Insider risk, measured
The quietest breach looks like an ordinary day of work.
A manager hands in notice, and over the last two weeks quietly walks out with the client list - one legitimate download at a time. No malware runs, no rule fires, and every event lands in a log nobody is reading. 1Security learns what normal looks like for every person, app and AI agent - and catches the slight variation that isn't.
- $17.4Maverage yearly cost of insider risk (Ponemon, 2025)
- 81 daysaverage time to contain an insider incident
- 1 in 3breaches involve an internal actor (Verizon, 2024)
The problem
Noise or silence - today's tooling fails both ways.
The scenario every security team quietly carries: someone hands in notice, and through the notice period reads four times their usual volume - client lists, pricing, the folder for the deal they ran. Every single event is legitimate. Their account, their permissions, files they were always allowed to open. There is nothing to detect - except the amount.
Detection built on rules fails this from both ends. Tuned sensitive, it drowns you: hundreds of alerts a day until the team stops reading them, and the one that mattered scrolls past unread. Tuned quiet, it simply never speaks. And from the outside the two failures are indistinguishable - both look like a screen with nothing on it.
In between sit the delicate cases that fall outside normal work without ever breaking a rule: the manager collecting board files before an exit, the admin reading a mailbox they had never touched, the agent suddenly crawling a finance site. "Have we been breached by one of our own?" is a question most stacks cannot even begin to answer.
The two black boxes
Why you can't answer it today.
Two decisions in your stack were made where you cannot see them: what deserves your attention, and who can reach what. An insider walks out between the two.
The threshold someone else picked
Anomaly detection usually ships as a black box: the vendor set the alert line, and you can neither see it nor move it. Too low, and the queue turns to noise; too high, and it never speaks - and you have no way of knowing what it decided not to tell you.
The evidence that was never kept
Whatever falls below that hidden line is discarded, not stored. When suspicion arrives later - a resignation, a tip, a competitor holding your pricing - the investigation needs the weak signals from the weeks before, and there is nothing to read. "Did we miss something?" has no data to run on.
The access nobody can map
Direct grants, sharing links, nested groups, broken inheritance: what one person could actually reach is a graph no admin console renders. So "what could they have taken?" costs a week of guesswork - usually answered after the notice period has ended.
The answer
Measure everything. Alert at the level you choose.
1Security splits the hidden decision in two. What is unusual is measured and always recorded. What deserves an alert is a line you own - and you see the effect of moving it immediately, on your real history.
- 01
A normal day, learned for every person, app and agent
Every detector and every identity learns its own normal: today's count against its own trailing 30-day median. Twelve a day becoming two thousand is an anomaly whatever the cause - a leaver copying the CRM export, a misfired automation, a token in the wrong hands.
- 02
Nothing below the line is thrown away
Every meaningful deviation down to 2 sigma is kept - alerted or not. "Have we been breached by a manager?" becomes an investigation instead of a shrug: lower the line, filter to the notice period, and read what was already recorded.
- 03
One dial, and the answer in view
The alert line sits in the open at the top of the screen. Move it and your real history re-classifies on the spot - no shadow mode, no quarter of tuning. A hospital drags it strict; a startup relaxes it; both run the same product with the dial in a different place.
The second box, opened
And when it fires: what could they have taken?
The baseline tells you the activity broke the pattern. The permission graph tells you the blast radius: every file, site and mailbox that account could reach - direct grants, sharing links, groups, inheritance - resolved in minutes rather than reconstructed over a week. The two answers arrive together: what they did that was unusual, and what they could reach while they did it.
The response
Watch closer exactly when it matters.
An employee resigns? Lower their personal alert line for thirty days, with a reason and an expiry - detection tightens around one person for exactly as long as the risk lasts, and the rest of the queue stays quiet. A noisy service account gets the opposite: muted for a week, on the record.
When a finding needs action, 1Security carries it there: revoke the access, expire the links, sever the sessions - through automations with grace periods and review queues, so nothing irreversible happens without a human deciding it should. And until you deliberately consent to write access, everything runs read-only.
Proof and deployment
Counted, not promised.
No agents to deploy, no premium add-on, no tuning engagement. Connect read-only in the morning; baselines start learning the same day, and detection goes live on your history in two weeks.
- 14 daysfrom connecting to a working baseline - no tuning quarter
- 2 sigmaeverything above it is recorded, alerted or not
- Instantmove the alert line, history re-answers on the spot
- Same dayfrom read-only consent to first findings
The quietest breach looks like an ordinary day of work.
See what normal looks like for every person, app and AI agent in your tenant - and the slight variations that are not.
Or keep assuming the leavers took nothing.