Compliance
Insider risk management: what it actually detects
It is not surveillance and it is not a lie detector. What the signals really are, what it catches, and the governance you need before turning it on.
What it is looking at
Insider Risk Management correlates activity signals into a risk score for a user: downloading unusual volumes to a personal device, copying to USB, uploading to personal cloud storage, renaming files before moving them, and access shortly before or after an HR event such as a resignation.
None of those signals is proof of anything individually. The product exists because the combination is far more meaningful than any one of them.
The scenario it genuinely catches
A salesperson resigns, and in the fortnight before their last day downloads the customer list, the pricing model and the pipeline export to a personal device. Every individual action is something they are permitted to do. The pattern is the problem, and no DLP rule catches it because no single action breaches a policy.
The governance to settle before you enable it
Who can see the alerts
Insider risk data is unusually sensitive. Scope the roles tightly, and separate the person who investigates from the person who decides consequences.
Pseudonymisation on or off
The product can show usernames as pseudonyms until an investigation is escalated. In many jurisdictions and under many works council agreements this is not optional.
The legal basis and the notice
Employees generally must be told this monitoring exists. Enabling it quietly is a legal problem in the UK and EU regardless of how good the security case is.
What happens after an alert
Decided in advance, with HR and legal. An alert with no agreed process produces either an overreaction or nothing at all.
The verdict
Worth enabling for departing-employee scenarios, with pseudonymisation on
That single scenario is where most real insider data loss happens, the signals genuinely fit it, and pseudonymisation makes it defensible.
Do not enable it without HR and legal agreement and an employee notice. The technical configuration is the easy part, and deploying it without the governance is the actual risk.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.