In the Netherlands, insider threat detection rarely fails due to technical issues and almost always due to organizational ones. The security team notices that an account is downloading 400 files at 1:30 a.m., but doesn’t know that the employee was told last week that his contract would not be renewed. HR does know this but has no idea that it’s relevant. Verizon’s 2026 Data Breach Investigations Report shows that internal actors are involved in a significant proportion of data breaches, with particularly high rates in sectors such as the public sector, where that share approaches 44 percent. The majority of these incidents are not acts of sabotage but rather mistakes or misjudgments.
The distinction that each program must make
Insider threat detection begins with distinguishing between three types of insiders, each of which requires a different response. The unintentional insider makes a mistake: sends a file to the wrong address, enters customer data into an AI tool, or leaves a laptop on a train. The negligent insider deliberately circumvents rules because they slow down work, without any malicious intent. The malicious insider acts intentionally, usually out of financial motive or resentment.
That balance is skewed, and that determines where insider threat detection should focus its attention. The vast majority of incidents fall into the first two categories, while virtually all attention and tools are directed toward the third. An insider threat detection program that starts with the assumption of malicious intent therefore focuses on the smallest group and, in the process, undermines the trust you need to address the other two categories.
The practical implication: the greatest gains come from better processes and clearer agreements, not from monitoring software. This is the same trade-off we described in our article on structurally improving information security, where training consistently yields greater results than an additional product.
What Dutch law requires you to do before you start
This is where many organizations go wrong when it comes to insider threat detection. Insider threat detection directly involves employee tracking systems, which are strictly regulated in the Netherlands. In its guidance for works councils, the Dutch Data Protection Authority explains that an employer must obtain the works council’s consent for any policy aimed at monitoring or controlling the presence, behavior, or performance of employees. A system capable of doing so already counts toward this requirement, even if you are not yet using it for that purpose in practice.
That criterion is broader than most teams working on insider threat detection realize. It includes logging who accesses which sensitive files. It includes software that records email traffic or internet usage. It includes a system that logs access via a badge. Anyone who sets up a detection program without involving the Works Council is building a legal problem right into the foundation.
Added to this is the DPIA requirement. The AP states that the large-scale or systematic processing of personal data to monitor employee activities is included on the list of processing activities for which a data protection impact assessment is mandatory. Covert monitoring is also subject to strict limits: systematic covert observation is not permitted, and occasional covert monitoring is allowed only in cases of reasonable suspicion, after other means have been exhausted, and where there is a compelling business interest.
Another provision that is rarely taken into account: a performance evaluation may not be based solely on data from a monitoring system, and employees must be given the opportunity to respond to the results shortly after the observation, with their perspective included in the results. For insider threat detection, this means that an alert may never be directly entered into an employee’s file without giving the employee a chance to respond.
The Protocol: What HR Reports to Security—and What It Doesn't
The solution for insider threat detection is not to grant shared access to each other’s systems. HR should not be given access to the SIEM dashboard, and the security team should not be granted access to performance review files. What does work is a narrow, predefined set of events in which HR flags an issue without providing substantive justification.
Four reporting points are sufficient for effective insider threat detection. An employee has given notice of resignation or submitted a resignation letter. An employee is involved in a formal escalation process. A job reassignment results in a change in access rights. And an external or temporary employee is nearing the end of their assignment. In all four cases, HR simply reports that the situation is occurring and when it will take effect, not why.
The latter is the key point. Security does not need to know that someone is in conflict with their manager; security only needs to know that increased attention to this account is justified during a defined period. This ensures that data processing remains proportionate—as explicitly required by the AP—and allows you to maintain effective insider threat detection without fostering a culture of surveillance. Document this in a protocol that you coordinate with the Works Council, as we also recommend for effective security processes in general.
Off-boarding is where things usually go wrong
Ask any IT manager how long it takes to revoke all access for a departing employee, and you’ll immediately be testing the maturity of your insider threat detection—and the answer is rarely a specific number. It’s usually a story about the main systems being shut down the same day, followed by a long list of SaaS applications, shared accounts, API keys, and VPN profiles that no one has a clear overview of.
