When extremist content becomes an insider risk
A TVEC indicator does not prove intent or show that someone poses a threat. But it is information a security team should not ignore. Combined with trusted access, repeated activity or other risk factors, it can reveal risk that traditional cybersecurity controls are not designed to see.
Insider risk grows around people who already have access
Insider risk does not always start with someone trying to infiltrate an organization. It can grow around people who already have legitimate access, as their circumstances, motivations, relationships or behavior change over time.
Outside actors may try to exploit that access through recruitment, manipulation or coercion. What an indicator means therefore depends on how it connects to the person's role, access and wider situation.
Hostile states look for people who may be willing
Security and intelligence agencies increasingly describe a landscape where state actors and violent extremists overlap. Sweden's Military Intelligence and Security Service (MUST) has warned that individuals in violent extremist environments can be used by state actors as proxies for intelligence and hybrid threat activities. Norway's Police Security Service (PST) has highlighted how employees recruited by foreign actors may be asked to identify weaknesses in their own organizations.
As tensions rise, people with trusted access become more attractive to outside actors. For organizations in critical infrastructure, government, defense and other sensitive sectors, human insider risk is increasingly a question of national security.
When geopolitical tension rises, the people with access to your systems become more interesting to others. That makes insider risk a security question, not only a matter for HR or IT.
Traditional security tools are not built to see TVEC
Terrorist and violent extremist content keeps circulating. Reporting from the Global Internet Forum to Counter Terrorism (GIFCT) shows how much of it exists and how long it lasts. Once produced, it can be copied, edited and shared again long after the event that created it.
Traditional security controls are built to detect malware, intrusion and data loss. A verified TVEC indicator is a different kind of intelligence, connected to people rather than to a cyberattack. Many organizations can see in detail what is attacking their systems but have far less insight into risk building up around people who already have access.
That is why a verified TVEC indicator should be taken seriously and assessed through established security and insider risk processes, even though it is not a traditional cyber threat.
The indicators come from trusted external sources
Organizations should not have to decide what counts as an extremist belief, political opinion or ideology. The focus should be on verified indicators based on intelligence from trusted external sources.
NetClean ProActive brings curated and verified TVEC Risk Indicators from trusted external intelligence sources, including Tech Against Terrorism, into existing security environments and workflows. The technology does not draw conclusions about anyone. It provides verified intelligence that can be assessed alongside access, context and other risk indicators.
Organizations should not have to judge what an employee believes. What they need is verified intelligence that can be assessed in the right context.
TVEC adds a new dimension to human insider risk
When a verified indicator meets trusted access, a sensitive environment or other risk factors, it can give an organization information it would otherwise not have.
This is part of the thinking behind NetClean's expansion of ProActive. The aim is to help organizations identify verified human risk indicators that conventional security tools are not designed to detect, and to assess that risk before it contributes to a more serious security incident.
What risks are you not seeing?
Our whitepaper From extremist content to insider risk goes deeper into what TVEC is, why it matters from an insider risk perspective, how the material spreads and how verified intelligence can support existing security operations. Download the whitepaper → Talk to NetClean →
More articles
You might also like...
Contact us
Talk to an expert
Explore how NetClean ProActive can bring specialized human insider risk intelligence into your existing security environment.