
There is one type of incident that no CEO wants to deal with, yet it is statistically almost inevitable: data theft from within the organization itself. We are not necessarily talking about the disgruntled employee who copies files before leaving, although that happens too. We are talking about a much broader spectrum that includes compromised credentials, unauthorized access by external contractors, and negligence with consequences equivalent to a deliberate attack, and also, yes, the intentional theft of intellectual property, customer data, or financial information.
The data framing this problem leaves no room for optimistic interpretations. According to the Insider Threat Report by Cybersecurity Insiders, 83% of organizations reported at least one insider attack in 2024. The Ponemon Institute estimates the average annual cost of insider threat-related incidents at $16.2 million per organization, a 40% increase since 2020. In Spain, the situation is no more reassuring: the average cost of a data breach for a medium-sized company is estimated at 3.7 million euros, including response costs, regulatory fines, and loss of customers, according to data from Cyber Safety.
What distinguishes organizations that overcome these incidents from those that do not is not having been immune to them. It is having had a clear protocol in place before they occurred.
When a data exfiltration is detected, the pressure on management is immediate and multidimensional. Technical, legal, communication, and business decisions must be made almost simultaneously, often with incomplete information and the clock ticking. Confusion during those first few hours can turn a manageable incident into a reputational and regulatory disaster.
The first principle is this: detection is not the start of the protocol. The protocol begins much earlier, in the preparation phase. However, if a breach is discovered without a pre-existing protocol in place, management's first priority must be to stop the incident, not to diagnose it.
Containing an incident means isolating affected systems, revoking compromised or suspicious access, and preserving evidence in its original state. This last point is critical and often mishandled: logs must not be deleted, affected systems must not be restarted without documenting their state, and audit files must not be altered before the forensic team has had access to them. Every technical action taken in the first few minutes can be decisive for the subsequent investigation, as well as for any legal or regulatory proceedings resulting from the incident.
The gold standard for incident management is the NIST (National Institute of Standards and Technology) framework, which structures the response into four stages: preparation, detection and analysis, containment and eradication, and post-incident recovery. The ISO/IEC 27035 standard, which governs information security incident management, establishes a similar structure and is the reference framework within the ISO 27001 ecosystem. In its updated version, Annex A 5.26 of ISO 27001:2022 introduces additional requirements that include threat containment and mitigation following the initial event, a crisis management procedure, identification of the exact cause of the incident, and communication to all relevant parties.
Before detailing the protocol, it is important to understand exactly what you are fighting. The insider threat does not have a single profile. CISA (the Cybersecurity and Infrastructure Security Agency) classifies insider threats into three broad categories: the malicious actor with legitimate access who acts with deliberate intent, the negligent employee whose actions create vulnerabilities that can be exploited by third parties, and the compromised insider, whose credentials have been captured by an external actor who uses them as a gateway.
This distinction is not merely academic; it has direct implications for how you should act. An employee who has sold credentials to a competitor requires an immediate legal response and discreet operational isolation so as not to alert the external actor using them. A negligent worker who has exposed customer data in a misconfigured shared folder, on the other hand, requires urgent technical correction and training, but not necessarily a criminal investigation. Confusing the two scenarios has consequences.
What unites them is the risk vector: authorized access. Unlike an external attack that must bypass perimeter defenses, the insider threat operates with valid credentials, within systems for which they have permissions, and at times and from locations that do not trigger basic alerts. That is why the Verizon Data Breach Investigations Report of 2024 identifies the human element as a factor in 68% of security breaches, and privilege abuse as responsible for 15% of documented breach patterns.
The detection of an internal data theft can occur through multiple channels: an alert from the SIEM (Security Information and Event Management), a notification from a third party that has received data they should not have, an anomaly detected in access logs , or even a report from another employee. The first action by management should not be investigation, but classification.
What is the nature of the compromised data? Does it include personal data of customers, employees, or third parties? Does it affect intellectual property, financial information, or trade secrets? Are there indications that the access was deliberate or could it be accidental? Is the exfiltrator still active in the systems? These questions must be answered, even if only preliminarily, before activating any response protocol, because the response will differ depending on the answers.
Classification also determines which regulatory clock starts ticking. And this is where one of the most critical obligations for any company operating in Spain or processing data of European citizens comes into play.
Article 33 of the General Data Protection Regulation (GDPR) establishes that any security breach that poses a risk to the rights and freedoms of natural persons must be notified to the competent supervisory authority within a maximum period of 72 hours from the moment the organization becomes aware of it. In Spain, that authority is the Spanish Data Protection Agency (AEPD).
This deadline is fixed and begins the moment the company has reasonable knowledge of the incident, not when it actually occurred. This distinction is important: if the technical department receives an ambiguous alert, there is a reasonable margin for verification. But as soon as there is reasonable certainty that personal data has been accessed, altered, lost, or disclosed without authorization, the 72-hour clock starts.
The consequences of non-compliance are significant. The GDPR establishes fines of up to 10 million euros or 2% of annual global turnover for failing to notify on time, and the AEPD takes into account aggravating factors such as lack of cooperation, absence of prior security measures, or manifest negligence. According to its 2024 Annual Report, published in May 2025, the agency opened 30 sanctioning or warning proceedings linked to breaches, with fines totaling 13.18 million euros, 70% of which fell on SMEs and freelancers..
