Skip to main content

Reducing data exfiltration by malicious insiders

Advice and recommendations for mitigating this type of insider behaviour.

Decorative image

This guidance can help organisations to reduce the likelihood of data exfiltration by malicious insiders. It's aimed at staff responsible for delivering insider risk mitigation programmes, including technical leaders, business delivery owners, senior line managers, and staff working in HR, data protection and legal departments.

This guidance provides examples of the methods malicious insiders have used or could use to exfiltrate data, and suggests technical measures that can be used to:

  • prevent data exfiltration
  • enable monitoring
  • carry out post-event audit

Note

Mitigations for data exfiltration should be one element within an overall framework of insider risk mitigation. This guidance assumes that organisations already have in place such a framework (such as NPSA's Insider Risk Mitigation Framework), and also procedures in place for managing incident response following data exfiltration (see NCSC's guidance on managing cyber incidents).


Note that:

  • You will need to interpret this guidance according to your organisation's own circumstances. This includes your use of trusted service providers, future technology developments, acquisitions, mergers and divestitures, and upgrades or modifications to existing technologies.
  • You should already have appropriate governance of insider risk mitigation, and have carried out essential activities including identifying critical assets. Without these it is difficult for organisations to make informed decisions about balancing technical controls with business processes, which is necessary for continued productivity.



This guidance has been collaboratively produced by NPSA, NCSC and SITIIE (Securing IT against Insiders Information Exchange).