The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/HR/Lowenstein Sandler's Executive Compensation and Employee Benefits Podcast
Lowenstein Sandler's Executive Compensation and Employee Benefits Podcast artwork

Insider Threats: How to Properly Conduct a Cyber Investigation from a Threat Within

Lowenstein Sandler's Executive Compensation and Employee Benefits Podcast · 2026-07-23 · 17 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality10 / 20
Guest Caliber12 / 20
Specificity & Evidence9 / 20
Conversational Craft11 / 20

Insider threats represent a critical intersection of cybersecurity, HR compliance, and legal risk that extends well beyond IT departments. Amy Mushore and Taryn Cannotero break down how unauthorized access to compensation data, benefits files, payroll records, and HR documentation creates exposure to ERISA fiduciary breaches, HIPAA violations, identity theft claims, and regulatory inquiry. The episode distinguishes between monitoring (baseline observation covered by policy) and investigation (triggered when anomalies cross a threshold), emphasizing the legal necessity of documented criteria and consistent application. Negligent insiders - those who click phishing links, reuse passwords, or email sensitive files to personal accounts - represent the most common threat category. Investigation triggers include unusual data access requests, excessive downloads, suspicious email forwarding, geographic login anomalies, and heightened activity from departing employees. The hosts stress retaining forensic experts under attorney privilege, involving legal counsel, HR, and IT in coordinated response, and establishing clear containment protocols. Post-investigation actions vary by breach type: malicious incidents typically warrant termination for cause with forfeiture of equity and bonus clawbacks, while negligent breaches require discretion to encourage employee reporting. Multi-factor authentication, mobile device management policies, behavioral monitoring of sensitive data, and incident response plans are presented as foundational preventative measures.

Key takeaways

  • →Insider threats create simultaneous exposure across ERISA fiduciary duty, HIPAA compliance, identity theft liability, and wrongful termination claims, making them employment and benefits issues as much as IT problems.
  • →Establish and document a clear threshold between ongoing monitoring (baseline user behavior) and triggered investigation (anomalies exceeding that baseline) to defend future legal proceedings and ensure consistent policy application.
  • →Retain forensic experts under attorney-client privilege and coordinate investigations through counsel rather than allowing IT to investigate independently, preserving legal protection and third-party distance from enforcement decisions.
  • →Not every IT incident warrants termination; negligent breaches like phishing clicks should allow for remediation to encourage employees to self-report compromises early rather than hide them.
  • →For malicious insider threats, termination for cause combined with equity forfeiture and bonus clawbacks serves as both enforcement and a tool to compel information disclosure that protects customers and employees.

Guests

Taryn CannoteroAmy Mushore

Topics in this episode

HIPAA complianceMulti-factor authentication (MFA)Incident response planningInsider threatsERISA fiduciary dutyMobile Device Management (MDM)Equity forfeiture and clawback provisionsForensic investigation and e-discoveryExecutive compensation and benefits dataEmployee monitoring policies

Questions this episode answers

What is an insider threat and why are they harder to detect than external threats?

An insider threat is a breach caused by an employee, executive, contractor, or authorized person who leverages legitimate access to harm the organization, either intentionally or negligently. They are harder to detect because traditional security tools assume threats come from outside, while insider threats come from people with legitimate access who blend in with normal user behavior.

What triggers an insider threat investigation?

Common triggers include requests for data access outside normal job duties, unusual financial activity from employees with material non-public information access, excessive or sudden downloads of gigabytes of data, suspicious email forwarding to personal accounts, login irregularities from unexpected geographic locations, and suspicious activity from departing employees - particularly those moving to competitive positions.

What is the difference between monitoring and investigation in the context of insider threats?

Monitoring is ongoing systematic observation of user activity establishing a baseline of normal behavior, typically covered by company policy. Investigation is triggered when monitoring reveals anomalies that cross a documented threshold warranting deeper activity. Having a clear documented investigation criteria is essential to defend the company's decisions in future legal proceedings.

What should a company do if a malicious insider threat is confirmed?

A malicious insider threat typically warrants termination for cause, which triggers forfeiture of unvested equity, clawback of previously granted compensation, and potential loss of bonuses. The company should also evaluate whether criminal or civil action is appropriate and determine whether disclosure to regulators or affected individuals is required under ERISA or HIPAA.

