Insider Threat
Attribution · Investigation · Evidence That Holds
An insider case is an investigation that ends in a personnel action, litigation, or a prosecution. That changes how you work from the first day.
The evidence base is ten years of casework. As a cybercrime and financial crimes detective I worked out who was behind an anonymous account, followed money through financial records and across the blockchain, sat down with the person at the end of it, held chain of custody, and testified in court.
What follows is the record itself: cases worked, evidence handled, people interviewed, incidents directed. None of it is an insider threat program, and none of it is offered as one. An insider matter is decided on specifics: who did it, how you know, and whether the proof still stands when someone is paid to take it apart.
Attribution: Tying Activity to a Person
- An anonymous account, and a name at the end of it. Cyberstalking and online harassment cases, where the harm was to a person rather than a balance sheet. The work was attributing anonymous accounts to a real identity, preserving platform and account records before they aged out, and building the result into a chargeable case. Preservation comes first, because the records do not stay available while you think about it.
- Placing a device after the fact. FBI-trained in historical cell site analysis: call detail records and tower data used to place a phone geographically after the event. It located several missing people, including cases where the phone was already powered off.
- Attribution as a discipline, not a lookup. Trained across digital footprints, internet identifiers, advanced search and deep web searching, dark web investigations, sock puppet account creation, conducting secure online investigations, and maximizing social media search warrant returns. The point of all of it is the same: get from activity to a person, and be able to show your work.
The Money Side: Insider Fraud
- Complex financial crime cases, end to end. Scams, investment fraud, money laundering, and crypto. On-chain tracing, OSINT, financial records, live interviews, and forensics, driven to charges, prosecution, or referral.
- Million-dollar fraud matters worked using forensics, OSINT, and blockchain analysis.
- Following the money on a public ledger. Identified the capability gap and secured grant access to cryptocurrency-tracing tooling, integrated it into investigative workflows, and trained the team. Zero cost to the department.
- The reporting side of the same problem. Trained in forensic accounting and fraud examination, the Bank Secrecy Act, suspicious activity reporting, and how money moves. Insider fraud is usually visible in records somebody already holds, and the question is who asks for them and what they ask for.
Evidence That Survives Challenge
- Legal process, start to finish. Applied for subpoenas, authored and executed search warrants, held chain of custody, and testified in court across financial crime, cybercrime, and digital forensics cases.
- Cross-border evidence. In most online cases the proof sits with a company rather than the subject: the account records, the login history, the messages. When that company is in another country a normal search warrant does not reach it, and the route is a Mutual Legal Assistance Treaty request instead, the formal channel between two governments. It is slow and it has to be drafted correctly or it comes back empty.
- Cross-examined as a court-qualified expert. Completed the Drug Recognition Expert certification school and maintained it through recertification. Qualified by the court as an expert and testified as one. The value carried forward is the credential and the testimony record rather than the subject matter: work that holds up when someone is paid to take it apart. An internal report nobody contests is written to a lower standard, and it shows the first time it is contested.
The Interview
An insider case eventually reaches a conversation with the person. It is the part no tool does for you, and there is usually one chance at it: once the subject knows, the account activity changes and so does the account of events.
Trained in interview and interrogation, victim interviewing, and statement taking. Live interviews were part of running financial crime cases end to end, alongside the records and the forensics. The interview is the difference between a file that explains what happened and a file that also has the subject's own account of it in their own words.
When It Becomes an Incident
Some insider matters stay quiet and end in a personnel file. Others turn into an incident at speed, and then the questions all arrive at once: what left, when, who has to be told, and whether the response itself is about to destroy the proof.
- Incident command. Directed every P1 and P2 from declaration through restoration across time zones, from the West Coast to Hong Kong, coordinating teams of up to 20 people on sustained events.
- The breach-response coalition. Ran the coalition of breach counsel, third-party forensic firms, and the cyber insurance carrier, holding the evidence, chain of custody, and privilege each of them needs out of the same event. That means working out early whether this ends in litigation, with a regulator, or as an insurance claim, and preserving for that outcome before anyone thinks to ask.
Credentials
Backed by roughly 60 courses across financial crime, cryptocurrency and on-chain tracing, OSINT and dark web, digital forensics, interviewing, and legal process. The complete inventory is published at Certifications & Training. The casework behind it is set out at Investigations.