5.4.1. Insider Risk Management
💡 First Principle: Not every security risk comes from an outside attacker — insider risk management uses signals like unusual data access patterns, mass downloads before a resignation, or policy-violating file sharing to flag potentially risky insider behavior early, using pre-built policy templates tuned to common scenarios like data theft by departing employees.
Detection here deliberately uses pseudonymization by default for privacy — flagged users can be shown to investigators by role or pseudonym rather than name initially, with full identification reserved for confirmed cases requiring deeper investigation — balancing legitimate risk detection against employee privacy.
⚠️ Exam Trap: Insider risk management specifically targets risky behavior originating from within the organization (employees, contractors) using behavioral signals — this is distinct from external threat detection covered by the Defender product family in Phase 4.
Reflection Question: Why might insider risk management pseudonymize a flagged user's identity during the early stages of an investigation, rather than immediately revealing exactly who triggered the alert?