsification, or deliberate circumvention of controls may warrant investigation, particularly in trusted positions.

7. Misuse of Digital Information

Case 6: Vestergaard Frandsen A/S v Bestnet Europe Ltd [2013] UKSC 31

Facts: Confidential information relating to technology was used in connection with a competing business.

Legal Issue: When individuals may be liable for misuse of confidential information.

Judgment: Liability depended upon knowledge and participation in the misuse.

Legal Principle/Ratio: Confidential-information liability requires careful examination of what the individual knew and how they participated.

Significance: Employers should not infer culpability merely from association; behavioural indicators require supporting evidence.

8. Monitoring Must Be Proportionate

Case 7: Bărbulescu v Romania (2017) 44 BHRC 274

Facts: An employer monitored an employee’s workplace electronic communications.

Legal Issue: Whether workplace monitoring adequately respected privacy rights.

Judgment: The European Court of Human Rights found insufficient safeguards concerning privacy.

Legal Principle/Ratio: Employee monitoring requires transparency, legitimate justification, proportionality, and appropriate safeguards.

Significance: Insider-threat programmes cannot justify unlimited surveillance.

9. Conclusion

Insider-threat behavioural indicators are therefore risk signals, not automatic evidence of guilt. Indicators such as unusual access, mass downloading, security-control circumvention, secret data transfers, concealment, conflicting interests, and misuse of confidential information may justify proportionate investigation. However, employers should combine behavioural evidence with access logs, policy requirements, legitimate business explanations, confidentiality obligations, and procedural fairness. Effective insider-threat management requires balancing organisational security with employee privacy, evidentiary reliability, and lawful monitoring.

LEAVE A COMMENT