How should an employer handle negligent insider threats like phishing clicks?

Employers should exercise discretion and avoid automatic termination for negligent breaches like phishing, as this may discourage employees from self-reporting compromises early. Instead, remediation and coaching should be considered to encourage employees to report security mistakes promptly, enabling faster containment and damage prevention.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode covers foundational insider threat concepts - negligent vs. malicious threats, investigation triggers, and post-investigation actions - with moderate density. However, much of the content is introductory framework (definitions of monitoring vs. investigating, basic policy reminders) rather than novel, non-obvious operational insights. The discussion lacks granular tactical depth or surprising findings that would elevate substance for experienced practitioners.

An insider threat, in practical terms is a threat that comes from an employee, an executive, a, uh, contractor, or any person who has authorized access to or knowledge of an organization's resources.
Negligent insiders are actually the most common category of an insider threat.

Originality

10 / 20

The episode presents conventional insider threat investigation frameworks and standard legal/compliance advice (document everything, retain forensic experts, balance privacy, use MFA). No contrarian arguments, counterintuitive data, or first-principles reimagining of insider threat strategy appears. The guidance tracks closely with NIST/industry playbooks without fresh angles or proprietary methodology.

The key is to have a clear documented investigation criteria and to apply them consistently.
Document everything to defend the company's decisions and conclusions.

Guest Caliber

12 / 20

Guests are in-house counsel at a law firm (Taryn, employment/benefits counsel; Amy, privacy/data/security practice chair). They offer relevant legal and compliance expertise but are primarily law-firm practitioners offering legal guidance rather than operators who have managed insider threat incidents at scale in corporate environments. No specific client war stories or operational depth from the front lines.

I'm Taryn Cannotero, counsel in the firm's executive compensation, employment and employee benefits group.
I'm Amy Mushore. I'm the chair of our privacy, Data, security, Risk Management and safety practice.

Specificity & Evidence

9 / 20

The episode is light on concrete examples, named companies, specific metrics, or dollar figures. Triggers are listed generically (gigabytes of data, excessive downloads, suspicious logins) without quantified thresholds. No case studies, real breach scenarios, or data on insider threat prevalence/cost are provided. Most advice remains abstract and procedural.

an employee suddenly downloading gigabytes of data that they have never accessed before.
Email forwarding to personal accounts on an excessive basis.

Conversational Craft

11 / 20

Host asks structured, logical follow-up questions (what triggers investigation, how to conduct one, post-investigation actions) but rarely probes for specificity, pushes back on claims, or explores nuance. Questions are answer-prompting rather than challenging. When guests make claims (e.g., negligent insiders are 'most common'), no request for data or proof follows. The conversation reads as a scripted walkthrough of talking points rather than dynamic inquiry.

Amy what triggers an insider threat investigation?
So once the investigation is triggered, how should an employer properly conduct an insider threat investigation?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker D59%
  • Speaker C24%
  • Speaker A12%
  • Speaker B6%

Most-used words

insider22investigation18access17employee16threats16threat14data13compensation11information10benefits9legal9example9monitoring9employees8executive7breach7

Episode notes

In this episode of Just Compensation, Amy S. Mushahwar , Taryn E. Cannataro , and Jessica I. Stewart discuss insider threats and how employers should approach cyber investigations when a threat comes from an employee or other service provider within the organization. They delve into common warning signs, evidence preservation, employee privacy considerations, the importance of coordination among legal, HR, IT, and forensic teams, and post-investigation issues such as considerations when disciplining or terminating employees, disclosure obligations, and the role of compensation structures in deterring and addressing insider threats. Speakers: Amy S. Mushahwar , Partner, Data Privacy, Security, Safety & Risk Management Taryn E. Cannataro , Counsel, Executive Compensation and Employee Benefits Jessica I. Stewart , Associate, Executive Compensation and Employee Benefits

Full transcript

17 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome to the Lowenstein Sandler Podcast Series. Before we begin, please take a moment to subscribe to our podcast series@lowenstein.com podcasts or find us on Amazon Music, Apple Podcasts, Audible, iHeartRadio, Spotify, SoundCloud, or YouTube. Now let's take a listen.

