Contact Bar
Sri Lanka
India
Sri Lanka
Bangladesh
Middle East

A regional sales manager at a mid-sized insurer hands in her notice. She is professional about it, serves her thirty days, trains her replacement, and leaves with a warm farewell email from the CEO.

Six weeks later, three of her largest accounts do not renew. They have moved to a competitor she now works for. Her old employer asks the obvious question: did she take the book with her?

The security team goes looking. The endpoint agent shows no malware and the firewall logs show nothing unusual. Somebody reads nine months of her archived mailbox and finds nothing, because she never emailed anything to herself. She opened the CRM, ran the standard quarterly pipeline export she had run for four years, and copied it to a personal cloud folder already syncing on her laptop because nobody had ever blocked it.

Her laptop was wiped and reissued on her last day.

There is no evidence and no timeline. Nobody can say what left the building, when, or whether anyone else did the same thing last quarter. Legal advises against action because the case cannot be substantiated. The insurer absorbs the loss, writes a memo about tightening offboarding, and moves on.

This is what insider risk actually looks like. Not a spy. A resignation.

The gap between the org chart and reality

Almost every security architecture in production today was designed around a boundary. There is an inside and an outside, the outside is hostile, and the stack exists to keep the two apart. Firewalls, secure web gateways, email security, endpoint protection, identity providers: all of it decides whether someone who is not supposed to be here gets in.

Insider risk breaks that model at the premise. The person is supposed to be here. They authenticated correctly, from an approved device, on a network you trust, using an application you licensed for them, to reach data their role entitles them to see. Every control in the chain returns “allow”, and every control is correct to do so.

What changed is not that employees became less trustworthy. What changed is how much data one ordinary employee can move, and how many ways there are to move it.

A decade ago, exfiltrating a customer database meant burning it to a disc or attaching it to an email a gateway would probably flag. Today it means dragging a folder into a personal sync client, logging into personal webmail in a browser tab, pasting contract text into a public chatbot, or pushing a repository to a code hosting service the company does not administer. None of this requires technical skill, and at the network layer several of them are indistinguishable from the legitimate work the same person does all day.

Hybrid work made this structural. Corporate data now sits on home networks, on personal devices, and in cloud tenancies that IT provisioned but never fully instrumented. The physical controls that used to quietly do a lot of work, a locked office, a supervised print room, a colleague who could see your screen, are gone for much of the workforce.

Then there is the access you granted deliberately. Contractors, outsourced development teams, managed service providers, seasonal staff. Across South Asia, Singapore and the Gulf this is not an edge case, it is the operating model for entire industries: shared-services centres running finance, HR and customer operations for clients on other continents, with real credentials into real systems holding real personal data.

The org chart says you employ two thousand people. The access model says several thousand identities can reach something that would hurt you if it left.

Where insider risk actually bites

  • Departure is the highest-risk window and nobody watches it

The period between a person deciding to leave and their last day is when most deliberate data loss happens. It is also when the organisation is at its most relaxed about them, because the relationship is ending amicably and everyone is focused on handover.

The practical failure is sequencing. HR knows about the resignation on day one. Security often finds out on the last day, through a ticket asking for the account to be disabled. In between sits a notice period of full access, a legitimate reason to be pulling reports, and a personal incentive.

The evidence also has a short life. Laptops get wiped and reissued, mailboxes get converted or deleted after a retention window, and browser history goes with the machine. By the time anyone suspects something, the artefacts are gone.

  • The exfiltration path is now a feature, not a hack

Consider a developer who has decided to leave. They defeat nothing. They add a second remote to a repository they already have cloned locally, and push. The traffic is HTTPS to a well-known developer platform the engineering team uses every day and the web gateway therefore allows.

Or a finance clerk who wants the payroll file but knows the USB ports are locked, so they photograph the screen with a phone. There is no network event at all.

Each is a different technical problem, and most organisations have a control for exactly one of them.

  • Generative AI turned careless into catastrophic

The newest version of this problem is the most common and the least tracked. An analyst with a dense vendor contract and a deadline pastes the whole thing into a public AI assistant and asks for a summary of the termination clauses. A support agent pastes a customer complaint, including full name, account number and medical detail, and asks for a polite reply.

