Blog

Inside the Firewall vs. Outside the Firewall: Why the Difference Matters for Insider Risk

by | Jul 28, 2026 | Blog

External Signals Come First

For years, insider risk programs have focused on what happens inside the network. Access logs, data transfers, authentication patterns, and behavioral analytics provide valuable signals, and catching anomalies in them matters.

But here is the problem: by the time those signals appear, the risk has usually already arrived.

The employee who has decided to exfiltrate data is already doing it. The fraudulent hire who fabricated their entire identity is already inside your systems. The contractor selling access to your network has already found a buyer.

Internal monitoring catches these events in progress. It was never designed to catch the conditions that created them, because those conditions developed outside the organization, where external signals for insider risk emerge long before internal tools can see them.

This is the gap that some insider risk programs have not closed. And it is not a small gap.

What External Signals Reveal About Insider Risk

Open-source intelligence, or OSINT (meaning intelligence gathered from publicly available and legally accessible sources), surfaces a category of external signals for insider risk that internal monitoring tools are structurally incapable of detecting.

These include:

  • Financial vulnerability indicators: public signals that suggest an individual may be susceptible to manipulation or coercion
  • Behavioral and sentiment shifts: changes in how someone presents publicly, including expressions of grievance, frustration, or disengagement that appear long before they manifest as internal incidents
  • Undisclosed affiliations: connections to competitors, hostile actors, or organizations that would raise concerns if they were known
  • Credential exposure: corporate login details appearing in breach datasets, sometimes months before anyone attempts to use them
  • Identity inconsistencies: discrepancies between a person’s claimed background and their verifiable digital footprint

None of these signals appear in a Security Information and Event Management (SIEM) platform – software that aggregates security event data from across an organization’s systems. None are captured by most Data Loss Prevention (DLP) tools or User and Entity Behavior Analytics (UEBA) platforms. They exist entirely in the external digital environment, visible to anyone who looks, but invisible to the tools most organizations have deployed.

The Timeline Advantage

Here is why this matters beyond just coverage.

External signals for insider risk tend to appear earlier in the risk pathway than internal ones. Financial pressure, grievance, and ideation (the early stages of insider risk development) frequently leave traces in the external digital environment weeks or months before they produce any anomaly in internal telemetry.

The organizations that detect insider risk early enough to intervene – before data moves, access is sold, or a fraudulent employee has spent months inside a sensitive environment – are the ones monitoring both directions. Inside, where incidents eventually surface. And outside, where the warning signs appear first.

This is the timeline advantage. And it is the difference between preventing an incident and responding to one.

Employment Fraud: When the Insider Was Never Who They Claimed to Be

The outside-the-firewall argument is highly visible, and urgent, in the context of employment fraud.

Traditional background checks are designed to verify what a candidate claims about themselves. They check criminal records, confirm employment history, and validate credentials. What they cannot do is verify that the person in front of you is actually the person those documents describe.

That distinction has become critically important.

In research recently published by Nisos, investigators spent four months running a North Korean operative as an unwitting intelligence source after a suspicious job candidate applied to Nisos directly. What they uncovered was not an isolated case of resume fraud, but an industrial-scale operation.

A single cell of 22 operatives submitted over 170,000 job applications between December 2024 and September 2025, securing 76 employment offers from US companies. Technology companies comprised 42.6% of their successful targets, with developers and engineers representing over 70% of pursued roles – positions offering high salaries, remote work flexibility, and access to sensitive systems.

The sophistication of the operation went well beyond falsified documents. Operatives built closed-loop reference networks where cell members provided employment verification for each other’s fabricated personas. They purchased identity packages through Telegram brokers, obtained fraudulent but legitimate-looking driver’s licenses, and digitally manipulated photos to match whoever would attend in-person screenings. During video interviews, operatives used AI-generated response overlays on their screens while maintaining eye contact with interviewers – in some cases with US-based facilitators attending interviews in person while the operative provided answers remotely.

These are not threats that traditional background checks are designed to detect. The documents were real. The references checked out. The interviews were convincing.

There were indicators that something was wrong, but they existed outside the organization, in the coordination happening through Discord servers and Telegram channels, in the inconsistencies between a candidate’s claimed background and their verifiable digital footprint, in the patterns visible to someone who knew where to look.

Identity Verification: a Missing Layer

The DPRK research illustrates a broader truth about pre-hire risk: document verification and identity verification are not the same thing.

Verifying a document confirms that a piece of paper says what a candidate claims it says. Verifying an identity confirms that the person presenting that document is who they say they are – that their professional history is consistent with their publicly observable digital presence, that their claimed background holds up against open-source scrutiny, and that there are no indicators of the kind of discrepancy that should prompt a closer look.

This is where OSINT-based identity verification adds a layer that traditional screening cannot. By examining what is publicly observable about a candidate – their professional history across platforms, the consistency of their digital footprint, and the absence of indicators that should raise concern – organizations can build significantly higher confidence in who they are actually hiring before access is granted.

