Insider risk, measured

The quietest breach looks like an ordinary day of work.

A manager hands in notice, and over the last two weeks quietly walks out with the client list - one legitimate download at a time. No malware runs, no rule fires, and every event lands in a log nobody is reading. 1Security learns what normal looks like for every person, app and AI agent - and catches the slight variation that isn't.

  • $17.4M
    average yearly cost of insider risk (Ponemon, 2025)
  • 81 days
    average time to contain an insider incident
  • 1 in 3
    breaches involve an internal actor (Verizon, 2024)

The problem

Noise or silence - today's tooling fails both ways.

The scenario every security team quietly carries: someone hands in notice, and through the notice period reads four times their usual volume - client lists, pricing, the folder for the deal they ran. Every single event is legitimate. Their account, their permissions, files they were always allowed to open. There is nothing to detect - except the amount.

Detection built on rules fails this from both ends. Tuned sensitive, it drowns you: hundreds of alerts a day until the team stops reading them, and the one that mattered scrolls past unread. Tuned quiet, it simply never speaks. And from the outside the two failures are indistinguishable - both look like a screen with nothing on it.

In between sit the delicate cases that fall outside normal work without ever breaking a rule: the manager collecting board files before an exit, the admin reading a mailbox they had never touched, the agent suddenly crawling a finance site. "Have we been breached by one of our own?" is a question most stacks cannot even begin to answer.

The two black boxes

Why you can't answer it today.

Two decisions in your stack were made where you cannot see them: what deserves your attention, and who can reach what. An insider walks out between the two.

  • The threshold someone else picked

    Anomaly detection usually ships as a black box: the vendor set the alert line, and you can neither see it nor move it. Too low, and the queue turns to noise; too high, and it never speaks - and you have no way of knowing what it decided not to tell you.

  • The evidence that was never kept

    Whatever falls below that hidden line is discarded, not stored. When suspicion arrives later - a resignation, a tip, a competitor holding your pricing - the investigation needs the weak signals from the weeks before, and there is nothing to read. "Did we miss something?" has no data to run on.

  • The access nobody can map

    Direct grants, sharing links, nested groups, broken inheritance: what one person could actually reach is a graph no admin console renders. So "what could they have taken?" costs a week of guesswork - usually answered after the notice period has ended.

The answer

Measure everything. Alert at the level you choose.

1Security splits the hidden decision in two. What is unusual is measured and always recorded. What deserves an alert is a line you own - and you see the effect of moving it immediately, on your real history.

  1. 01

    A normal day, learned for every person, app and agent

    Every detector and every identity learns its own normal: today's count against its own trailing 30-day median. Twelve a day becoming two thousand is an anomaly whatever the cause - a leaver copying the CRM export, a misfired automation, a token in the wrong hands.

  2. 02

    Nothing below the line is thrown away

    Every meaningful deviation down to 2 sigma is kept - alerted or not. "Have we been breached by a manager?" becomes an investigation instead of a shrug: lower the line, filter to the notice period, and read what was already recorded.

  3. 03

    One dial, and the answer in view

    The alert line sits in the open at the top of the screen. Move it and your real history re-classifies on the spot - no shadow mode, no quarter of tuning. A hospital drags it strict; a startup relaxes it; both run the same product with the dial in a different place.

The second box, opened

And when it fires: what could they have taken?

The baseline tells you the activity broke the pattern. The permission graph tells you the blast radius: every file, site and mailbox that account could reach - direct grants, sharing links, groups, inheritance - resolved in minutes rather than reconstructed over a week. The two answers arrive together: what they did that was unusual, and what they could reach while they did it.

The response

Watch closer exactly when it matters.

An employee resigns? Lower their personal alert line for thirty days, with a reason and an expiry - detection tightens around one person for exactly as long as the risk lasts, and the rest of the queue stays quiet. A noisy service account gets the opposite: muted for a week, on the record.

When a finding needs action, 1Security carries it there: revoke the access, expire the links, sever the sessions - through automations with grace periods and review queues, so nothing irreversible happens without a human deciding it should. And until you deliberately consent to write access, everything runs read-only.

Proof and deployment

Counted, not promised.

No agents to deploy, no premium add-on, no tuning engagement. Connect read-only in the morning; baselines start learning the same day, and detection goes live on your history in two weeks.

  • 14 days
    from connecting to a working baseline - no tuning quarter
  • 2 sigma
    everything above it is recorded, alerted or not
  • Instant
    move the alert line, history re-answers on the spot
  • Same day
    from read-only consent to first findings

The quietest breach looks like an ordinary day of work.

See what normal looks like for every person, app and AI agent in your tenant - and the slight variations that are not.

Or keep assuming the leavers took nothing.