Investigations, evidence and insider risk, explained.
Practical guides, articles and a glossary from the team building Safrix, written for the people who run sensitive investigations.
What is an insider threat investigation?
Insider threat investigations are among the most sensitive an organisation runs. Here is what they involve, the lifecycle they follow, and why a defensible record matters as much as the finding.
Chain of custody for digital evidence: a practical guide
Chain of custody is the documented, unbroken record of who handled evidence and when. For digital evidence, getting it right is what makes findings hold up.
UEBA explained: how behavioural analytics surface insider risk
UEBA models normal behaviour and flags deviations. Used well, it helps investigation teams decide where to look first, provided the scoring can be explained.
Audit trails that stand up in disclosure
An audit trail is only as good as its integrity. Here is what separates a log that reassures from one that actually withstands scrutiny.
Least-privilege access for investigation teams
In sensitive investigations, who can see a case is part of the case. Least-privilege access is how you keep confidentiality and accountability at once.
Building an insider threat program: the first 90 days
You do not need a large team to start an insider threat program. You need clear scope, a defensible process, and the discipline to record everything.
Glossary
Plain definitions of the terms used across investigations, evidence and risk.