This is not about invasive monitoring or building dossiers on candidates. It is about applying the same kind of external signal analysis to the pre-hire decision that a mature insider risk program applies to active employees, and doing it at the point in the lifecycle where it has the most leverage.

Inside and Outside: Two Halves of the Same Program

Employment fraud and insider risk are often treated as separate problems managed by separate teams. HR owns hiring. Security owns insider threat. The two functions work from different playbooks, have different skillsets, monitor different signals, and may not share what they know until something has already gone wrong.

But they are not separate problems. They are two phases of the same risk lifecycle.

An employee who becomes a risk during their tenure often shows warning signs that appear outside the organization long before anything surfaces internally. Treating these as separate problems – one for HR, one for Security – creates exactly the kind of siloed ownership that allows both to go undetected.

A trusted workforce program addresses both dimensions as part of a single, connected discipline. It monitors for external signals of insider risk during employment. It screens for identity inconsistencies and employment fraud before access is ever granted. And it applies the same outside-the-firewall intelligence approach to both – because the methodology that surfaces a fraudulent hire is the same methodology that surfaces a disgruntled employee being manipulated by an outside actor.

The threat does not respect the organizational boundary between HR and Security. The program should not either.

What an Outside-the-Firewall Approach Looks Like

A trusted workforce program that addresses both inside and outside the firewall looks different from a traditional insider threat program in a few important ways:

  • It monitors external signals systematically. Not ad hoc, not only when a concern has already been elevated, but as a continuous, scoped practice applied to populations where risk or concern is elevated.
  • It screens candidates for whether the person presenting those documents is who they claim to be, not just for what their documents say but.
  • It applies experienced analyst judgment to distinguish genuine risk from noise, because automated tools alone cannot make that call reliably at scale.
  • It shares what it finds across Security, HR, and Legal – because the full picture only emerges when the functions that each hold a piece of it are working from the same information.

None of this requires replacing existing internal monitoring tools. DLP, UEBA, and SIEM remain necessary components of a mature program. The question is what sits alongside them. And the answer, increasingly, is external signal intelligence that surfaces what those tools were never designed to see.

The Signals You’re Missing Are Already Out There

The DPRK research is an extreme example, but the principle it illustrates applies to every insider risk program, regardless of industry or threat profile.

The signals that matter – the warning signs that precede data theft, the identity inconsistencies that flag a fraudulent hire, the external coordination that no internal tool can detect – are often already visible. They exist in public posts, in digital footprints, in the data exhaust of a professional life conducted partly in the open. The organizations that find them are the ones that know where to look, and that have built the capability to look there systematically.

That is the difference between inside the firewall and outside it. It is the difference between a program that responds to incidents and one that prevents them.

Build a Program That Looks in Both Directions

If your current insider risk program relies primarily on internal monitoring, you are working with half the picture. The Trusted Workforce Handbook sets out a practical framework for closing that gap – covering the full signal landscape, the cross-functional program design that connects Security and HR, and a self-assessment to help you identify where your program stands today.

Frequently Asked Questions (FAQs) on External Signals for Insider Risk

K
L

What are external signals for insider risk?

External signals for insider risk are publicly observable indicators that may reveal elevated workforce risk before an employee gains access to organizational systems. These signals can include identity inconsistencies, credential exposure, financial vulnerability, undisclosed affiliations, and changes in publicly available digital activity.
K
L

How do external signals differ from traditional insider risk monitoring?

Traditional insider risk monitoring focuses on activity that occurs after an individual has access to corporate systems. External signals are identified outside the firewall and can help organizations recognize potential risk earlier in the employee lifecycle.
K
L

How does OSINT help identify insider risk?

Open-source intelligence (OSINT) analyzes publicly available information to identify external signals that internal security tools cannot detect. This information helps organizations verify identities, investigate inconsistencies, and assess workforce risk before it develops into an internal incident.
K
L

Why is identity verification important for insider risk?

Identity verification goes beyond confirming that documents are authentic. It helps determine whether a candidate's claimed identity, professional history, and publicly available digital footprint are consistent, reducing the risk of employment fraud and other pre-hire threats.
K
L

Can external signals replace SIEM, DLP, or UEBA?

No. External signal intelligence complements traditional security technologies rather than replacing them. SIEM, DLP, and UEBA remain essential for monitoring activity inside the enterprise, while external signals provide visibility into risks that develop before internal monitoring can detect them.

About Nisos®

Nisos is a trusted digital investigations partner specializing in unmasking human risk. We operate as an extension of security, risk, legal, people strategy, and trust and safety teams to protect their people and their business. Our open source intelligence services help enterprise teams mitigate risk, make critical decisions, and impose real world consequences. For more information, visit: https://nisos.com.