When content categories converge, insider risk grows

Anna Borgström

CEO | NetClean

Online harms are no longer developing in separate lanes.

Tech Against Terrorism and the Trust & Safety Forum describe this as the “hybridisation” of online harms: the lines between terrorist, violent and extremist content, CSAM, image-based sexual abuse and disinformation are becoming increasingly blurred.

These different categories often share infrastructure, distribution channels and evasion tactics. This means they can no longer be viewed only as separate detection problems.

What convergence means for insider risk

At NetClean, we are seeing the same convergence in our own data.

Around half of the detections we have made over the years have included other types of high-risk content, such as material related to weapons, violence or radicalization.

That is an important indicator. It tells us that the content itself may only be one part of the security problem. What it reveals about behavior, vulnerability and potential risk can be just as significant.

The content itself may only be one part of the security problem. What it reveals about behavior, vulnerability and potential risk can be just as significant.

Expanding what organizations can detect

This is why we are building out our platform.

NetClean pioneered the detection of CSAM in enterprise environments. We are now applying that same pioneering approach and hash-based precision to other types of high-risk material, including terrorist, violent and extremist content.

These can reveal important indicators of human insider risk, yet they remain largely invisible to traditional security tools.

When someone with access to an organization’s systems is consuming or storing material they need to conceal, that secrecy can create vulnerability. It may expose the individual to coercion, manipulation or blackmail. The presence of certain types of high-risk content can also provide important context when assessing potential insider risk.

At that point, it is no longer only a content issue. It becomes relevant to the organization’s wider understanding of human insider risk.

Closing the visibility gap

Most organizations have invested heavily in EDR, XDR, DLP and SIEM. These are essential security tools, but they are generally not designed to identify these types of risk indicators when someone is operating with legitimate access.

Closing that visibility gap means bringing new intelligence into the security environments organizations already use.

That is why we are bringing NetClean’s risk intelligence into Microsoft environments, allowing organizations to use it within the security tools and workflows they already have in place.

Learn more about how NetClean risk intelligence can be used with Microsoft Defender for Endpoint and Microsoft Sentinel →

As different categories of high-risk content continue to converge, organizations need a practical way to bring this intelligence into their existing security operations.

That is what we are building.

Our mission just got bigger

NetClean is expanding ProActive to include intelligence on terrorist and violent extremist content (TVEC), adding a new category of human insider risk indicators alongside CSAM. Read the launch announcement →

Want to understand what emerging human insider risk indicators could mean for your organization? Talk to our team →