Insider threats account for 60% of data breaches, at an average incident cost of £3.2 million (ISACA 2024; Ponemon Institute). Detecting them before they act, rather than reconstructing them afterwards, requires five layers beyond access logs and reactive DLP: deception technology (honeytokens and decoy files), user and entity behaviour analytics (baseline deviation, flight-risk profiling, data staging), HR and cyber cross-correlation (grievances, disengagement, irregular badging), continuous endpoint integrity (security tampering, shadow IT), and behavioural precursors — the affective and cognitive signals that appear before any digital artefact exists. The first four layers are well served by existing tooling. The fifth is where most programmes have no instrumentation at all, because it is the only layer that does not require the insider to have already taken a digital action — which is precisely what makes it both the earliest signal available and the hardest one to act on responsibly.
Defence suppliers: see seven sabotage and insider risk controls for UK drone and munitions manufacturers, and how to detect a deepfake job candidate in remote hiring.
The five layers of insider threat detection
Mature insider risk programmes are built in layers, each catching a different stage of the same progression. They are listed here in the order an insider typically encounters them, which is roughly the reverse of the order in which most organisations deploy them.
| Layer | What it detects | Representative signals | Typical tooling | When in the timeline |
|---|---|---|---|---|
| 1 | Deception technology & cyber tripwires |
Interaction with honeytokens, decoy files and fake credentials that no legitimate workflow touches | Honeytoken platforms, canary files | At the moment of exploration — near-zero false positive rate |
| 2 | User & entity behaviour analytics (UEBA) | Deviation from an individual digital baseline: data staging, non-routine directory access, flight-risk correlation, unsanctioned AI tool usage | UEBA and insider risk management platforms | During the accumulation phase, typically days to weeks before exfiltration |
| 3 | HR & cyber cross-correlation | Formal grievances, sustained interpersonal conflict, productivity collapse, disengagement, irregular badging, off-hours patterns | Case management, GRC, manual review boards | Weeks to months out, but usually reviewed only after an alert elsewhere |
| 4 | Continuous endpoint & process integrity | Disabling endpoint agents, registry alteration, silenced logging, unauthorised VPN tunnels or virtualisation | EDR / XDR | Immediately before action — the insider preparing the ground |
| 5 | Behavioural precursors (the human layer) |
Sustained deviation from an individual affective baseline: stress, suppression, disengagement and cognitive load measured across 44 FACS Action Units | EchoDepth — existing cameras, on-premise | Earliest — present before any digital artefact exists |
Layers 1 to 4 are not optional and this page is not an argument against them. Deception technology produces the cleanest alerts in the entire discipline. UEBA is the workhorse of any serious programme and catches the accumulation phase reliably. Endpoint integrity monitoring is non-negotiable. An organisation with none of these should build them before considering layer 5.
What layers 1 to 4 share is a dependency: each requires the insider to have already done something digital — touched a file, staged data, tampered with an agent. That is what makes them tractable, and it is also what bounds how early they can fire. Layer 5 is the only one that does not require a digital action to have occurred, which is why it sits earliest in the timeline and why its absence is the most common gap in otherwise mature programmes.
The honest limitation of layer 5: it produces the weakest individual signal of the five. Affective deviation has many causes that have nothing to do with security — bereavement, illness, personal circumstances, ordinary workplace stress. It is a prioritisation input for analysts, not an alerting mechanism, and it is the layer with the highest proportionate privacy cost. It earns its place only where it is correlated with layers 2 and 3 rather than acted on alone, and only under the governance described below.
What Is the Timeline Problem With Digital Monitoring?
Insider threat detection is the identification of personnel who may misuse authorised access to cause harm. Research shows emotional and behavioural signals precede digital acts by an average of 14 months. Camera-based emotion AI detects these pre-digital indicators — stress, disengagement, and baseline deviation — that UEBA and SIEM systems cannot see.
UEBA, SIEM, and DLP systems are excellent at what they are designed to do: detect anomalous digital behaviour relative to established patterns. Unusual file access at 2am, lateral movement to systems outside a user's normal scope, credential use from unexpected geographic locations — these systems catch these events reliably when properly tuned.
