/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Report: 60% of insider cybersecurity threats involve employees leaving their jobs, with 44% forwarding content to personal emails, 16% misusing cloud privileges

Charlie Osborne / ZDNet :

ZDNet Charlie Osborne

Context & Ripple Effects

This 2020 ZDNet report is the baseline data point in the corpus' insider-threat arc: most insider incidents cluster around employee exits, and the dominant behavior is mundane exfiltration — 74% of third-party breach victims blamed over-privileged access, suggesting exit-time privilege cleanup is where the same failure shows up internally.

Later coverage widens the aperture from departing employees to insiders generally: by 2022, [[a:975336|65% of large IT firms reported being approached to help ransomware operators gain insider access]], and Verizon's analysis found 12% of ~22K incidents carried out by internal actors via synthetic insider techniques. The departure-driven threat this article documents is the entry point that those later attack classes exploit.

First-order effects

  • Offboarding becomes a security control rather than an HR task: the 44% who forward content to personal email and 16% who misuse cloud privileges put HR-triggered access revocation and egress monitoring on IT's critical path for every resignation.

Second-order effects

  • Security vendors gain a concrete selling point for user-behavior analytics and data-loss-prevention tools keyed to notice-period windows, competing on detecting the personal-email forwarding pattern specifically rather than generic anomaly detection.

Third-order effects

  • If the pattern holds, insider-risk programs converge with the synthetic-insider problem into identity-and-privilege-centric defense: continuous entitlement review replaces perimeter trust, and coerced or fabricated insiders meet hardened exit controls at the same choke point.

The trend: Insider threat is evolving from opportunistic data-taking at departure toward a broader identity-abuse surface that now includes recruited and synthetic insiders.