Hello. In the previous lesson, you classified threat sources as internal or external, and intentional or accidental. You also learned that a trusted employee account may be misused by an external attacker, so the username in a log is not automatically proof of employee wrongdoing.
This lesson focuses on the harmful actions an employee or other insider can take: sabotage, theft, unauthorised access, and accidental disclosure. By the end, you should be able to explain the chain from an action, to the asset affected, to the resulting impact on the organisation. That cause-and-effect explanation is what moves a BTEC answer beyond simply naming a threat.
From an insider action to organisational harm
An insider is not only a permanent employee. It can include a manager, administrator, temporary worker, contractor, supplier, or former employee who has had authorised access or useful internal knowledge.
The key point is that an insider already has some level of trust, access, or knowledge. This can make their actions particularly damaging:
- They may know where valuable files, backups, systems, or physical assets are.
- They may already have a valid account or access card.
- Their activity can look more legitimate than an outsider’s.
- They may know which security procedures are weak or ignored.
The National Protective Security Authority (NPSA) describes an insider event as activity by an insider, intentional or unintentional, that could cause harm or loss. Its categories are useful because they show that insider risk is broader than “an angry employee stealing data.”
Setting the foundations: Five principles for a shared approach to Insider Risk
Read the NPSA guidance to establish precise meanings of insider, insider event, and insider risk. It then maps the main ways an insider can harm an organisation, including theft, access facilitation, and sabotage.
In “Principle 1: Adopting a shared language,” read the core definitions. Then, in “Principle 2: Broadening our understanding of potential insider threats,” read the five event categories, focusing especially on information theft, unauthorised access, and sabotage. Finally, in “Principle 3: Considering the ‘spectrum of intent’: unintentional to intentional insider activity,” read the explanation of unwitting and negligent insiders. Notice that knowingly breaking a rule is not always the same as intending organisational harm.

When explaining harm, connect the action to the security objective affected:
| Security objective | Meaning | Example insider harm |
|---|---|---|
| Confidentiality | Information is available only to authorised people. | An employee copies customer records or emails them to the wrong recipient. |
| Integrity | Information and systems remain accurate and trustworthy. | An employee alters payroll details, deletes records, or changes system settings. |
| Availability | Systems and data are available when needed. | An administrator disables a server, deletes files, or damages equipment. |
One action can affect more than one objective. For example, a malicious administrator who deletes a database harms availability immediately, may harm integrity if restored data is incomplete, and could also expose confidentiality if they copied the database first.
Sabotage: deliberately damaging operations, systems, or reputation
Employee sabotage is a deliberate attempt to damage, disrupt, or undermine an organisation. The motive might be revenge, anger after disciplinary action, ideological disagreement, financial gain, or an attempt to hide another offence.
Sabotage can be physical, electronic, or reputational.
Physical sabotage
An employee might damage a server, disconnect network equipment, cut cables, destroy stock, or interfere with a building-access system.
The immediate impact is often loss of availability: staff cannot access systems, customers cannot use services, and production or teaching may stop. The organisation may then face repair costs, lost sales, missed deadlines, and overtime payments. If safety systems are affected, the consequences can extend to physical safety and legal responsibility.
Electronic sabotage
Electronic sabotage is especially relevant to IT systems. Examples include:
- deliberately deleting files or backups;
- changing network settings to stop systems communicating;
- disabling antivirus software or monitoring tools;
- encrypting internal files maliciously;
- modifying financial, stock, or customer records;
- creating hidden administrator accounts for later misuse.
A key distinction-level point is that deleted data is not always simply “lost.” If the attacker also deletes backups or alters logs, recovery becomes slower and investigators may struggle to establish exactly what happened. That increases downtime, recovery costs, and uncertainty about whether restored data can be trusted.
Reputational sabotage
An insider may intentionally spread false information about an organisation, post damaging material, leak private internal communications, or impersonate the organisation online.
This may not directly disable a computer system, but it can still cause serious harm. Customers may lose confidence, partners may reconsider contracts, and staff morale may fall. A reputational attack can therefore create financial loss even where no money was stolen directly.
