Female employee holding a laptop while standing by large windows overlooking a modern office.

Insider Threat Detection: The Missing Part of Your Human Risk Strategy

Published on 01.09.20265 min read

Most SMB/mid-market IT teams already have a human risk strategy, even if they'd never call it that. Security awareness training, phishing simulations, policy management, reporting workflows: all of it exists to stop an employee's mistake from becoming a breach before someone clicks the wrong link or hands over a password.

That entire strategy is built around risk arriving from outside the business. It rarely covers what happens once someone is already inside, using an account that should be there.

"That's not a risk we have"

Ask most IT directors at a 200-person company about insider threat and the instinct is to file it under enterprise problems: banks, defence contractors, organisations with something worth stealing on a large scale. It doesn't feel like a mid-market risk.

But the data says otherwise. 77% of organisations experienced insider-related data loss in the past 18 months, and the profile of the average case looks nothing like corporate espionage[1]. In non-enterprise organisations it can look like:

  • A departing employee downloading files before their last day.

  • A compromised account accessing systems it's always had access to.

  • Someone connecting an unauthorised AI tool that quietly scans through SharePoint.

  • A document forwarded to a personal inbox to finish over the weekend.

None of it looks malicious. It looks like someone doing their job.

"The tools for this aren't built for us"

The second assumption is more accurate, and it's the one that explains the inaction. Most insider threat tooling was built for organisations with a security team behind it: analysts to label sensitive data, write detection rules per department, tune thresholds, and investigate what gets flagged. That's a real project, requiring setup, configuration and ongoing investigation before it becomes useful, and it needs headcount most mid-market IT teams don't have.

So, the tooling is avoided, not because the risk isn't believed, but because turning it on looks like a second job nobody has time for. 72% of security leaders admit they lack full visibility into how users interact with sensitive data across their own environment[2].

The problem isn't necessarily that organisations don't understand the risk. It's that closing that visibility gap has traditionally required more time and resource than a lean IT team can spare.

What "doing nothing" costs

Containment is the single largest cost driver in insider risk incidents, averaging $247,587 each, and the average incident takes 67 days to contain[3]. The longer unusual activity goes undetected, the more it costs to work out what happened, what was accessed, and whether anything else was touched. Most of that cost comes from negligence, not malice: well-meaning employees moving too fast or sharing something they shouldn't, not deliberate wrongdoing[4]

A sales director syncing a client folder to a personal cloud account to catch up on work over the weekend, then forgetting to remove it. A finance employee forwarding a sensitive document to their personal inbox because it was faster than the approved process. Neither looks suspicious at the time. Both can go unnoticed for weeks, because nobody is monitoring for the moment a legitimate account starts behaving differently.

Detection that doesn't add a second job

This is where the assumption about tooling stops being accurate. Presence from Pistachio closes that gap without asking your team to run a security operation to do it.

  • You get told, not asked to look. Presence learns what normal looks like for every user and sends a contextual alert when something breaks the pattern. Your team reacts to a specific alert instead of hunting through logs to see if anything looks wrong.

  • No rules, no labelling, no analyst. There's nothing to configure per department and nothing to maintain as roles change. The behavioural baseline updates itself.

  • Deploys in under 10 minutes. Connects directly to Microsoft Entra ID, with no agents or months of setup before it starts working.

  • Covers where the data lives. Monitors activity across Microsoft 365, including SharePoint and OneDrive.

  • Privacy-first by design. Detection focuses on behaviour patterns, not email content or productivity.

"Presence automatically detects suspicious behaviour and gives us the visibility we need without constant manual oversight. Within the first few weeks we were already seeing alerts that would have otherwise gone unnoticed," said Carrie Sheen, IT Operations Director at Auxo Talent.

The other part of the strategy

Training your people to spot a phishing email is one part of a human risk strategy. Knowing when one of those same accounts starts acting differently, whether that's an attacker who's already in or an employee making a mistake on their way out, is another part most IT teams have never addressed. Not because they don't see the risk, but because until now, addressing it meant taking on work they didn't have the time for.

See how Presence closes that gap. Email contact@pistachioapp.com to book your 15-minute demo.

Anyone can fall for a phishing scam.

That’s the point of Pistachio’s approach to hands-on learning over snooze-worthy training videos.

Activity overview of user