In September, a NSW Corrective Services officer was charged over alleged unauthorised access to inmate information — 85 restricted-data offences alleged. Those are allegations before a court, not findings. But the shape of the case is worth studying regardless of its outcome, because it is the most common insider pattern there is: a person with legitimate credentials allegedly using them far outside their legitimate purpose.
The insider problem is an access problem wearing a trust costume
Security spending overwhelmingly points outward — firewalls, email filters, endpoint tools. The insider walks past all of it, because the insider is supposed to be there. What failed is never authentication; it is the assumption that authentication equals authorisation for everything, forever.
Three questions expose the gap in most SMEs:
- Who can currently see your most sensitive records? Not who should — who can. In most organisations the second list is much longer, padded by role changes, departed contractors whose access survived them, and "temporary" grants from 2024.
- Would you know if someone browsed records they had no business reason to touch? Eighty-five separate alleged accesses implies a pattern over time. Patterns over time are exactly what audit logs plus periodic review exist to catch — and what nothing else catches.
- Do your people know that access is logged and reviewed? Deterrence is a legitimate control. Staff who know that record access leaves a trail behave differently from staff who assume it vanishes.
The controls, in priority order
- Least privilege, enforced by role. Access maps to the job, not the person, and changes when the job does. This is the number one control in every serious framework for a reason.
- Audit logging on sensitive records — with someone actually assigned to review anomalies monthly. A log nobody reads is a diary, not a control.
- Joiner/mover/leaver discipline. Most orphaned access comes from movers, not leavers: people who changed roles and kept the old keys. Pair this with the credential hygiene basics in password security training for employees.
- A written acceptable-access policy staff have actually seen. "I did not know I could not look" is a defence you remove in one training session.
Why this belongs in awareness training
Insider risk training is usually pitched at catching the malicious colleague. The more valuable framing is protecting everyone else: clear rules about what access is for, visible logging, and a normal, blame-free path for reporting concerns. Curiosity browsing thrives in ambiguity; it withers under stated expectations. It is the same cultural mechanics we describe in social engineering tactics targeting NZ employees — behaviour follows what the organisation makes explicit.
Practical takeaway
- Run an access review on your top three most sensitive systems this month; remove anything that fails the "current business need" test
- Confirm sensitive-record access is logged, retained, and reviewed by a named person
- Tell staff, in writing, what access is for and that it is auditable
- Add an insider-access scenario to your next training cycle
SecureAZ's awareness modules cover acceptable use, data handling and the human side of insider risk, with completion records you can show an auditor. Start a free 45-day trial.