Privileged user risk
Detecting slow-burn behavioral shifts in high-trust individuals
The most dangerous insiders are rarely caught by basic indicators. This episode is for practitioners who have already built the program — and now need to sharpen the blade.
Every insider risk program is built to catch the obvious cases — the disgruntled employee on their way out, the accidental data leak, the policy violation that triggers an alert. But the hardest threats don’t look obvious. They look normal. A trusted senior employee with decades of tenure quietly manipulating systems. A remote worker whose behavioral patterns have slowly shifted. A contractor who passed every background check — and is routing data out of the organization over months.
In this episode, three practitioners who have seen these cases firsthand examine the detection challenges that mature programs still get wrong: privileged user risk, nation-state infiltration through legitimate hiring, AI and agentic identity as a new attack surface, and the false positive problem that causes organizations to tune away their own visibility. They also take on the question security teams avoid — where does monitoring end and surveillance begin, and how do you build a program that protects the organization without destroying employee trust.
Detecting slow-burn behavioral shifts in high-trust individuals
When the threat actor passes your background check and joins your team
The visibility gap when employees and agents create unmapped risk
Reducing false positives without creating dangerous blind spots
Where the line is — and how transparency changes everything
SaaS gaps, agentic infrastructure, and what keeps practitioners up at night
Founder, Waintraub Cyber Solutions
Chief Security Evangelist, Exaforce
CISO, Alchemy Cyber
Field CISO, Teramind