Report: 60% of insider cybersecurity threats involve employees leaving their jobs, with 44% forwarding content to personal emails, 16% misusing cloud privileges
Charlie Osborne / ZDNet :
Context & Ripple Effects
This 2020 ZDNet report is the baseline data point in the corpus' insider-threat arc: most insider incidents cluster around employee exits, and the dominant behavior is mundane exfiltration — 74% of third-party breach victims blamed over-privileged access, suggesting exit-time privilege cleanup is where the same failure shows up internally.
Later coverage widens the aperture from departing employees to insiders generally: by 2022, [[a:975336|65% of large IT firms reported being approached to help ransomware operators gain insider access]], and Verizon's analysis found 12% of ~22K incidents carried out by internal actors via synthetic insider techniques. The departure-driven threat this article documents is the entry point that those later attack classes exploit.
First-order effects
- Offboarding becomes a security control rather than an HR task: the 44% who forward content to personal email and 16% who misuse cloud privileges put HR-triggered access revocation and egress monitoring on IT's critical path for every resignation.
Second-order effects
- Security vendors gain a concrete selling point for user-behavior analytics and data-loss-prevention tools keyed to notice-period windows, competing on detecting the personal-email forwarding pattern specifically rather than generic anomaly detection.
Third-order effects
- If the pattern holds, insider-risk programs converge with the synthetic-insider problem into identity-and-privilege-centric defense: continuous entitlement review replaces perimeter trust, and coerced or fabricated insiders meet hardened exit controls at the same choke point.
The trend: Insider threat is evolving from opportunistic data-taking at departure toward a broader identity-abuse surface that now includes recruited and synthetic insiders.