How Access Controls Stopped an Insider Threat
The Insider Threat That Almost Went Undetected And the Synology-Powered Access Controls That Caught It
When businesses think about cybersecurity threats, they often focus on ransomware groups, phishing attacks, and external hackers. However, some of the most damaging incidents originate from inside the organization itself. Insider threats, whether intentional or accidental, can bypass traditional security controls because the individual already has legitimate access to systems and data.
At Epis Technology, we recently worked with a client that experienced suspicious internal activity that initially appeared completely normal. Because the actions were being performed by an authorized user account, standard perimeter security controls never triggered alerts.
Fortunately, a combination of monitoring, auditing, and Synology access controls helped identify the activity before significant damage occurred.
The First Signs of Concern
The client operated a growing business with multiple departments accessing shared files, project documentation, financial records, and operational data.
Initially, there were no obvious indicators of compromise.
The environment appeared healthy:
- No malware alerts
- No failed login spikes
- No ransomware activity
- No unusual external connections
However, department managers began noticing unusual patterns involving file access and document activity.
Several employees reported:
- Files being opened unexpectedly
- Unusual document modifications
- Access to projects outside normal responsibilities
- Missing versions of certain documents
Individually, these events seemed minor. Together, they suggested a deeper issue.
Why Insider Threats Are Difficult to Detect
Unlike external attackers, insiders often have legitimate credentials and approved access to systems.
This makes detection more challenging because:
- Login activity appears normal
- Access requests seem authorized
- Traffic originates from trusted locations
- Security tools may not classify actions as malicious
In many cases, suspicious behaviour can continue for weeks or months before being discovered.
The client wanted answers before the situation escalated further.
The Investigation
Epis Technology conducted a detailed review of user activity, file access records, and storage permissions.
Our investigation focused on:
- File access patterns
- Permission assignments
- Administrative actions
- User activity logs
- Storage system auditing
The analysis revealed a user account accessing information well beyond normal business requirements.
Although the activity had not yet caused major damage, the behaviour represented a significant security and compliance concern.
Identifying the Root Cause
The issue was not caused by a software vulnerability or external attacker.
Instead, we discovered:
- Excessive permissions
- Poor role separation
- Legacy access assignments
- Inconsistent permission reviews
- Limited auditing visibility
Over time, access rights had accumulated as employees changed roles and responsibilities.
The result was an environment where some users had far more access than they actually needed.
Immediate Response
Once the risk was identified, Epis Technology helped the client quickly reduce exposure.
We:
- Reviewed user permissions
- Restricted unnecessary access
- Audited shared folders
- Examined administrative privileges
- Verified account activity
- Increased monitoring coverage
These actions immediately improved security while preserving business operations.
Leveraging Synology Access Controls
A major component of the solution involved improving controls within the client’s Synology environment.
The Synology infrastructure provided capabilities that allowed us to strengthen:
Role-Based Access Control
Permissions were aligned with actual job responsibilities.
Users received access only to the resources required for their roles.
Detailed Auditing
Enhanced logging improved visibility into:
- File access
- Permission changes
- Administrative actions
- User behaviour
Shared Folder Security
Sensitive information was segmented and protected using more granular access policies.
Administrative Oversight
Changes to permissions and critical resources became easier to monitor and review.
Building a Least-Privilege Security Model
One of the most important improvements involved adopting least-privilege principles.
Rather than granting broad access, permissions were assigned based on:
- Department responsibilities
- Operational requirements
- Business needs
- Compliance considerations
This significantly reduced insider risk.
Improving Monitoring and Visibility
The incident highlighted a common challenge.
Many organizations collect logs but do not actively analyse them.
To improve visibility, Epis Technology implemented monitoring for:
- Unusual file access activity
- Permission changes
- Administrative actions
- Sensitive data access
- Account behaviour anomalies
Earlier visibility dramatically improves response times.
Protecting Backup and Recovery Systems
Because insider threats can also affect recovery infrastructure, we reviewed the organization’s backup environment.
The client relied on Synology systems for:
- Backup storage
- Snapshot protection
- Disaster recovery
- File retention
Additional safeguards were implemented to ensure critical recovery assets remained protected.
The Results
Following the project, the client achieved:
- Improved access governance
- Better visibility into user activity
- Reduced insider threat exposure
- Stronger compliance readiness
- Enhanced auditing capabilities
- Improved business continuity protection
Most importantly, the organization gained confidence that unusual activity could be detected and investigated before becoming a serious incident.
Why Insider Threats Matter More
As organizations grow, access management becomes increasingly complex.
Businesses today face risks from:
- Excessive permissions
- Former employee access
- Accidental misuse
- Malicious insiders
- Compromised user accounts
Protecting against these risks requires more than traditional perimeter security.
Organizations need:
- Access controls
- Auditing
- Monitoring
- Least-privilege policies
- Backup protection
- Continuous reviews
About Epis Technology
Epis Technology helps organizations strengthen cybersecurity through Synology consulting, access control optimization, Microsoft 365 protection, backup automation, and disaster recovery planning. The company specializes in enterprise IT infrastructure, large-scale storage solutions, Microsoft 365 and Google Workspace backups, fully managed PC backups, cybersecurity resilience, and business continuity services.
By combining proactive monitoring, secure access management, and resilient storage architecture, Epis Technology helps businesses reduce insider risk while protecting critical data and maintaining operational continuity.