Neither thinks they are doing anything wrong. They are being efficient. But the material has left your control boundary, entered a third party’s processing environment, and nobody in your organisation knows it happened.

Under India’s DPDP Act, Singapore’s PDPA, the UAE PDPL, Saudi Arabia’s PDPL and Sri Lanka’s PDPA, that is a disclosure of personal data to a processor you have no contract with and no record of. Your privacy notice does not cover it. If a regulator asks, you cannot answer.

  • You cannot protect what you have never located

Ask most organisations where their sensitive data lives and you get an answer describing the systems of record: the core banking platform, the HR system, the EMR, the billing engine. That answer is true and almost useless, because the copies are the problem.

The copies sit in a folder called “Analysis 2024 final v3” on a departmental share, in the attachment of a five-year-old email thread, in a spreadsheet that began as a board-pack extract, and in the test database refreshed from production because anonymising it would have taken a sprint nobody had.

You cannot write a meaningful data loss policy over an estate you have not classified. Every rule ends up either so broad it blocks normal work, or so narrow it misses the copies.

  • Fraud is an insider risk problem that security does not own

A procurement manager runs a tender. The winning bidder is registered at the same residential address as the manager’s brother-in-law. The award is within delegated authority, the paperwork is complete, and internal audit will review this category of spend in about eighteen months.

Nothing here trips a security control, because none of it is a security event. It is a pattern spread across email, procurement records and a relationship nobody documented, held in fragments by different functions, with no function looking at all of them.

The same shape appears in kickbacks, expense manipulation, ghost vendors, moonlighting for a competitor and collusion with a customer. In BFSI and government these carry regulatory consequences ordinary data loss does not.

  • Three functions each hold a third of the picture

HR knows the resignation, the failed promotion, the grievance, the sudden change in demeanour. Security knows the after-hours logins, the bulk export, the USB attempt. Legal knows the restrictive covenant and what evidence would stand up.

None of them share a system, a vocabulary, or in many organisations a working relationship. Security escalates to HR and is told it is a people matter. HR flags a difficult exit and is told there is nothing in the logs. Legal is brought in after both have concluded there is no case. A company holding every ingredient of a clear picture never assembles one.

  • Monitoring people is a governance problem before it is a technical one

This is the part most vendor material skips, and the part that sinks projects.

Watching employees is lawful in most jurisdictions, but conditional. Regional data protection law treats employee data as personal data, with all that implies: a defined and legitimate purpose, proportionality between what you collect and what you are protecting, transparency to the people affected, retention limits, and access controls over the monitoring data itself, which is often more sensitive than the data it protects.

In practice, employees generally must be told that monitoring occurs and in what form. Scope must be proportionate, which is why blanket, permanent, full-content capture of everyone is far harder to defend than targeted capture tied to defined risk. Where you operate in or serve jurisdictions with collective labour representation, works councils or employee consultation bodies may have a formal role. And the monitoring system must itself be auditable.

Organisations that get this wrong rarely get caught by a regulator first. They get caught internally, when a capability deployed quietly becomes known, trust collapses, and the board shuts the programme down. Insider risk management that is not policy-led, disclosed, scoped and reviewable is not a security control. It is a liability with a dashboard.

Why more visibility produces less clarity

The standard response to insider risk is to buy more visibility, and the standard result is more noise.

An organisation adds a DLP product for email and web, a separate agent for removable media, a cloud access layer for sanctioned SaaS, and file server auditing because compliance asked for it. Each has its own console, its own policy language, its own definition of sensitive, and its own alert queue.

Nobody correlates them, because correlating them was never anyone’s job. The queue grows past what the team can triage, so policies get tuned down until the volume is manageable, and at that threshold they stop catching the handful of events that mattered.

The second failure is treating insider risk as a headcount problem: hire an analyst to read the alerts and investigate. Outside very large banks and telcos, that role rarely survives contact with reality. It demands security, HR, legal and investigative skills at once, and in most of the markets EGUARDIAN serves that person is hard to hire, expensive to retain, and a single point of failure the moment they take leave.

The third failure is the spreadsheet: HR emails security a list of leavers each Monday, logs get pulled by hand, findings go into a shared workbook. It works for two quarters, then degrades, and it produces nothing an employment tribunal would accept as evidence.

