Chronological Examination of Insider Threat Sabotage: Preliminary Observations

SEI Report
In this paper, the authors examine 15 cases of insider threat sabotage of IT systems to identify points in the attack time-line.
Publisher

Software Engineering Institute

Abstract

The threat of malicious insiders to organizations is persistent and increasing. We examine 15 real cases of insider threat sabotage of IT systems to identify several key points in the attack time-line, such as when the insider clearly became disgruntled, began attack preparations, and carried out the attack. We also determine when the attack stopped, when it was detected, and when action was taken on the insider. We found that 7 of the insiders we studied clearly became disgruntled more than 28 days prior to attack, but 9 did not carry out malicious acts until less than a day prior to attack. Of the 15 attacks, 8 ended within a day, 12 were detected within a week, and in 10 cases action was taken on the insider within a month. This exercise is a proof-of-concept for future work on larger data sets, and in this paper we detail our study methods and results, discuss challenges we faced, and identify potential new research directions.  

Cite This SEI Report

Claycomb, W., Huth, C., Flynn, L., McIntire, D., & Lewellen, T. (2012, December 1). Chronological Examination of Insider Threat Sabotage: Preliminary Observations. Retrieved September 11, 2026, from https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/.

@techreport{claycomb_2012,
author={Claycomb, William and Huth, Carly and Flynn, Lori and McIntire, David and Lewellen, Todd},
title={Chronological Examination of Insider Threat Sabotage: Preliminary Observations},
month={Dec},
year={2012},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/},
note={Accessed: 2026-Sep-11}
}

Claycomb, William, Carly Huth, Lori Flynn, David McIntire, and Todd Lewellen. "Chronological Examination of Insider Threat Sabotage: Preliminary Observations." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, December 1, 2012. https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/.

W. Claycomb, C. Huth, L. Flynn, D. McIntire, and T. Lewellen, "Chronological Examination of Insider Threat Sabotage: Preliminary Observations," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 1-Dec-2012 [Online]. Available: https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/. [Accessed: 11-Sep-2026].

Claycomb, William, Carly Huth, Lori Flynn, David McIntire, and Todd Lewellen. "Chronological Examination of Insider Threat Sabotage: Preliminary Observations." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 1 Dec. 2012. https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/. Accessed 11 Sep. 2026.

Claycomb, William; Huth, Carly; Flynn, Lori; McIntire, David; & Lewellen, Todd. Chronological Examination of Insider Threat Sabotage: Preliminary Observations. Software Engineering Institute. 2012. https://www.sei.cmu.edu/library/chronological-examination-of-insider-threat-sabotage-preliminary-observations/