Speaker A: Welcome to the latest episode of Just Compensation. My name is Jessica Stewart, and I'm an associate in Lillenstein's executive compensation, employment and benefits group. I'm joined today by Taryn and Amy, who I'll turn over to introduce themselves.

Speaker C: Hi, I'm Taryn Cannotero, counsel in the firm's executive compensation, employment and employee benefits group.

Speaker D: Hi, my name is Amy Mushore. I'm the chair of our privacy, Data, security, Risk Management and safety practice. So excited to be here today.

Speaker A: Today's episode tackles a topic that every employer should understand where data privacy, employee benefits, and executive compensation overlap Insider Threats and How to Properly Conduct an Investigation but facing a threat from within we are going to discuss what insider threats are specific risks that intersect with employment, employee benefits, and executive compensation. What triggers a cyber investigation, how to properly conduct one, and what practical steps employers can take to avoid another one. As always, this is not intended to be an exhaustive discussion, and we encourage you to consult with your legal counsel and cybersecurity professionals with specific questions to set the stage. What is an insider threat?

Speaker D: Well, that's a great question, Jessica. An insider threat, in practical terms is a threat that comes from an employee, an executive, a, uh, contractor, or any person who has authorized access to or knowledge of an organization's resources. And it uses that to access, whether it's intentionally or sometimes unintentionally to cause harm to an organization. Not all insider, uh, threats look the same. Some insider threats are malicious and deliberately meant to harm the organization, while others are purely negligent. Negligent insiders are actually the most common category of an insider threat. These types of threats can include clicking phishing links, reusing weak passwords, emailing sensitive files to personal accounts for convenience, and also we want to emphasize reuse of passwords. If you have an iPhone and a password keeper on your device, you should be able to see compromised passwords as you page down proof. So very important not to reuse passwords, but traditional security tools often assume threats come from the outside. However, insider threats come from all people with legitimate access, which makes them uniquely difficult to detect and potentially more damaging. And with the rise of remote work and expanded system access, it is a problem that we are seeing more frequently as a firm and I am seeing more frequently in my daily practice.

Speaker A: Erin how do insider threats overlap with executive compensation employee benefits issues?

Speaker C: Anyone with access to the company's compensation, employee benefits and or HR files has access to a great deal of private and very sensitive information. For example, employee benefit plans, such as retirement plans and health and welfare plans hold enormous amounts of sensitive personal information. This could include Social Security numbers, financial data and protected health information. Plans that are subject to ERISA can result in a breach of fiduciary duty. A breach can expose benefit plan fiduciaries to the risk that they fail to safeguard plan assets if plan data is mishandled or if they fail to monitor third parties with access to plan data. A breach of personal health information could also result in potential investigations by the Department of Health and Human Services and or a state's Attorney General and could suggest HIPAA non compliance as well. Anyone with access to payroll and human resource files can also give unauthorized parties access to private employee information as well. This could include C suite salaries, pending equity awards, future corporate transactions, severance arrangements. Releasing this information can be damaging both publicly and internally. Human resource files may contain personnel files, employee addresses, summaries of disciplinary actions and investigations, and even tax records. The organization can be exposed to identity theft claims and employee litigation if some of this information were to be leaked.

Speaker A: Amy what triggers an insider threat investigation?

Speaker D: Common triggers suggest the need for investigation can include the types of items like an employee requesting access to data or systems outside their normal role without a clear business need. Also, um, police have measures to detect that unusual financial activity, particularly for employees with access to material. Non public information also have means to detect all of these excessive or suspicious downloads. For example, an employee suddenly downloading gigabytes of data that they have never accessed before. Email forwarding to personal accounts on an excessive basis. We understand that employees from time to time might need to forward something to print, but this is, you know, monitoring excessive amounts above baseline login irregularities such as failed authentication spikes or logins from geographic locations that do not match that person's normal pattern and then suspicious digital activity from an employee who's leaving the company. Especially employees that leave the company need to be monitored and um, whether or not it's voluntary or involuntary. We find the vast majority of our insider threats that we investigate happen because someone is changing jobs and into uh, another competitive position. It is important to know the legal distinction between monitoring and investigating. Monitoring is ongoing systematic observation of user activity and system behavior. This is your baseline. This is typically covered by your policies and procedures in your user guides. An investigation, however, is triggered when monitoring reveals anomalies or indicators that cross a threshold warranting deeper activity. The key is to have a clear documented investigation criteria and to apply them consistently. You want to balance thoroughness with privacy and very, very key as layers are saying, have this documented. If it's not documented, you do not have a baseline in order to measure whether or not your behavior was at least commensurate, um, with the spirit and investigation or they experience a past process. So as many lawyers will tell you, if it's not documented, it doesn't exist. We uh, want to make sure the documentation is there.

