IndustriesInsider risk

Two tools. One question.A spreadsheet in between.

Your identity platform knows who can reach the data. Your behaviour platform knows what they did. Nexyron is the first thing that holds both.

Three domains, built separately, integrated shallowly.

Every vendor owns one of the three well and integrates the other two through a connector and a field mapping. The question an executive actually asks has never been confined to one of them.

This person has access they should not have, their behaviour changed six weeks ago, and they resign on Friday. How worried should we be?

Entitlements

Who can reach what, through which groups and inherited permissions. Owned by identity governance.

Behaviour

What someone did, when, and whether it departs from their pattern. Owned by behavioural analytics.

Context

Whether they are leaving, were passed over, or work for a contractor whose engagement ends in a fortnight. Owned by HR, which does not consider itself a security system.

Three consoles, three exports and a spreadsheet, assembled by an analyst, usually after something has already happened.

Why the anomaly is not the point

Most detections are uninteresting, and the reason is structural.

A baseline compares a person to their own history or to a broad population. Both fire when somebody's job changes, which happens constantly and legitimately. A new team means new systems. A quarter close means more downloads.

The comparison that carries meaning is against a peer group: same job, same entitlements, same point in the cycle.

A fair peer group is not a filter, it is a construction. “Same department” produces a group that differs from the subject in exactly the ways that matter, and comparing against it produces confident nonsense at scale.

What Nexyron does instead

One model across all three domains, and a peer group that has been tested.

Nexyron takes entitlement exports, access logs, HR events, contractor records and system inventories into a single connected model. Group memberships and nested permissions are traversals rather than a reconciliation somebody runs monthly, so effective access is computed rather than assumed.

Time is a property of the model. A review, an entitlement change, an access event and a resignation sit on one sequence, which is where the meaning of the whole thing lives.

And the peer group is built by the engine and balance-tested before anything is ranked. Where the group is not comparable, Nexyron says so and declines rather than producing a score somebody will act on.

That refusal is not a limitation. In a jurisdiction with a works council, it is the thing that keeps the programme alive.

A simulated review

Constructed to show the method. No customer, no real individual, no benchmark.

  1. 01

    What can this person actually reach

    Not what the role grants on paper. Group memberships, inherited permissions, nested groups and assumable service accounts followed to the resources at the end of every path. The effective access includes a third repository, reached through a group nested during a reorganisation eighteen months ago.

    Nobody granted that deliberately. At each individual step, every grant was legitimate.

  2. 02

    Was it used

    First access seven weeks ago, eleven times since. Before that, never, in eighteen months of holding it.

  3. 03

    Is that actually unusual

    Against a peer group tested for balance on the attributes that predict access behaviour. Unusual on two dimensions: no peer accesses that repository at all, and the times fall outside both the person's own pattern and the group's.

  4. 04

    The sequence

    Entitlement changes, access events and HR milestones on one timeline. Performance review, six weeks unchanged, first access, steady increase, resignation. No single element is evidence. The order is the finding.

  5. 05

    Toxic across systems

    Separation of duties inside one system is well handled by that system. A combination that is only toxic across two is nobody's control, because neither system can see the other half. Create a supplier in one, release a payment in another.

  6. 06

    Do our interventions work

    Reminder notices and watchlisting, measured against comparable employees who received neither. Notices show a measurable effect on one category of behaviour and none whatsoever on another.

    This field is unusual: the record already exists, because programmes document their actions by mandate. The question is answerable in year one.

Five things, without deploying a single new sensor.

01

One question, not three consoles

Entitlements, behaviour and context answered in the same query, against the same model.

02

Effective access, not nominal access

What a role grants on paper and what it resolves to through nested groups are different things. The difference is exactly where unintended access lives.

03

Peer comparison, constructed and tested

Balance-testing before ranking is the difference between a defensible finding and an accusation.

04

Cross-system combinations become visible

Which no single system can see, by construction, no matter how good it is.

05

The analysis compounds

Every review leaves behind a Lens, a saved analysis that can be run again on its own, together with its report and the features it built, so next quarter starts from this quarter rather than from a fresh export.

The dimension nobody in this category occupies

Does anything your programme does actually work?

Awareness training, reminder notices, watchlisting, access reviews, offboarding procedure. Every insider risk programme runs them and every one is defended with a narrative.

Nexyron carries 42 causal and decision procedures on the same graph as the access events. Uplift rather than association. Comparable populations identified rather than assumed. Policies compared against each other before the next control gets funded.

This is the one field where the record needed to answer it already exists, and it is the last field where anybody has tried.

Running it

For most of the category, deployment is a preference. Here it is a condition.

In several European jurisdictions a works council holds genuine veto power over systems that monitor employees, and it is exercised. Sovereign and defence environments restrict where data may be processed. Some regulated operators cannot place workforce telemetry into shared infrastructure at all.

Where any of those apply, the leading platforms are structurally unavailable regardless of how good they are, because their architecture requires the data to move.

Some of the organisations with the largest insider risk exposure in the world run the weakest programmes for exactly this reason. Nexyron runs entirely inside the perimeter, which is what makes the programme possible at all.

Take your last close call.

Ask what your organisation already knew before it escalated, and how many days those facts sat in three separate systems with nobody able to see them together.