The 15.00 slot in Runway 1 at HELish Summit 2026 was the one session of the day that was not about building anything. Tatu Seppälä, Security Architect and Microsoft MVP for Security at Context&, formerly Sulava, gave “Insider threat: First aid for a misunderstood risk vector”. He runs insider threat programmes for Finnish companies and multinationals, and he said at the start that this was deliberately not a product demo but an argument that we do not take the risk seriously. This is my recap. The observations and the cases are his.

The story he opened with

Two brothers in the United States had wire fraud and unauthorised access convictions from 2015. Nine years later they were hired by a private contractor working for the federal government, because the screening was not thorough enough. When the contractor later found out about the record, both were invited to a call and terminated on the spot. One of them had his account locked during that call. The other did not.

That was the trigger. While the call was still running, the brother with the working account locked everyone else out of the database he administered and started deleting. He asked ChatGPT how to remove the server logs about deleting records. Then he went through 96 databases in an hour, took personal data on 450 people, and deleted around 1,800 government files. They wiped their laptops before handing them in.

The detail that makes the case is how it was solved. The HR director had left the call, but the recording was still on, and the brothers stayed on it to coordinate the sabotage. Everything they did was in the transcript.

Slide showing the Akhter brothers case: 2015 wire fraud and unauthorised access convictions, hired at a federal contractor in 2023-24
The case that opened the session. The gap that mattered was not the hiring decision but the account that nobody locked during the termination call.

Three words that are not the same thing

He spent real time on vocabulary, and it was worth it. An insider is anyone who works for you now or worked for you in the past, including partners, anyone with knowledge of your systems, your processes or your intellectual property. That includes board members and it includes the caretaker. Insider risk is the potential of those people to cause damage, whether or not they intend to. Insider threat is the subset who are likely to cause harm, either on purpose or through careless work.

His example was blunt: if someone has access to a critical database, they are a risk, not a threat. The potential is there and has not been realised. Mitigating risk and mitigating threat are two different jobs, and the field treats them as such.

Slide defining insider threat as an insider, or group of insiders, that either intends to or is likely to cause harm or loss to the organization
The definition he asked the room to remember. The line between risk and threat is intent or likelihood, not access.

The profile, and why it does not help you screen

A UK study of several hundred organisations that had actually been hit produced a profile of the typical insider: male, 31 to 45, university educated, permanent staff rather than a contractor and not C-level, usually employed for under five years. The part he found most useful is that most of them were not recruited with any intention to cause harm. They came to work normally and were frustrated, triggered or radicalised while they were there.

That is the point the profile actually makes. You cannot filter this out at the recruiting stage. He also noted that he fits the profile himself.

Slide titled The typical threat listing the profile of a typical insider, source NPSA Insider Data Collection Study
His slide, sourced to the NPSA Insider Data Collection Study. Under five years of service and self-initiated after being hired are the two lines that matter most.

What security can actually change

For a crime to happen, criminology says three things have to be present at once: someone predisposed to commit it, a suitable target, and the absence of a capable guardian. Security work, he said, is almost entirely about the third one, supplying a capable guardian or at least the belief that you will be caught. Access management works on the second by making targets harder to reach. Nobody in this room gets to work on the first.

The motives repeat: greed, ego, ideology, revenge, and occasionally plain curiosity with no malice in it. So do the triggers. Being fired, being isolated from the work community, personal financial trouble, and right now large scale layoffs and the uncertainty that comes with them. Nothing happens randomly, and there is always a trigger.

The cases each name a fix

A network administrator in San Francisco who saw a layoff coming took the city network hostage by changing the passwords, and the standoff ran for days. The fix is not a product. It is an off-boarding playbook for privileged roles, and the honest question he put to the room: how many of you know an admin who left and whose account was not locked the same day?

An NSA contractor hoarded roughly 45 terabytes of tooling, picked up project by project across two decades, because his access was never removed when a project ended. He carried it out on thumb drives with no controls in the way. Endpoint data loss prevention would not have made that impossible, but it would have produced friction and a visible pattern, which is the point. He asked for hands on that one too: who has access from a finished project that was never taken away?

His preferred answer to the access half is Entra ID access packages. Bundle the SharePoint sites, groups and roles a project needs into one package, assign it for a fixed period, and let it expire on its own. Nobody has to remember to remove anything. He said it is badly underused.

My Access portal showing one active time limited access package with start and end dates
A time limited access package in My Access, with a start and an end date. The expiry is what removes the access, not a person remembering to.

Where to look first

Research presented at Black Hat last year, covering more than a thousand insider risk cases, found that about a quarter involved activity after the person had already been let go, and that the last 30 to 90 days of employment is when intentional exfiltration happens. Hence his advice for anyone starting with Insider Risk Management: build the policy for data theft by departing users first.

The 9,999 you are ignoring

For every intentional insider, he put the unintentional ones at 9,999, and said that is most of what data security consultants actually work on. Samsung engineers pasted internal research into ChatGPT. A city employee sent a colleague in another municipality an Excel file containing personal data on thousands of people, to a work address and a personal one to be safe, and the class action that followed was 92.9 million dollars. United States military email went to Mali for over a decade because .ML and .MIL are one keystroke apart.

None of those are the individual’s fault, and that was his sharpest point. A usability specialist he interviewed put it as a law: when there is an easy way and a secure way, people take the easy way, so the secure way has to be the easy one.

If people route around security to get their work done, security has failed, not the employees.

He closed with Eric Cole, former CTO at McAfee and Chief Scientist at Lockheed Martin: what matters is not where the threat comes from but the potential for damage, and by that measure the most serious damage is done from the inside. Asked afterwards how he balances detection against prevention, his order was detect first, then friction, then education, and blocking only as a last resort, because security that stops the business has stopped doing its job.

Tatu is a fellow Microsoft MVP, and this was the most uncomfortable 45 minutes of my conference day. That is a compliment.