top of page

Insider Risk Perspective


Identity Is Verified. Behaviour Isn’t
Passwords have been strengthened by multi-factor authentication. Single sign-on has simplified and centralised access. Biometrics, privileged access management and increasingly sophisticated identity controls have made it much harder for someone to simply pretend to be somebody else.

Boaz Fischer
Sep 8


The Problem Started Long Before the Incident
Whenever an insider incident occurs, the story remains consistent. Someone took action. They stepped over a boundary. They resulted in harm. The organisation reacts with surprise, begins an investigation, and works on remediation.

Boaz Fischer
Jul 29


Unexamined Trust
Trust is how organisations function. People are trusted with information. Leaders with authority. Suppliers with access. Technology with decisions. Without it, nothing moves.

Boaz Fischer
Jul 15


AI Moves Faster Than Governance
It’s no secret that organisations are moving faster than ever to deploy artificial intelligence. However, governance is not.

Boaz Fischer
Jul 3


Leadership Behaviour Is The Real Policy
Policies sit in folders. Leadership sits in the room.
When a senior executive bends a rule, protects the wrong person, or turns a blind eye, everyone watching learns what truly matters. Not the code of conduct. Not the compliance framework.

Boaz Fischer
Jun 26


Absence of Evidence Is Not Evidence ofAbsence
One of the most common assumptions organisations make about insider risk is also among the most dangerous.

Boaz Fischer
Jun 23


Insider Risk Is Not A Cybersecurity Problem
When organisations hear the words “insider risk”, they call their cybersecurity team. They review access logs, tighten permissions, invest in monitoring tools, and brief their security operations centre team. It feels like the right response, but it is the wrong starting point.

Boaz Fischer
Jun 9


Dashboards Create False Confidence. Not Clarity
Your dashboard is green. Your metrics are trending in the right direction. Your board pack shows coverage, incidents logged, and response times within tolerance. Everything looks fine.

Boaz Fischer
Jun 4


Policies Don't Stop Incidents. Capability Does!
Your acceptable use policy exists. Your data handling policy is documented. Your incident response plan is approved and filed. Yet insider incidents still occur in organisations that have all of them. The reason is straightforward: Policies create expectations. They do not create detection, escalation, or the judgement to act when something feels wrong but is not yet undeniable.

Boaz Fischer
May 20


Most Insider Incidents Start Quietly
They don’t begin with alarms, obvious breaches, or dramatic acts of sabotage. Most start quietly, buried inside everyday work.
All true. But the reality is that TRUST doesn’t set boundaries, log actions, or stop a bad click at 5 p.m. Trust isn’t a control.
That imbalance is becoming NEGLIGENT.

Boaz Fischer
May 12


Why Policies ≠ Capability
To have a Policy or not have a Policy isn't the question...The question is whether your organisation can actually act on it.
All true. But the reality is that TRUST doesn’t set boundaries, log actions, or stop a bad click at 5 p.m. Trust isn’t a control.
That imbalance is becoming NEGLIGENT.

Boaz Fischer
May 8


Trust Isn’t Control
We celebrate trust. We hire for it, reward it, and tell ourselves it’s what makes great teams work.
All true. But the reality is that TRUST doesn’t set boundaries, log actions, or stop a bad click at 5 p.m. Trust isn’t a control.
That imbalance is becoming NEGLIGENT.

Boaz Fischer
May 8
bottom of page