Insider Threat (Accidental)
One wrong attachment. Forty-seven salaries exposed.
What Is Insider Threat (Accidental)?
Two browser tabs and a Monday rush, and a confidential salary spreadsheet goes out attached to an email meant for a client. This exercise runs the whole lifecycle: DLP flags the outbound message, you file the incident report under time pressure, and you classify what was exposed. The exotic version of this almost never happens. It is the wrong recipient, the wrong attachment, a permission set too wide. You will practice send delay, sensitivity labels, and checking recipients before sending.
What You'll Learn in Insider Threat (Accidental)
- Identify the behavioral patterns that lead to accidental data exposure in email workflows
- Apply data classification labels to documents based on sensitivity level and audience
- Execute incident reporting procedures within the first 15 minutes of discovering a data leak
- Configure email safeguards including send delay, sensitivity labels, and recipient verification
- Distinguish between accidental and malicious insider threat indicators for appropriate escalation
Insider Threat (Accidental) — Training Steps
-
A Busy Monday Morning
It's Monday morning and your calendar is packed. You have a compensation review meeting with HR on Wednesday, and a client proposal that was due last Friday. Your inbox is overflowing and you're already behind.
-
Confidential HR Data
An email arrives from Priya Sharma in Human Resources with the Q3 compensation data Alice needs for Wednesday's meeting.
-
The Waiting Client
Alice notices the confidential warning in the HR email. She saves the spreadsheet to her downloads for the Wednesday meeting.
-
The Rushed Reply
Another message arrives - James Porter at Pinnacle Corp needs the project proposal by end of day. Under pressure, Alice rushes to reply. Both files are in her downloads - the confidential HR spreadsheet and the client proposal. In her rush, she grabs the wrong one.
-
DLP Alert
Minutes later, an automated alert appears in Alice's inbox. The company's Data Loss Prevention system has flagged her outgoing email.
-
The Realization
Alice's stomach drops. She just sent the entire Analytics department's salary data - names, compensation figures, bonus amounts, and performance ratings for 47 colleagues - to an external client. This isn't a phishing attack. There's no malicious actor. Alice made a simple, human mistake under time pressure. But the consequences are just as real as any cyberattack.
-
Reporting the Incident
Alice knows she needs to act fast. She opens the Security Incident Portal to file a report.
-
Filing the Incident Report
The incident report form asks Alice to describe what happened. She provides a clear, factual account - what was sent, to whom, and how it happened. The security team needs accurate details to assess the scope and begin containment.
-
Report Submitted
The portal confirms the incident report has been submitted and assigned case number INC-2024-0847. The security team has been notified and will begin their response immediately.
-
Security Team Response
An hour later, Alice receives an email from the Security Operations team with an update on the incident.
Security Framework Coverage
CIS Controls
- CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind