Blog Post

Insider Risk Breaks the Frequency Side of the Model

September 10, 2026

Table of Contents

External threat models estimate how often somebody gets in and what they reach afterward. The susceptibility term does most of the work, weighing what an attacker can do against what the controls prevent.

An insider is already inside. The credentials are valid, the access is entitled and the workflow is familiar. None of that makes the model harder to run, it changes which side of it breaks, and the break is on frequency rather than on magnitude.

What Happens to the Susceptibility Term?

It collapses toward certainty. Control strength against an authorized user, for actions inside their entitlement, is close to zero.

An external model carries a discount for the possibility that controls prevent the attempt. Multi-factor authentication, segmentation, endpoint detection and access controls all reduce the chance an attacker reaches the target. None of them applies to somebody using access that was granted to them for a legitimate purpose, so a model applying the same discount to an insider scenario understates it by whatever the discount was.

Which Signals Stop Being Informative

The ones external monitoring is built around. Failed authentication, blocked connections, denied requests and perimeter alerts are all absent, because nothing was refused. An insider acting within their privileges generates a log of successful, permitted operations, which valid accounts as an access path illustrates at the individual level.

Should Insider Risk Be One Scenario?

No, and this is the modeling error that matters most. Insider exposure covers three situations with different frequencies, different severities and different remedies.

Exceedance curve showing the likelihood of annual loss exceeding successive percentages of revenue, with the average marked on the curve
Blending distributions with different shapes into one scenario produces a curve that describes none of them.

Negligence is frequent and mostly small. Somebody sends a file to the wrong recipient, stores regulated data in the wrong place or pastes something into a tool they should not have. High likelihood, contained consequence, and the population is everybody.

Deliberate misuse is rare and severe. Somebody with knowledge of where the valuable material sits takes it purposefully, which is low likelihood and high magnitude with a small population.

The Third Is Not an Insider Event at All

A compromised credential is an external actor wearing an insider's identity. The mechanism is phishing or credential theft, the frequency belongs to the external threat landscape, and the available base rates are among the better-evidenced in conventional loss data. Modeling it inside the insider scenario double-counts it against the external model that already includes it.

Why Is the Frequency Term the Hard Part?

Because insider incidence depends on organizational characteristics rather than on the threat landscape, and peer data is correspondingly weaker.

External attack frequency is driven by what attackers are doing, which is observable across large populations and reasonably transferable between organizations of similar profile. Insider frequency depends on headcount, turnover rate, sector, how much valuable material sits within reach of ordinary roles and how closely behavior is monitored. Those vary enormously between companies that look identical on an external threat profile.

What Can Be Measured Instead?

Three things, all internal and all knowable. The population with access to the material that matters, which is a query rather than an estimate. The departure rate, since separation is the period when deliberate misuse concentrates. Then the time to detection, since insider events run longer than external ones and duration multiplies the consequence.

Is the Magnitude Side Really Unchanged?

Higher rather than unchanged, and the direction is worth stating because it runs against intuition. Per event, insider severity tends to be higher.

Program performance trended across quarters alongside the history of assessments behind each figure
Tracking the position across periods is what shows whether the controls that shorten detection are working.

An external attacker explores, takes what is reachable and frequently leaves with material that is partly irrelevant. An insider knows which system holds the customer master, which folder holds the contracts and which export produces the complete record. The selection is precise, so the same volume of exfiltration carries more consequence per record.

Detection Also Runs Longer

Insider activity looks like work, so it survives longer before anyone notices, and every additional week extends the exposure. Where external incidents are frequently discovered by a third party or by an obvious failure, insider events are found through variance analysis or not at all, which continuous rather than periodic observation affects directly.

How Do Controls Reduce This Exposure?

Through two mechanisms rather than one, and neither is the mechanism external controls use.

External controls reduce the probability that access occurs. The route is unavailable against somebody entitled to the access, so insider controls either narrow the entitlement or shorten the time to detection. Narrowing entitlement reduces what any single person can reach, and shortening detection reduces how long they can act before somebody looks.

The Benefit Calculation Differs

A control reducing external probability shows up as a lower frequency in the model. A control narrowing entitlement shows up as lower severity, and one shortening detection shows up as lower duration and therefore lower severity again. Presenting all three as frequency reduction misstates what the investment buys, and which lens the program uses determines whether that distinction is visible.

What Does This Do to the Aggregate?

It raises the extreme figure more than the average, because the deliberate-misuse component sits in the tail rather than in the body.

Negligence contributes a steady stream of small losses that show up in expected annual loss and barely affect the extreme case. Deliberate misuse is the reverse, contributing little to the average and potentially dominating a one-in-hundred figure where the population with access to the most valuable material is large. An organization reporting only the average has largely reported the negligence component, and reading a distribution at two points is what separates them.

Does It Correlate With the External Scenarios?

Less than most exposures, which is a rare and useful property. An insider event and a ransomware event share no cause and no dependency, so the two are close to independent in a way that most cyber scenarios are not. The independence matters for the aggregate, since genuinely independent components widen the distribution less than correlated ones.

Where Does the Population Figure Come From?

An access review, which most organizations run for compliance reasons and rarely read as a modeling input. The number that matters is how many people can reach the material whose loss would hurt most.

The figure is a query against entitlements rather than an estimate, and it is frequently much larger than anyone expects. A customer database readable by four hundred people has a deliberate misuse population of four hundred, whatever the organization believes about how many need it. Narrowing that number is the single most direct reduction available on the severity side.

Which Access Reviews Are Useful Here?

The ones asking who can reach a named dataset rather than who holds a named role. Role-based reviews confirm that entitlements match job titles, which is a different question from how many people can export the customer master. The second is what the model needs and the first is what most reviews produce.

Does Reducing the Population Reduce Exposure?

On the deliberate misuse scenario, substantially, since fewer people with reach means fewer opportunities and a smaller expected consequence. On negligence, less so, because negligent exposure tracks how many people handle the data in the course of their work rather than how many hold standing entitlement, and prioritizing by what each control removes keeps those two effects separate.

What Should the Model Contain?

Three separate scenarios rather than one, with the third moved out.

A negligence scenario with high frequency, contained severity and a population equal to everybody who handles the relevant data. A deliberate misuse scenario with low frequency, high severity and a population defined by who can reach the most valuable material. Then credential compromise modeled where it belongs, in the external set, since including it twice is the most common error in this area. Cyber risk quantification, or CRQ, that separates damage types and scenarios makes each of the three readable rather than blended.

The Break Is on Frequency

An insider scenario does not need a different engine, it needs a different treatment of the susceptibility term, which collapses toward certainty because control strength against an entitled user is close to zero. The signals external monitoring relies on are all absent, since nothing was refused. Insider exposure covers three situations that should be modeled separately, and one of them is a credential compromise that belongs in the external set entirely. Frequency is the hard side, because it depends on headcount, turnover and monitoring rather than on the threat landscape, while severity runs higher per event because the selection is precise. Kovrr's CRQ separates scenarios and damage types, which is what keeps the three components distinguishable.

To see insider and external exposure modeled as separate scenarios rather than blended, book a demo with our risk experts.

Tomer Shoolman

Product Manager

Insider Risk Modeling FAQs

Speak to an Expert

What happens to the susceptibility term for an insider scenario?

Should insider risk be modeled as one scenario?

Why is frequency the hard side for insider risk?

Is insider severity higher or lower per event?

How do controls reduce insider exposure?

What does insider risk do to the aggregate figure?