Absence of Evidence Is Not Evidence ofAbsence
- Boaz Fischer

- Jun 23
- 2 min read

One of the most common assumptions organisations make about insider risk is also among the most dangerous.
If nothing has happened, everything must be working.
No breaches.
No investigations.
No arrests.
No reported insider incidents.
The conclusion appears obvious. The organisation must be managing insider risk effectively.
However, that conclusion deserves closer examination.
The absence of evidence is not evidence of absence. An organisation reporting no insider incidents may have effective controls, strong governance, and a healthy organisational culture. Equally, it may simply lack the visibility needed to recognise what is already happening.
These are two very different realities.
The challenge is that insider risk rarely announces itself.
Unlike many external threats, insider harm often develops gradually. Trust and access already exist. Behaviour changes incrementally. Individual events appear insignificant when viewed in isolation.
By the time the organisation recognises the pattern, the window for early intervention may already have closed.
This is why the absence of reported incidents should never be taken as proof that insider risk is being managed effectively.
It should prompt a different question. How confident are we that we would recognise an insider incident if it were already developing today?
For many organisations, the answer is less certain than they care to admit.
Not because information is unavailable. But because organisational visibility is fragmented.
Human Resources observes behavioural changes. Information Technology detects unusual system activity. Security investigates alerts. Managers notice changes in performance or conduct. Legal becomes involved when evidence has already accumulated.
Each function sees part of the picture. But not one function sees all.
Few organisations reliably combine these observations into a unified view of organisational risk.
Culture further complicates the picture.
In organisations where employees are reluctant to raise concerns, managers avoid difficult conversations, or teams operate in silos, early warning signs often remain exactly where they started:
Unnoticed.
This is why a mature insider risk capability should not be measured solely by the number of reported incidents. It should also be measured by the organisation's ability to recognise weak signals, connect information across functions, and intervene before harm occurs.
That requires more than monitoring. It requires organisational awareness.
Because an organisation reporting zero insider incidents may indeed have reduced its exposure. Or it may simply lack the visibility to recognise what is already happening.
The difference is not measured by silence. It is measured by understanding.
Perhaps that is the question every Board should be asking.
Would we know if something was happening right now?