A strong explanation follows this pattern:
A disgruntled systems administrator deliberately deletes the organisation’s booking database. This is electronic sabotage because the action is intended to disrupt operations. It harms availability because staff and customers cannot access bookings, and it may cause financial loss through cancelled appointments, recovery work, and reputational damage if customers view the organisation as unreliable.
Theft: taking assets or copying valuable information
Theft can involve a physical asset, such as a laptop or phone, but in cybersecurity scenarios it often involves information. An employee might copy customer records, source code, designs, product plans, price lists, examination materials, or business strategy documents.
A useful distinction is that digital theft does not always remove the original file. A staff member can copy intellectual property to a personal drive while the organisation still has its own copy. The immediate security failure is therefore usually a loss of confidentiality, rather than availability.
However, the longer-term consequences can be severe:
- A competitor could gain an advantage from stolen designs, source code, or strategy.
- Customer information could be sold or used for fraud.
- The organisation may lose future revenue from intellectual property it developed.
- Clients may no longer trust the organisation to protect confidential information.
- Investigating the theft may require legal, technical, and staff time.
For instance, an engineer who downloads confidential product designs before joining a competitor may cause a loss of intellectual property. The competitor could produce a similar product more quickly, reducing the original organisation’s competitive advantage. The harm is not limited to the value of the files themselves; it includes lost future income and weakened market position.
Theft can also be part of a larger attack. An employee who steals administrator credentials or an access card may enable later unauthorised access, fraud, or sabotage.
Unauthorised access: exceeding permission or enabling someone else
Unauthorised access occurs when someone accesses a system, account, building, file, or service without permission. An employee can be involved in two main ways.
First, they may exceed their own authorised access. A valid staff account does not give a person permission to view every record in the organisation. For example:
- A receptionist accesses medical records out of curiosity.
- A payroll employee looks up a colleague’s bank details without a work reason.
- An administrator uses privileged access to read confidential emails.
- A staff member uses another employee’s account to bypass restrictions.
Second, an employee may facilitate another person’s access. This could include:
- sharing a password with a colleague or contractor;
- lending an access card;
- allowing an unknown person to follow them through a secure door;
- creating an account for someone who has not been approved;
- leaving a logged-in device unattended for another person to use.
The employee may intend to help someone complete work quickly, rather than intend harm. But the access is still unauthorised if it bypasses the organisation’s approval process. This is why security depends on both technology and staff behaviour.
Unauthorised access is dangerous because it can be the starting point for further harm. Once someone has access, they might:
- view or copy confidential information;
- change records or system configurations;
- install malware;
- commit fraud;
- delete data or disrupt services.
So, unauthorised access is sometimes the incident itself, but it can also be the route that makes theft or sabotage possible.
Consider this answer:
An employee shares a departmental password with an unapproved contractor so that work can be completed more quickly. This facilitates unauthorised access because the contractor has not been granted an individual account or approved permissions. The contractor could view confidential documents, alter files, or install malicious software. The organisation would also struggle to identify who performed each action because several people used the same credentials.
That final point about accountability is valuable: shared accounts weaken audit trails, making investigation much harder.
Accidental disclosure: mistakes can still become major incidents
An accidental disclosure happens when an employee reveals information to an unauthorised person without intending to do so. The intent is accidental, but the impact can still be high.
Common examples include:
- sending an email attachment to the wrong recipient;
- using email auto-complete and selecting the wrong contact;
- placing confidential files in a publicly accessible cloud folder;
- uploading passwords, access keys, or source code to a public repository;
- losing an unencrypted laptop or USB drive;
- discussing confidential information where others can hear it;
- printing sensitive documents and leaving them on a shared printer.
The ICO defines a personal data breach broadly. It can include accidental or deliberate loss, destruction, alteration, unauthorised disclosure, or access involving personal data.
Personal data breaches: a guide
Read this ICO guidance for the UK definition of a personal data breach and realistic examples of accidental disclosure, unauthorised access, and lost or stolen devices. Focus on how the seriousness of a breach depends on the likely impact on affected people.
