
Chris Denbigh-White at Next DLP considers the dangers of monitoring bias in insider threat programs
Insider threat monitoring has become a crucial component of every proactive cyber-security strategy. Without it, organisations are susceptible to a wide range of risks created by both employee mistakes and malicious activities. According to the 2023 Insider Threat Report, nearly two-thirds of respondents report they had experienced an insider attack in 2022. Clearly, the danger is very real.
It’s perhaps not surprising, therefore, that the same survey found that 89% of organisations either have an insider threat program in place or are planning to add one in the future.
Clearly, this is an important and encouraging trend, but in designing an effective strategy, it’s vital that security teams don’t overlook a critical issue: monitoring bias.
Put simply, monitoring bias is placing selective and unwarranted emphasis and attention on specific employees, groups or teams – irrespective of their actual behaviour and use of technology systems. From a risk monitoring perspective, it can lead to unfair judgments and assumptions about the levels of trust attached to the employees in question.
Conversely, it can also create situations where certain users are given a free pass for activity that might otherwise be considered risky or in breach of security policy.
In practical terms, monitoring bias can manifest itself in a number of ways. First, organisations can be susceptible to carrying out unequal monitoring activities where certain people, teams or roles are monitored more intensely than others. The main problem this can create is awareness blindspots and heightened exposure to potential breaches from the less-monitored areas.
Next is the problem of selective attention, where insider monitoring focuses too heavily on specific behaviours or activities that are deemed to be riskier, leading to a situation where other risk factors and indicators are overlooked. Attribution bias is when certain employees are consistently categorised as either high risk or low-risk, without reference to their actual behaviours and how they might change over time.
Group identity bias occurs when employees from specific backgrounds or demographic groups are seen as presenting a higher insider threat risk based on either prejudice or stereotyping. Finally, confirmation bias over-emphasises insider threat monitoring data that supports preconceptions, irrespective of analysis that may indicate the contrary.
If one or more of these behaviours are influencing how organisations approach insider threats, there is a heightened risk that security teams will focus their time, effort and technology resources in the wrong areas. In doing so, they actually increase the likelihood that a breach will emanate from a person or group that was considered to be less risky.
The wider effects of this aren’t just the impact of the breach itself but anything from legal liability and a breakdown in employee relations to major reputational damage for any organisation found to have been biased in its treatment of employees.
Legacy monitoring and risk management technologies have also contributed to the presence of bias within the insider threat process. Originally built for organisations that operated within the confines of corporate firewalls and with little or no remote working, outdated monitoring systems rely on intrusive approaches such as key logging, web monitoring and screen recording to inform the level and potential source of insider risk seen across the organisation.
Today, this approach is seen as something of a blunt instrument that focuses more on productivity tracking than security or data protection.
So where does that leave the many organisations out there who are fully committed to eliminating bias and discrimination from their processes and culture?
The first point to appreciate is that getting rid of monitoring bias and improving cyber-security standards are not mutually exclusive objectives. Striking the right balance can be achieved by identifying those activities which could put sensitive data at risk, breach regulations, or create vulnerabilities caused by negligence or malicious intent.
The most effective next-generation threat monitoring systems utilise a data-driven approach to monitor how each user interacts with sensitive data, as opposed to focusing on their identity. This is then used to create a baseline from which anomalous behaviour can be detected should it deviate from an established pattern.
This data-driven approach employs analytics as the method for identifying risk factors as opposed to subjective interpretations of user behaviour that are inherently susceptible to bias. In addition, systems that detect and mitigate threats without revealing the identity of the user (until it becomes necessary) can prevent bias from impacting the validity and effectiveness of the overall monitoring process.
If further investigation is required, authorised security personnel can request additional, audited data access so that insider threats can be properly monitored within the boundaries of employee privacy rules.
As the need to address insider threats increases, more organisations will come under pressure to implement effective monitoring processes and technologies. In doing so, some will also allow bias to influence their decision-making, and whether this is a result of misjudgement or lack of awareness, they are running the very real risk of adding to their security concerns rather than eliminating insider threats.
In contrast, organisations that can strike an effective balance between effective threat monitoring and employee privacy will be well placed to optimise their security posture while also preserving compliance integrity, employee trust and positive company culture.
Chris Denbigh-White is CSO at Next DLP
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543