---
type: "term"
title: "Insider Threat"
description: "Not a TLCTC category."
resource: "tlctc:term:insider-threat"
tags:
  - "glossary"
---
# Insider Threat

Not a TLCTC category. The industry label mixes two rows of the cause-side partition that answer to different control regimes: an insider acting **inside** their entitlement against its purpose is **Abuse of Rights** (operational risk, no cluster, no SRE), while an insider reaching **outside** their entitlement is the **Attack** row and classifies to a cluster exactly as an outsider would (Axiom IV: the row is a property of the action, not the actor). A programme built around "insider threat" therefore procures endpoint and network telemetry for events that never pass through a compromise, and segregation-of-duties controls for events that do. TLCTC splits the label at the entitlement envelope (R-SCOPE).

See also: Abuse of Rights, Cause-Side Partition, Entitlement, R-SCOPE
