M ManySignal

Insider Threat

Catch data theft before the resignation email. Or after.

ManySignal builds 90-day behavioral baselines per user, correlates access patterns with HRMS signals, and detects data staging, exfiltration, and privilege misuse before or during departure — with HIPAA and SOX-compliant evidence packaging.

An insider threat scenario — from signal to response

A real pattern ManySignal detects. Names and details are fictional.

1

Day 1

Departure signal detected

An employee in the legal department emails their personal address three times in one hour — a departure indicator pattern. ManySignal's entity risk score for this user increases from 22 to 54. No alert yet; the system is building context.

2

Day 3

Abnormal data access volume

The same user accesses 340 documents in SharePoint over 4 hours — 8x their 90-day average and 4 standard deviations above their peer group. Risk score increases to 78. A finding fires in the triage queue.

3

Day 3+2h

Triage and evidence assembly

The Triage agent evaluates the finding against the user's full behavioral history. Evidence: departure signal, data volume spike, document types accessed (contracts, IP-sensitive files), and a Google Drive auth from a personal email 20 minutes earlier.

4

Day 3+3h

HR system cross-reference

ManySignal's HRMS integration shows this employee has a pending resignation effective in 10 days. The case is elevated to HIGH severity with full evidence: access logs, document names, email metadata, and the resignation record.

5

Day 3+4h

Analyst review and response

The analyst reviews the pre-assembled case and approves three containment actions: SharePoint access restriction, DLP policy elevation for this user, and a notification to HR and Legal. All three execute within 90 seconds of approval.

Insider threat capabilities

Departure-risk scoring from day 30

Combined behavioral drift, data access volume, and HRMS signal creates a per-user departure risk score updated in near-real-time.

HRMS integration for proactive elevation

Connect Workday or BambooHR and departure events automatically elevate monitoring thresholds 10 days before a user's last day.

Data staging and exfiltration detection

Bulk downloads, personal cloud uploads, and external email forwards are detected against per-user and peer-group baselines.

Privilege misuse detection

Access to systems and data outside the user's established work scope fires a targeted finding with behavioral context.

HIPAA, SOX, and CMMC-compliant evidence

Every insider threat case generates downloadable evidence: access logs, behavioral baseline deviation, HRMS context, and response actions.

Privacy-preserving monitoring controls

Monitoring scope, data retention, and role-based case access are all configurable to meet GDPR and CCPA requirements.

Insider threat — common questions

How does ManySignal handle insider threat investigations while preserving employee privacy?

ManySignal's insider threat features operate within configurable privacy controls. Behavioral monitoring can be scoped to business systems only (excluding personal email, browsing history). Access to investigation cases is restricted to authorized roles. All monitoring is documented for compliance with privacy regulations including GDPR and CCPA.

What is the departure-risk detection model based on?

Departure-risk scoring combines: recent behavioral drift from established patterns, data exfiltration indicators (high volume access, personal cloud uploads, email to external addresses), access to sensitive document categories outside normal work scope, and HRMS signals (resignation, PIP, termination date) when the integration is configured.

Can ManySignal integrate with HR systems to correlate risk signals?

Yes. ManySignal integrates with Workday, BambooHR, SAP SuccessFactors, and ADP via API. When a resignation, termination, or PIP event occurs in the HRMS, ManySignal automatically elevates monitoring thresholds for the affected user and cross-references their recent behavioral activity.

How long does the behavioral baseline period take before insider threat detection is reliable?

Per-user baselines stabilize after 30 days of active monitoring. For organizations with 90+ days of historical IdP and endpoint telemetry, baselines can initialize at connection time using historical data — making insider threat detection reliable from week one.

What compliance frameworks does ManySignal's insider threat capability support?

Insider threat case documentation supports HIPAA breach investigation requirements, SOX access control audit evidence, CMMC Level 2 insider threat program requirements, and NIST SP 800-53 Insider Threat Program (PM-12) controls. Evidence packaging includes the access log, behavioral context, and response actions in a downloadable format.

What is the false positive rate for insider threat alerts?

Insider threat detection inherently has higher false positive rates than perimeter detection — most anomalous behaviour is innocent. ManySignal's per-entity baselines reduce noise vs. population-average models, but teams should expect 60–80% of high-risk alerts to be benign on investigation. The triage agent surfaces the evidence so analysts spend time on the most anomalous patterns, not on every deviation.

How does ManySignal handle contractor and third-party accounts differently from employees?

Contractor and third-party accounts can be tagged with their scope of authorised access. Detections evaluate whether observed access is within the scope tag — access outside the declared scope triggers an escalation regardless of behavioural deviation score. This catches both negligent overreach and deliberate misuse.

What response actions can be taken when an insider threat is confirmed?

Response options include: suspend the account in the IdP, revoke active sessions across all connected systems, quarantine devices via EDR, preserve all access logs to legal hold, and trigger an HR notification workflow. Actions are gated by the autonomy ladder — account suspension typically requires human approval even in autonomous deployments.

Can we conduct a retrospective investigation of a departing employee's activity?

Yes. The entity graph and event store preserve 180 days of activity by default. You can reconstruct the full access history, data movement, and anomaly timeline for any user across the retention window — relevant for exit investigations, litigation support, and post-incident forensics.

Does monitoring employees for insider threat require them to be notified?

Notification requirements vary by jurisdiction. In the EU and many US states, employee monitoring policies must be disclosed. ManySignal provides guidance on compliant deployment scoping; legal review of your monitoring policy before deployment is recommended for multi-jurisdictional organisations.

See insider threat detection in your environment

Connect your IdP and endpoint telemetry. We'll show you entity risk scores for your user population and highlight departure-risk patterns in the first session.