The initial notification to the AEPD does not require complete information. If all data is not available within the 72-hour window, the GDPR allows for a phased notification: first with the available information, and then with the remainder. What is not acceptable is waiting to have complete information if that means exceeding the deadline.
Additionally, when the incident poses a high risk to those affected—which includes practically any breach involving financial or health data, or data that allows for the direct identification of individuals—Article 34 of the GDPR also requires notifying the affected parties directly, without undue delay and in clear language.
For companies in sectors regulated under the NIS2 Directive (which expanded its scope as of October 2024 to 18 sectors, covering tens of thousands of entities in the EU), there is also a different notification cascade: an early warning to INCIBE-CERT within 24 hours, a detailed notification within 72 hours, and a final report within one month.
Once the incident is contained and the regulatory clock is ticking, forensic investigation is the operational core of the response.This is an area where management must resist the temptation to improvise or informally delegate to the IT team without a proper structure.
Forensic investigation into an insider threat has its own unique characteristics. Unlike an external attack, where forensic artifacts typically point outside the perimeter, here the indicators are intertwined with legitimate activity. The logs of the exfiltrator show valid authentications. File movements were performed with real permissions. The communication channels used to extract data (corporate email, USB drives, cloud services, and even printers) are the same ones any employee uses in their daily work.
Forensic analysis must document: what data was accessed or copied and in what volume, from which devices and locations, during what time frames, to which destinations (internal or external), and whether there were any deletion or alteration actions prior to detection. The chain of custody for evidence must be maintained in a way that is valid in legal proceedings should it reach that point. Recognized forensic tools such as Volatility for memory analysis or SIEM solutions with event correlation capabilities are the technical standard for these types of investigations.
ISO 27001:2022, in Annex A Control 5.28, establishes the requirements for forensic analysis as part of the incident management cycle. The fundamental principle is that forensic analysis must be performed without compromising the integrity of the evidence.
While the forensic investigation is underway, management must simultaneously handle three fronts that have their own logic but must be coordinated.
The legal front requires the immediate intervention of the legal department or external advisors specializing in cybersecurity and data protection. Implications under the GDPR (already activated in phase 2) must be evaluated, as well as the potential criminal liability of the perpetrator if the theft was deliberate, the possibility of civil action to recover damages, and contractual obligations to clients or partners whose data may have been compromised.
The Human Resources front requires determining, in coordination with legal, how to handle those potentially involved. If a suspect is identified, the internal investigation strategy must be designed so as not to compromise evidence or create labor-related liabilities. The interview with the involved employee, if conducted, must take place at the appropriate time in the process, with legal counsel present, and with full awareness that their statements may be relevant in subsequent proceedings.
The communications front is the most visible and the most difficult to manage. Management must define who communicates, what is communicated, when, and to whom. Affected clients, shareholders, the board of directors, employees, the media, and regulatory authorities have different information needs and different timeframes. A communication error—saying too much too soon, too little, or being inconsistent—can significantly aggravate reputational damage.
ISO 27001 establishes that information security incidents must be communicated strictly under the "need-to-know" principle. Externally, communication must comply with legal obligations, but must be careful not to reveal information that could jeopardize the ongoing investigation or create additional exposure.
Once the incident is contained and analyzed, the organization must eliminate the vectors that enabled it. This may involve revoking excessive permissions, re-patching vulnerable systems, implementing or reinforcing Data Loss Prevention (DLP) controls, reviewing least privilege access policies, or introducing multi-factor authentication for critical systems.
Technical recovery is only one part. The post-mortemanalysis, which ISO 27001 mandates, must identify not only what happened, but why existing controls failed to detect or prevent it in time. This honest reflection is what turns an incident into a real opportunity for improvement.
The final incident report must document the facts, the timeline, the measures taken, the lessons learned, and the improvements implemented. This document has operational value, but also evidentiary value: in the event of an AEPD inspection, it demonstrates the organization's diligence and can be a deciding factor in the severity of a potential penalty.
Most of what is described in this article is reactive management. But the most devastating insider threat incidents are not those that occur, but those that occur without anyone being prepared to respond to them.
The preventive measures that make the difference are, in essence, of three types. Technical measures include implementing a least-privilege access model, encrypting sensitive data at rest and in transit, continuous monitoring of anomalous behavior using UEBA (User and Entity Behavior Analytics) solutions, and segmenting critical systems. Organizational measures include clear acceptable use policies, regular cybersecurity training, offboarding procedures that ensure immediate access revocation, and regular permission audits. Contractual measures include robust confidentiality and non-disclosure clauses, specific agreements with contractors and third parties who access sensitive data, and cyber insurance policies that cover these types of incidents.
Only 25% of organizations report having a fully mature internal risk management program with defined metrics and executive oversight, according to the Ponemon Institute. Most improvise once an incident has already occurred. And improvisation, in this context, comes with a measurable price: in fines, lost customers, eroded reputation, and competitive advantage handed over to whoever took the data.
A protocol is not a guarantee that an incident won't happen. It is the guarantee that, when it does, the organization will be prepared to respond effectively, within the legal framework, and without the incident management process compounding the initial damage.