Speaker C: You'll also have to balance workplace privacy expectations and any applicable state law considerations. Privacy expectations at work are limited, but they are not non existent. So as Amy said, the company policy should make it clear that all systems are owned by the company. They should provide notice that the company has the right to monitor email messaging platforms and file transfers. And you should apply that policy consistently and avoid targeting a uh, single employee or employees based on protected characteristics. Certain states may also require notice or consent for monitoring and recording or have their own employee monitoring and notice statutes. So it's important to be mindful of those as well.

Speaker D: I would love to add just one item that make sure you also have a mobile device management policy. Because anything, any of your data crossing a ah, telephone you have a right to inspect and you have a right to inspect on the phone and within the primary, for example email server in the event that it is email, but you may need to preserve the entire device. Um, you might not be able to legally preserve the entire device depending on the state in which you find yourself, but reserve the right to within the policies and that at least preserves the argument in the event that you need it.

Speaker A: So once the investigation is triggered, how should an employer properly conduct an insider threat investigation?

Speaker D: Sure, uh, well, the very first steps are to preserve any evidence and loop in the appropriate parties. Next you identify who should be involved in the investigation and in what capacity. Legal versus HR versus it. Your policies typically will describe what you do for varying different pieces of investigation and define the scope of the investigation. What systems were accessed, what data was misappropriated, whether or not the threat is ongoing, and if the insider is an executive. Consider whether board involvement is warranted or required. You might need for example as well forensic professionals to help you better understand the scope of the incident. Know that all of this is not decided at once and it is typically decided in waves. Containment options can range from increased monitoring to immediate access or Revocation and the right choice depends on the threat severity and the evidence strength. Document everything to defend the company's decisions and conclusions. For example, what document triggered the investigation, what was found, what actions were taken and when. You may need this for future legal proceedings. For example, if wrongful termination is alleged, regulatory inquiries and to improve future detection of later events. The right technical resources make or break these types of investigations. Our team has 20 plus year relationships with forensic responders. So if you especially find yourself in a technically difficult conversation, very important to retain a uh, forensic expert, have them retained under privilege and have them be a part of your investigation team. So you're fully and fairly looking at this through a lens of a third party. A third party also gives you the ability for the company to have a little bit of distance between the immediate investigative function and preservation and um, the ultimate investigation and legal consequences after the investigation included.

Speaker A: What are the key post investigation actions and allegation?

Speaker C: The answer here turns on whether the activity was malicious, negligent or accidental. For example, if the breach was malicious, you may want to consider whether criminal or civil action could be appropriate. But depending on the type of breach, you'll need to consider whether the employee should be terminated, suspended or reprimanded in any way. This is where some of the termination considerations that we've discussed in a prior episode become directly relevant. You'll need to think about the timing of the termination if that's the route you want to take, what documentation is needed, whether you're going to ask the person for release, and whether or not you need to pay any severance or consideration in order to get them. If the breach was malicious, it would almost certainly rise to the level of a termination for cause. A for cause termination often triggers forfeiture provisions related to vested and unvested equity awards, bonuses or even clawbacks of previously granted compensation. These can all be key enforcement tools in these situations. You'll also need to consider whether disclosure to regulators or affected individuals is required. For example, disclosure may be required for ERISA plans if the breach triggers any DOL notification procedures and or any participant communication requirements. Regardless of what type of insider threat you're dealing with. It's important. Review and tighten access controls across the organization. Update your policies and training, provide employees with the proper training and align your uh, it, hr, legal and benefits functions on how to handle these types of threats.

Speaker D: I just want to add one tiny component to this is especially as you're investigating an IT incident, not every IT incident is a fireable event. You have to have some discretion. For example, if anyone who clicks on a malicious phishing link is terminated, that might discourage your employees from coming forward in the event that they click on a link. The same thing goes for lost laptops. So you know, as you think of especially those negligent events, you are also weighing in that decision of to terminate or non to terminate. Will something have a deterrent effect or might it actually deter good conduct, which we want to encourage, which is if you make a mistake, come to it early and we'll be able to contain the issue, contain the problem, protect consumers and protect employees.