All three try to assemble, by human effort, a picture the underlying tools were never designed to produce. The problem is not insufficient alerting. It is that the classification of the data, the record of what happened to it, the context of the person and the evidence needed to act live in different places and are never brought together.

How SearchInform approaches this differently

SearchInform starts from a different assumption: that insider risk is one problem, not four, and that the classification of data, the monitoring of channels, the behaviour of people and the evidence for an investigation belong in one platform rather than being stitched together afterwards.

EGUARDIAN distributes SearchInform across its territories, and the reason it sits in the portfolio is architectural rather than feature-driven. The pieces are designed to reference each other.

1. It starts by finding and classifying the data

SearchInform FileAuditor is the discovery and classification layer, built on the data-centric audit and protection approach. It performs content-based classification of files held on workstations, across the local network and in database management systems, labelling documents by data type, with manual refinement where the automated result needs correcting.

It audits user operations against the file system at driver level rather than relying on operating system logging, so it sees what happened to a file rather than what a log source chose to record. It audits access rights, including full access, editing, reading and writing, and surfaces unauthorised permission changes on local and network file systems.

It also makes shadow copies of critical files on workstations, servers and network folders, retaining their revision history. That is the difference between knowing a document was touched and showing what it contained at the time.

2. It monitors the channels people actually use

SearchInform Risk Monitor covers the transfer paths through discrete modules, each responsible for a real-world channel. MailController covers corporate and public email, including web-based mail. IMController covers corporate and public messengers. CloudController covers transfers to cloud services and collaboration platforms. HttpController and FtpController audit, categorise and where required block browser and FTP traffic. PrintController addresses leakage through printing, and DeviceController audits files moved through removable storage and input/output ports.

For channels with no network signature there are matching controls: MonitorController with keylogging for screen activity, watermarking to constrain screenshots and unauthorised recording, and MicrophoneController for audio capture with speech-to-text. Microsoft 365 has dedicated coverage, including attachments, chats and messages in Teams Online and Exchange Online.

The platform ships with a large library of preset security policies, general-purpose and industry-specific, alongside custom policy creation, so you do not start from a blank rulebook. Detection is not limited to pattern matching: user behaviour analytics surface risk early rather than only at the moment of transfer, and blocking is available where prevention is the requirement.

3. It keeps evidence that survives the investigation

The forensic capability is where the platform separates itself from alert-centric tooling. Rather than storing only the fact of an event, it retains the raw material: original emails, chat messages, transferred documents. An investigator can reconstruct a chain of events after the fact, which is exactly what was missing in the scenario this post opened with.

Insider investigations almost always begin retrospectively, weeks after the activity and often after the person has left. A platform that retained only alerts has nothing to offer then. One that retained the underlying artefacts, under defined retention and access rules, can answer the question.

4. It adds behavioural context, carefully

SearchInform ProfileCenter analyses employee correspondence from email and corporate messengers against more than seventy criteria to surface behavioural indicators: personality traits and emotions, motivation and needs, patterns of conduct and thinking, indicators of loyalty and reliability, and a person’s role and influence within a team. It produces these signals from existing communication rather than through open testing of employees.

This is the most governance-sensitive component in the platform and should be treated as such. Behavioural profiling of employees is exactly the processing regional data protection law expects you to justify, scope, disclose and limit. Deployed as a targeted capability within a disclosed policy, it surfaces risk no log will show. Deployed silently across a workforce, it is the fastest route to the trust collapse described earlier. The governance is yours.

5. It handles the analyst problem directly

SearchInform SIEM correlates events from security tools, applications, databases, network hardware and directory services over standard protocols, with a large body of prebuilt correlation rules, for organisations with no security engineering function.

The more significant answer is SearchInform MSS, the vendor’s managed security service. Under a subscription model, SearchInform assigns analysts who configure the policies and monitor the environment on the customer’s behalf, delivering incident reports on an agreed cadence with immediate contact when something urgent surfaces, plus recommendations on data handling and compliance. There is a parallel programme for service providers delivering insider risk monitoring to their own clients.

