Insider threats: what can internal audit learn from a recent ICO case?

While external cyber threats continue to dominate headlines, many organisations remain more vulnerable to the misuse of legitimate access than they realise.

A recent case highlighted by the Information Commissioner's Office (ICO) illustrates why insider risk remains an important consideration for organisations handling sensitive information. In July 2026, a Herefordshire Council employee was prosecuted for unlawfully accessing approximately 490 records and downloading 94 documents containing highly sensitive personal information over a four-day period. The records included medical information, social worker reports and child and family assessments. He was sentenced to a two-month prison sentence suspended for 12 months, 120 hours of unpaid work, £2,000 costs and a £154 victim surcharge.

Although the incident involved a local authority, the underlying risks extend far beyond local government. Similar challenges exist across the education sector, local authorities, police forces, social housing providers, NHS organisations, children's services teams, adult social care teams and other organisations and teams responsible for safeguarding vulnerable individuals.

For internal audit functions, the case highlights an increasingly important question: how much assurance do organisations have that authorised access is being used appropriately?

Managing insider risk and access to sensitive data

Cyber security strategies often focus on preventing unauthorised access to systems and information. However, insider incidents demonstrate that risk can also arise from individuals who already have legitimate access.

In many cases, misuse is not the result of sophisticated attacks or technical weaknesses. Instead, it can stem from excessive access permissions, ineffective monitoring, poor supervision or a lack of challenge around whether access remains appropriate.

As organisations become increasingly data-driven and systems become more interconnected, ensuring that users only have access to the information they genuinely need is becoming a critical aspect of organisational resilience.

For organisations handling safeguarding information or sensitive personal data, the consequences of getting this wrong can be significant. Beyond potential regulatory action, incidents can undermine public trust, damage organisational reputation and potentially expose vulnerable individuals to harm.

How internal audit can address insider risk

The recent ICO case provides a useful reminder that access management should not be viewed purely as an IT responsibility.

At its core, this is a governance issue that spans cyber security, information governance, safeguarding and organisational culture. It therefore presents a valuable opportunity for internal audit to provide assurance over whether key controls are designed and operating effectively.

Rather than focusing solely on compliance with policies, internal audit can help organisations understand whether controls are genuinely reducing the risk of inappropriate access and whether unusual behaviour would be identified quickly if it occurred.

Internal audit checklist for insider risk controls

Many insider-related incidents have their roots in access management weaknesses.

Reviews should consider whether access is granted on a least-privilege basis (giving users only the bare minimum permissions and access needed to perform their jobs), whether permissions remain appropriate as roles evolve and whether joiner, mover and leaver processes are operating effectively. Particular attention should be given to privileged user access accounts and areas containing highly sensitive information.

The ability to detect unusual behaviour quickly is often what determines whether an incident becomes a minor concern or a major breach.

Internal audit can assess how activity is monitored, whether audit logs are reviewed and whether automated alerts are in place to identify unusual access patterns. Equally important is understanding how incidents are investigated and escalated once identified.

Strong information governance arrangements help ensure sensitive information is handled appropriately throughout its lifecycle.

This includes considering compliance with UK GDPR requirements, the management of special category data, staff awareness of data protection responsibilities and whether information-handling expectations are consistently applied across the organisation.

For organisations working with children or vulnerable adults, or victims of crime or domestic abuse, there is a close relationship between information governance and safeguarding.

Access to safeguarding and confidential records should be proportionate, closely managed and subject to appropriate oversight. Internal audit can play an important role in assessing whether governance arrangements recognise this connection and whether appropriate controls exist to protect highly sensitive information.

Common insider risk weaknesses identified by internal audit

Across many sectors, similar control weaknesses continue to emerge when reviewing insider-risk arrangements.

These frequently include excessive user access permissions, limited monitoring of user activity, inconsistent or underdeveloped information governance practices, gaps in training and awareness, and insufficient oversight of new starters or temporary workers.

Individually, these issues represent a control weakness that could expose organisations. Combined, however, they can create an environment where inappropriate access is less likely to be detected and challenged.

A growing assurance priority

Historically, organisations have focused significant investment on preventing external attacks. While this remains essential, insider risk is becoming an increasingly prominent consideration for boards, regulators and audit committees and internal auditors.

The lesson from this particular ICO case is clear. Organisations cannot assume that authorised access is always appropriate access. Internal audit has a key role to play in providing assurance that access controls, monitoring arrangements and information governance frameworks are operating effectively and protecting sensitive information from both external threats and internal misuse. Automation in relation to continuous assurance (and the use of AI and AI Agents) is also a key consideration for internal audit teams and 2nd line assurance.

How we can help

Our internal audit, risk assurance and cyber security specialists work with all organisations across the public sector (Police, Fire, Local Authorities, NHS, Central Government) and not for profit sector (housing associations, Education providers and Charities) and other public interest organisations to assess the effectiveness of governance, access management, safeguarding and information governance controls.

By providing independent assurance over key risks, we help organisations strengthen resilience, improve oversight and reduce the likelihood of inappropriate access to sensitive information. If you would like to discuss how your organisation can strengthen controls around insider risk, access management and information governance, contact Daniel Harris.

authors:daniel-harris