Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Insider Risk Without Spying on Employees

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large amounts of files right before they resign. Used carefully, they protect the business. Used carelessly, they damage trust and create legal risk.

Why insider risk deserves attention

Not every threat comes from outside. Departing employees taking customer lists or designs, careless sharing of confidential files, and occasional malicious insiders all cause real losses. Traditional security tools aren't designed to spot them.

The balance to strike

Employees expect a reasonable degree of privacy. Laws in many countries restrict workplace monitoring. A program perceived as surveillance can harm morale and retention. The best programs are narrow, transparent and governed.

Questions to ask your team

  • What data would hurt us most if an employee took it to a competitor?
  • Do we currently know when large amounts of sensitive data are downloaded or shared?
  • Have HR and legal agreed on what monitoring is acceptable?
  • Who would investigate an alert, and what would happen next?

What good looks like

A focused program protecting your most sensitive data, involving HR and legal from the start, with privacy protections, limited investigator access and a clear response process.

The decision

Start with one narrow, well-justified scenario — such as departing employees with access to highly confidential data — and expand only after reviewing results with HR and legal.

microsoft insider risk management impactIgnite 20192019

More on this story