Identity Is Verified. Behaviour Isn’t
Why Organisations Get This Backwards

We have become very good at proving who someone is.
Passwords have been strengthened by multi-factor authentication. Single sign-on has simplified and centralised access. Biometrics, privileged access management and increasingly sophisticated identity controls have made it much harder for someone to simply pretend to be somebody else.
That is important progress. But there is another point that receives far less attention.
Once we know who someone is, how well do we understand what they are doing?
Identity and behaviour are closely connected, but they tell us very different things. Authentication can give us confidence that the person accessing a system is who they claim to be. It cannot tell us why they are accessing a particular file, whether downloading that information is appropriate, or whether their activity is consistent with what we would normally expect of them.
That note is very important when considering insider risk.
Access Is Only the Beginning
Most employees need access to information and systems to do their jobs. We trust people because organisations could not function without it.
The challenge is that legitimate access can also create opportunity.
Someone does not necessarily need to defeat a security control to cause harm. They may already have the credentials, be authorised to enter the system, or even have been accessing it legitimately for years.
What changes may be what they do with that access.
Perhaps someone begins reviewing information unrelated to their work. An employee preparing to leave starts downloading considerably more material than usual. A contractor working on one project begins accessing systems associated with another project.
Each person may still be correctly authenticated.
The identity has not changed. The behaviour has.
That does not mean anything malicious is happening. There may be a perfectly reasonable explanation. But there is a difference between assuming everything is fine and having enough visibility to recognise when something warrants a closer look.
Understanding Behaviour Without Watching People
This is where discussions about behavioural visibility can become uncomfortable.
Nobody wants to create a workplace where employees feel they are constantly being watched. Nor should behavioural understanding be about treating every unusual action as suspicious.
The objective is much simpler: Understanding enough about normal activity to recognise meaningful change.
What would we normally expect someone in this role to access? What would be unusual? Which activities might be significant given the sensitivity of the information involved? And, importantly, who should ask the question when something does not look right?
Those are not simply technology questions. They are questions of governance, context and judgement. Technology can identify that something has changed. Determining whether that change matters often requires the organisation to understand the person, their role, the information involved and the circumstances surrounding the activity.
Identity Gives Us Confidence. Behaviour Gives Us Context.
Organisations should continue to invest in robust identity controls. Knowing who is accessing critical systems and information remains fundamental.
But verification should not be where our understanding ends.
Some of the most significant insider risks do not involve someone pretending to be somebody else. They involve a legitimate employee, contractor or trusted individual using legitimate access in a way the organisation did not expect.
The system may recognise them perfectly.
The more important question is whether the organisation recognises when its behaviour changes.
Identity tells us who has access. Behaviour helps us understand what they are doing with it.
For insider risk, we need to understand both.