The problem is the word "after." UEBA detects anomalous digital behaviour after it has occurred. The digital act is the triggering event, not its detection. By the time a UEBA alert fires on unusual data access, the access has already happened. In many significant insider cases — Wen Ho Lee, Robert Hanssen, Chelsea Manning — the digital activity that eventually triggered investigation had been occurring for months or years before detection.
Insider threat research provides a consistent answer to why: the digital acts are not the beginning of the insider threat timeline. They are closer to the end. The beginning is typically a precipitating event — financial stress, personal crisis, ideological radicalisation, recruitment by a foreign intelligence service, coercion — that produces measurable changes in an individual's emotional and behavioural state before it produces changes in their digital behaviour.
What the Psychology of Insider Threat Actually Shows
The US Department of Homeland Security's Common Sense Guide to Mitigating Insider Threats identifies a characteristic behavioural trajectory: a concerning life event or stressor, followed by a change in attitude or behaviour observable to colleagues, followed eventually by an operational act. The Carnegie Mellon CERT Insider Threat Center's longitudinal analysis of 150 insider cases found that the average time between the first observable precursor and the first malicious act was 14 months.
Fourteen months. The precursors were observable — to colleagues, in some cases to managers. In almost no case were they systematically monitored. The monitoring infrastructure was watching network logs. Nobody was watching the person.
This is the gap EchoDepth addresses. Continuous emotional baseline monitoring — tracking arousal, valence, and dominance over time for each monitored individual — surfaces deviations from an individual's established pattern. A person whose emotional baseline has been calm-neutral for six months who begins showing sustained negative valence and elevated arousal during routine access events is not necessarily an insider threat. But they represent an anomaly that warrants closer attention, months before the digital signals that a SIEM would detect.
"In the majority of insider threat cases examined, there were observable behavioural indicators prior to the damaging act. In almost all cases, no systematic monitoring was in place to detect these indicators."
— Carnegie Mellon CERT Insider Threat Center, Common Sense Guide (7th edition)How EchoDepth's Three-Phase Detection Architecture Works
EchoDepth's insider threat monitoring capability operates in three phases. In the baseline establishment phase, the system builds an individual emotional profile per monitored person from routine sessions over two to four weeks. This profile captures the individual's typical VAD range, micro-expression frequency, and arousal patterns across different contexts.
In the anomaly detection phase, ongoing sessions are scored against the individual baseline. Deviations above a configurable threshold in valence, arousal, or dominance generate weighted anomaly scores. The system also tracks trajectory — a gradual drift in baseline over weeks may indicate progressive emotional change, while a sudden spike indicates an acute stressor.
In the integration phase, anomaly scores feed directly into SIEM platforms via REST API — Splunk, Microsoft Sentinel, IBM QRadar. Security teams receive the human-layer signal alongside their digital event feeds, enabling correlation: does this individual's elevated anomaly score coincide with unusual access patterns? This correlation is much more powerful than either signal alone.
The Privacy Architecture: Why This Is Legal and Proportionate
Continuous emotional monitoring raises legitimate privacy questions. EchoDepth's architecture addresses these directly. All biometric data is pseudonymised by default — the system scores deviation from baseline rather than storing raw identifiable biometric data. Role-based access controls govern who can access individual-level scores versus aggregate team readiness metrics. All data is processed within UK borders. Full audit logging meets UK GDPR requirements for biometric data processing in security contexts.
The proportionality argument is straightforward: organisations that already operate CCTV, keycard access logging, email monitoring, and DLP systems are conducting extensive monitoring of their personnel's digital behaviour. Extending that monitoring to include emotional baseline deviation scoring — using camera infrastructure already in place — is proportionate to the insider threat risk and less intrusive than many existing monitoring practices.
A full Data Processing Agreement is available under NDA for procurement teams requiring detailed GDPR and DSP Act compliance documentation.
Continuous emotional baseline monitoring for insider threat detection
Individual baseline profiling. Anomaly scoring. SIEM integration. UK data residency. No wearables.