For an organisation of a few hundred to a few thousand people in Colombo, Dhaka, Mumbai or Dubai, this is often the deciding factor. The technology was never the blocker. Having nobody to run it was.

Where a lighter footprint fits better, EGUARDIAN also carries Safetica, which brings data protection, insider risk, cloud security and compliance together in one platform. It reads behavioural signals, data and user identity together to give visibility into actions and intent, and it monitors and controls sensitive data across devices and cloud services including Microsoft 365 and file-sharing platforms. It is available as a cloud platform or on-premises.

What this looks like in practice

Return to the resigning sales manager, with this architecture in place.

  1. FileAuditor has already classified the CRM exports, board packs and customer lists wherever copies exist, including the departmental share and her own workstation.
  2. HR records the resignation. She moves into a heightened-monitoring group under a disclosed policy, for the notice period only, with an end date.
  3. She runs the quarterly pipeline export. It is normal, not blocked, recorded, and the file is recognised as classified customer data.
  4. She copies it to a personal cloud sync folder. CloudController sees a classified file moving to an unsanctioned destination. Depending on policy it is blocked, or allowed and flagged.
  5. Behavioural signals accumulate: after-hours access, file activity above her baseline, access to accounts outside her territory.
  6. The case is escalated with the underlying artefacts attached, not an alert ID. Security, HR and legal see the same record.
  7. The conversation happens before her last day, while she is still an employee and the laptop exists.
  8. The monitoring scope expires at the end of the notice period, and the fact that it was applied, by whom and under which policy, is itself logged.

The outcome is not that she is caught. It is that the organisation has a defensible answer either way.

Mapping the problem to the platform

ChallengeHow the platform addresses it
Sensitive data exists in uncounted copies outside systems of recordFileAuditor classifies content across workstations, network storage and databases, with access rights auditing
Exfiltration happens through everyday channels that look like normal workRisk Monitor covers email, messengers, cloud, web, FTP, print and removable media through dedicated modules, with blocking where required
Screen photography, audio and non-network leakage leave no traceScreen monitoring, watermarking and microphone capture with speech-to-text cover channels the network cannot see
Investigations start after the evidence is goneForensic retention of raw artefacts, including original messages and documents, supports retrospective reconstruction
Fraud and collusion span systems no single team watchesBehavioural analytics and ProfileCenter indicators surface patterns across communication and file activity
No dedicated insider risk analyst existsSearchInform MSS provides assigned analysts, configured policies and scheduled incident reporting under subscription
Monitoring itself must be lawful and defensibleScoped policies, defined retention and auditable access support a disclosed, proportionate programme

Who this is for

Banks, insurers and asset managers under central bank technology and outsourcing guidance, where customer data movement, relationship-manager conduct and third-party access are all supervised concerns.

Government and public sector bodies holding citizen data at scale, where the insider risk is often a contractor or a long-tenured employee with accumulated access nobody has reviewed.

Outsourcing, shared services and BPO operators across Sri Lanka, India, Bangladesh, Singapore and the Gulf, contractually accountable to overseas clients for the behaviour of staff handling those clients’ data, and routinely audited on it.

Manufacturing, healthcare and telecommunications organisations with concentrated intellectual property, patient records or subscriber data, and lean security teams relative to the estate they defend.

The wider point

Insider risk is usually framed as a security problem, and it is one. The more accurate framing is that it is a records problem. Most organisations can eventually work out what happened. The question is whether they can do it quickly enough to prevent harm, credibly enough to act on, and lawfully enough to defend how they found out.

Getting this right is also not an act of suspicion. A well-run programme protects employees as much as it monitors them. It clears the innocent quickly, removes the ambiguity that makes managers act on rumour, and gives anyone accused of something a factual record rather than an impression. That beats the arrangement most organisations have now, in which nobody knows anything and the loss is quietly written off.

The organisations that handle this well are not the ones that deploy the most monitoring. They are the ones that decide, deliberately and in writing, what they are protecting, from whom, for how long and with what oversight, and then implement exactly that.

Talk to our experts at EGUARDIAN. If you are trying to build an insider risk programme that stands up to both a regulator and your own employees, let us talk through the data you are protecting, the jurisdictions you operate in and the scope of monitoring you could genuinely defend. Reach out to us at hello@eguardian.com.