The Hidden Cost of “Low and Slow” Insider Threats

When organizations think about insider threats, they often imagine a dramatic event: an employee walking out the door with a thumb drive, or a sudden bulk download of sensitive files that triggers an alert. But the most damaging insider incidents rarely look like that.

The most dangerous insider attacks are low and slow. They unfold over weeks or months. Each individual action is small enough to be dismissed as normal. The sum of those actions is devastating, and by the time anyone notices, the damage is done and the evidence is cold.

BLUF — Bottom Line Up Front
  • The most damaging insider incidents unfold over weeks or months, not in a single dramatic event
  • Every individual action stays under the threshold, so no rule ever fires
  • Threshold-based detection is calibrated to the organization, not to the individual, which is the gap patient attackers operate in
  • Longer dwell time means more data exfiltrated, more systems accessed, and materially higher remediation cost
  • Detecting the drift requires measuring each entity against its own history, not against a population average

What Low and Slow Looks Like

Consider a Finance Operations employee at a regional health system. Four years on the job. Access appropriate for the role. Knows the systems, knows the schedules, and knows how to move data without triggering volume-based alerts.

Over three weeks, the employee begins accessing file shares outside Finance scope, gradually, a few folders at a time. Patient records, legal contracts, billing data. Not all at once. A few files Tuesday evening. A few more Thursday morning. Each access event is individually plausible. None of them triggers a rule, because no rule exists for “Finance employee accessed one additional folder.”

On night three, 4.2 gigabytes are staged across three sessions and uploaded to an external Dropbox account. The upload goes out through a cloud service the organization allows. No policy violation. No alert.

Three weeks of behavioral drift. Personam detected the shift on day four.

This is an HR case before it is an IT case. The behavioral shift, the slow expansion of scope, the off-hours access pattern, the staging behavior, is the signal. Personam surfaces it. The organization decides what to do next.

Why Threshold-Based Detection Fails Here

Traditional detection approaches are calibrated for volume and velocity. Download 10GB at once and an alert fires. Access 500 files in an hour and an alert fires. But a patient attacker who has studied the environment knows what the thresholds are. They stay under them. Every single day, for weeks, they stay under the threshold.

The data that defines normal for a threshold-based system is the aggregate of all users’ behavior. But one employee’s normal is not the average. It is specific to them: their role, their working hours, their file access patterns, their peer group. A threshold calibrated to the whole organization will never flag someone who is just slightly outside their own personal baseline, which is exactly how low-and-slow attackers operate.

The Real Cost

The IBM Cost of a Data Breach report consistently shows that breaches with longer dwell times cost significantly more to remediate. Every day an insider continues undetected adds scope: more data exfiltrated, more systems accessed, more cleanup required, more legal exposure.

In healthcare, the stakes are higher still. Patient records carry regulatory liability under HIPAA. Contracts and billing data carry legal exposure. When a low-and-slow insider finally surfaces, usually discovered accidentally or by a third party rather than by a security tool, the organization is months behind in understanding the full scope of what was taken.

What Each Approach Sees

Traditional security sees
  • Authorized employee accessing authorized systems
  • Transfer volume under threshold, no alert
  • Allowed cloud service, no policy violation
  • Three weeks pass. Nothing fires.
Personam detects
  • File access scope expanding outside Finance peer norm
  • Off-hours access pattern shift, day 4
  • Cloud upload to a service outside historical behavior
  • Staging velocity far above this entity’s own baseline

The Personam Approach

Personam detects low-and-slow insider threats because it is not measuring against a population average or a static threshold. It measures every entity against its own established behavioral baseline, built from continuous observation of that specific user, device, or service account.

When file access scope begins to expand, Personam sees it relative to that entity’s own history. Not relative to policy. Not relative to the average Finance employee. Relative to them. That granularity is what makes low and slow detectable before the staging event rather than after it.

In a U.S. government insider-threat evaluation, Personam achieved 84% recall on injected insider scenarios while narrowing analyst review scope to roughly 3% of the monitored population. The program that found the most threats required the least analyst time. That is what behavioral precision looks like in practice.

Sources
  • IBM Security: Cost of a Data Breach Report 2024
  • Personam case study: Global IP law firm, four-person executive insider conspiracy
  • Personam case study: U.S. government insider threat evaluation, 84% recall
  • HHS 405(d): Hospital Cyber Resiliency Initiative Landscape Analysis

See what Personam finds in your network. Live demo, 30 minutes.

Schedule Demo