In “What is a personal data breach?”, read the definition and examples. In “Risk-assessing data breaches,” read the individual consequences, including identity theft, fraud, financial loss, and distress. Then find “When do we need to tell individuals about a breach?” and read the hospital, university, and medical-record examples, beginning with the hospital example. Compare why sensitivity, scale, and recovery affect the seriousness of an incident.
The seriousness of accidental disclosure is not determined by whether the employee made a mistake. It depends on factors such as:
- Sensitivity: Medical, financial, safeguarding, and identity data are more harmful if exposed.
- Scale: A mistake involving one email address is different from a public file containing thousands of records.
- Recipient: A trusted professional who deletes a wrongly received file creates less ongoing risk than an unknown public audience.
- Protection: Encrypted data may be less usable to a person who finds a lost device.
- Speed of reporting and containment: Quickly removing access, recalling an email where possible, or changing exposed credentials can reduce harm.
The following short example shows how a small technical mistake can rapidly lead to substantial cost.
The Insider Threat | Security Detail
Watch Red Hat’s “The Insider Threat | Security Detail” for an example of accidental exposure of cloud credentials and why staff must report mistakes promptly rather than hide them.
Watch the accidental credentials, where cloud access keys are mistakenly uploaded to a public code repository and quickly exploited. Then watch the reporting culture. Focus on the link between a human error, the short opportunity for attackers, financial impact, and the importance of early reporting.
In that example, the employee did not intend to cause harm. Nevertheless, exposed cloud credentials enabled criminals to use the organisation’s computing resources, leading to very large bills. This shows why “accidental” describes intent, not severity.
Writing a distinction-level explanation
For each insider scenario, avoid stopping at a label such as “this is theft.” Build a clear chain:
Here is how that works in a single organisation, Northbridge Design Ltd.
| Employee action | Immediate security harm | Wider organisational impact |
|---|---|---|
| A departing designer copies product plans to a personal account. | Confidentiality of intellectual property is lost. | A competitor may obtain a market advantage; Northbridge may lose future sales and client trust. |
| A disgruntled administrator deletes shared files and backup copies. | Availability is lost; integrity may be uncertain after recovery. | Work stops, recovery costs increase, deadlines are missed, and customers may view the business as unreliable. |
| An employee gives a visitor their access card. | An unauthorised person gains physical access. | The visitor could steal equipment, access devices, install malware, or reach restricted areas without a clear audit trail. |
| A finance worker emails payroll data to the wrong external address. | Confidentiality of personal and financial data is lost. | Employees may face fraud or distress; the organisation faces investigation, response costs, and reputational damage. |
Notice the careful language. A high-quality response does not claim that every breach automatically leads to a fine, fraud, or business closure. Instead, it explains plausible consequences using words such as could, may, and is likely to, supported by scenario details.
Also keep the categories separate while recognising overlap:
- An employee may commit theft by copying data after gaining unauthorised access.
- An employee may facilitate unauthorised access, allowing an outsider to carry out sabotage.
- An accidental disclosure may give criminals the information needed for later fraud.
- A malicious employee may steal data first, then delete it to hide evidence.
This is why an incident can have more than one category. Your job is to identify the primary actions and explain how they connect.
Key takeaways
- Sabotage is deliberate damage or disruption to physical assets, IT systems, operations, or reputation. It commonly harms availability and integrity.
- Theft may involve devices, money, or copied information. Information theft often harms confidentiality and can destroy an organisation’s competitive advantage.
- Unauthorised access includes employees exceeding their own permissions or enabling another person to bypass access controls. It can lead to theft, fraud, malware, and sabotage.
- Accidental disclosure is unintentional, but it can still expose sensitive personal or commercial data and cause major financial, legal, operational, and reputational harm.
- For stronger exam answers, explain the full chain: action, asset, confidentiality/integrity/availability effect, and realistic organisational consequence.
- Intent affects how an event is classified, but it does not determine how serious its outcome may be.
Next, you will identify unsafe staff practices and weak organisational security measures that make these insider events more likely.
Can't find a good explanation? Sign up and we'll make it for you
Sign up