Finding Needles in a Haystack: Effective Indicators of Insider Threat

It’s easy to get overwhelmed with system telemetry as well as social and behavior indicators when it comes to identifying insider threat. In practice, what are some of the most effective indicators that you have used to identify insider threat, and do you focus those indicators on specific events (employee onboarding, contractor offboarding, etc.)?

Learning Objectives:
1: Learn which indicators of insider threat are most effective for detection.
2: Learn which employement events to focus on for insider threat detection.
3: Discuss how you negotiate and handle sensitive data for some indicators.
Talhah Mir


Principal PM Manager, Microsoft