Speaker A: What are some key takeaways employers should keep in mind with respect to insider threats?

Speaker D: Insider threats are not just IT issues. They affect employment benefits, data privacy, and could open you up to a host of legal issues, fiduciary risk and regulatory disclosure obligations. Please to those on the line, do not just hire a technical expert and not have that technical expert underprivileged. Do not just have it investigate and not have that investigation being done, at least under internal counsel in house counsel privilege. Make sure that that is orchestrated. If you are investigating, the key here is to plan ahead and prevention starts with company policies and security awareness. Please have an incident response plan that contemplates insider threats. If you do not, we have incident response plans that workflow this for you. We also want you to conduct regular trainings and tabletop exercises, risk assessments and phishing simulations and to of course know where your sensitive data lives and who has access to it and have the behavioral monitoring over that sensitive crown jewel data so you can distinguish baseline user behavior between excessive behavior that might indicate a potential insider threat. Understand what specific IT controls you have in place. You know, as we are thinking about negligent insiders, multi factor authentication is still one of the best ways to to prevent just immediate account access. We know it's not foolproof. We know MFA can be spoofed, but it should be enabled for all systems and those that hold sensitive benefits and compensation data. One thing that I want to emphasize and the reason why we're saying insider ah threats and mfa if threat actor takes control over your user account you typically in the immediate access you might not be able to distinguish threat actor behavior from baseline user behavior. So do indeed make sure that you protect against your accounts by having strong multi factor authentication and then compensation structure such as forfeiture and clawback can be an easy enforcement tool for dealing with insider threats. That can be a um, means for you to get the information that you need to get in order to secure your employees and to secure your customers.

Speaker A: Insider threats represent one of the most significant and often overlooked risks uh at companies. Employers should ensure they have a comprehensive insider threat framework in place, maintain strong access controls and monitoring programs, and develop trusted relationships with technical and legal resources they will need when an incident occurs. Thanks for joining us today. If you enjoyed today's discussion, please subscribe, leave us a review and share this episode with your colleagues. We look forward to having you back on the next episode of Just Compensation.

Speaker B: Thank you for listening to today's episode. Please subscribe to our podcast series@lowenstein.com podcast or find us on Amazon Music, Apple Podcasts, Audible, iHeartRadio, Spotify, SoundCloud or YouTube. Lowenstein Sandler podcast Series Series is presented by Lowenstein Sandler and cannot be copied or rebroadcast without consent. The information provided is intended for a general audience and is not legal advice or a substitute for the advice of counsel. Prior results do not guarantee a similar outcome. Content reflects the personal views and opinions of the participants. No attorney client relationship is being created by this podcast and all rights are reserved.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Enterprise Software Buyers Now Demand a Vendor AI Training Data AuditB2B SaaS Talks with Fexingo · on HIPAA compliance90 / 100
  • The Healthcare Black Box: Prior Authorization, AI Denials, and Fiduciary Duty (Ep. 54)The Benefit Whisperer · on ERISA fiduciary duty85 / 100
  • Why Your Engineering Team's Size Doesn't Matter Anymore w/ Michael Kopko | Episode 207The Software Leaders Uncensored Podcast · on HIPAA compliance84 / 100
  • Why Most Productivity Apps Fail Neurodivergent PeopleColorado Tech People · on HIPAA compliance83 / 100
  • Episode 015: The Last Flintstones LawyerAI Tools for Practicing Lawyers · on HIPAA compliance82 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100

More from Lowenstein Sandler's Executive Compensation and Employee Benefits Podcast

All episodes →
  • Sections 457(b) and 457(f): Designing Deferred Compensation Plans for Tax-Exempt and Governmental Employers64 / 100
  • Navigating Inducement Equity Grants to Attract Top Talent53 / 100
  • What's New in Employment Law? Part II: General Trends55 / 100
  • What's New in Employment Law? Part I: State-Specific Changes86 / 100
  • Commission Basics: Key Considerations for Commission Plans
Explore the best B2B HR podcasts →
All Lowenstein Sandler's Executive Compensation and Employee Benefits Podcast episodes →