That loose end is the biggest concrete risk in insider threat detection—and at the same time, the easiest to resolve. An off-boarding checklist based on an up-to-date overview of all the systems to which an employee had access closes the gap within a day. This follows the same discipline as a structured onboarding plan, only in reverse, and it’s striking how many organizations have the former but not the latter.
When detecting insider threats, pay attention to the period between the notice of termination and the last day of work. That is the window during which a departing employee retains legitimate access to everything, even though their ties to the organization have already been severed. Data taken during this time is rarely done with malicious intent—it’s the customer list that someone finds useful for their new job. That’s a conversation HR should have at the time of resignation, not a detection issue.
The skills the security team needs for this
Detecting insider threats places different demands on analysts than external threats do. There is no malware, no suspicious connection to an unknown country, and no exploit attempt in the log. There is an authorized user performing authorized actions, but in a pattern that deviates from the norm. This requires analysts who know what normal usage looks like in their own environment and who can distinguish between an employee meeting a deadline and an employee emptying an archive.
That assessment skill can be learned. The SOC T1 + T2 Analyst training program lays the foundation for structured triage of such indicators, while the SOC T3 Analyst training program focuses on the investigation that follows when a pattern extends over weeks. If a case is heading toward labor law or criminal law consequences, evidence suddenly becomes crucial; the Cyber Forensics Expert training program teaches teams how to secure evidence in a way that will stand up to scrutiny later on.
Don’t underestimate the non-technical side either. The best way to reach the “unintentional insider” is through targeted training on what is and isn’t allowed when it comes to company data—something that Cyber Awareness Training focuses on. And keep your team’s workload in mind: a group already struggling with alert fatigue is less able to assess subtle behavioral cues than a well-rested team, no matter how good the protocol is.
Retention is the most cost-effective preventive measure
The uncomfortable truth about insider threat detection is that it’s merely treating the symptoms. Malicious insiders almost always emerge from a prolonged period of dissatisfaction: being passed over, seeing no prospects, or feeling unheard. Each of these factors can be influenced by HR policy, but not by detection. Organizations that take career paths seriously as a retention tool reduce the number of people falling into that category more effectively than any detection platform could.
The same applies to training as an employment benefit. An employee who feels that the organization is investing in him or her develops a different attitude toward that organization than someone who has been stuck in the same position for two years. We explored that logic in our article on training as an employment benefit. This isn’t just wishful thinking; it’s the most cost-effective form of risk mitigation available to HR.
Here's how to get started without building a surveillance device
A practical starting point for insider threat detection consists of four steps you can take within a quarter. Identify which data would actually cause damage if it were leaked, as this is typically a limited set and not everything. Work with HR to establish the four reporting points and coordinate the protocol with the employee representative body. Ensure the offboarding process is airtight and test it against a recent departure. And train the security team to assess unusual user behavior within your own environment.
Measurement is an integral part of insider threat detection, but make sure you’re measuring the right things: time to full access revocation, number of orphaned accounts, and turnaround time from an HR alert to a security response. Our article on meaningful cybersecurity KPIs explains how to set up such metrics without getting bogged down in meaningless numbers. Tools can support this, but without people to interpret the results, the same thing happens here as with SIEM investments without trained analysts: the dashboard is on, but no one is looking at it.
For the meeting with senior management, it helps to present insider risk as a business continuity issue rather than as a matter of mistrust toward staff—an approach we outlined in the “Bringing Security to Your Management Team” guide. You should also run through the scenario once with representatives from both disciplines present; our exercise playbook can be used for this, substituting an insider case for an external attack.
The page for employers explains how to build that analytical capacity using your current staff, from open-class to in-company programs. You’ll find the complete overview of course levels for all programs, including the comprehensive Cyber Security Specialist program for employees transitioning from IT management to a security role. Want to see how quickly your organization turns an HR signal into action? Check out the upcoming start dates or schedule an introductory meeting to discuss what’s right for your team.



