Home  ›  Glossary  ›  Insider Threat

What is insider threat?

Insider threat is the risk that someone with legitimate access to an organization's systems, such as an employee, former employee, contractor or service provider, causes harm with that access. The harm can be deliberate, like sabotage or theft, or accidental, like deleting the wrong volume. CISA's definition covers both.

Why insider threat matters for backup and recovery

Backup administrators hold some of the most destructive permissions in IT. From the backup console they can delete restore points, shorten retention, disable jobs or change encryption settings. All of these are routine maintenance tasks, which is exactly why misuse of them is hard to spot.

An insider also skips the steps an outside attacker has to take. There is no break-in to detect and no password to steal. The person already knows where the repository is, how long data is kept and which copies matter most. When the only thing protecting backups is that administrators are trusted, one administrator can end the organization's ability to recover.

Types of insider threat

TypeWhat it looks like around backups
AccidentalThe wrong retention policy applied to a job, or a repository removed during a cleanup
NegligentShared administrator passwords, or MFA switched off on the backup console to save time
MaliciousRestore points deleted by an administrator before leaving the company
Third-partyA contractor or MSP technician account with rights across many systems or many clients
CompromisedA legitimate account used by an outsider after credential theft, which looks identical in the logs

For recovery, the motive matters less than the result. A deleted backup chain is gone whether the cause was a typo, a grudge or a stolen password.

What insider threat means for a small IT team

In a mid-sized organization, two or three people often run production, virtualization and backup together, with no one reviewing anyone else's changes. Separation of duties, the classic control for insider risk, is hard to staff. In many environments this leaves one person able to delete production data and also remove the backups that would bring it back.

MSPs face the same issue at a larger scale. A technician account that manages backup for dozens of clients is an insider in every one of them, and a departing or compromised technician affects all of those clients at once. The administrative blast radius of that one account is the whole client base.

The practical consequence is that the storage ends up carrying part of the control that the org chart cannot. When retention is enforced by the storage and no administrator can shorten it, insider damage stops at production and at recent data not yet locked; the protected restore points remain. When retention is only a setting in the backup software, it lasts exactly as long as every administrator leaves it alone. Logs kept out of reach of the people they record matter as well, because after an incident someone has to establish who did what, for management, insurers and sometimes courts.

How insider threat relates to ARTESCA

With S3 Object Lock in compliance mode, ARTESCA keeps a locked object version in place until its retain-until date whichever user asks for its deletion, including the root account. Governance mode offers less protection against insiders: any identity holding s3:BypassGovernanceRetention that sends x-amz-bypass-governance-retention:true can remove the lock. Object Lock requires versioning, and retention ends on the retain-until date.

The ARTESCA Cyber Guarantee covers external cyberattacks and lists unauthorized acts by approved personnel among its exclusions, so deliberate insider actions fall outside it. For investigating those actions, ARTESCA audit logs can be forwarded to Splunk, Graylog, Elasticsearch or syslog, beyond the reach of the storage administrators whose actions they record.

Related terms