A finance manager downloads three years of customer records to a personal Google Drive on her last week before resigning. A help-desk technician falls for a vishing call and resets a privileged account. A long-tenured admin, frustrated by a denied bonus, deletes a backup volume on the way out. These are the three faces of insider threat, and traditional perimeter security has nothing useful to say to any of them.
Zero trust security in Malaysia is the architectural response. Assume no implicit trust, verify every action, and limit the blast radius when something goes wrong. This guide breaks down the three insider archetypes, the five zero trust principles that contain them, and the implementation roadmap Malaysian enterprises can run starting this quarter. The full security delivery sits inside Net Onboard’s managed cyber security services.
The Three Insider Threat Archetypes
Not all insider risk wears the same face. Three patterns repeat across Malaysian breach investigations.
- Malicious insiders. Employees or contractors with intent to harm. Common triggers: resignation, denied promotion, financial pressure, ideological motive.
- Negligent insiders. Well-meaning staff who click the phishing email, write the password on a sticky note, or share the wrong file with the wrong external party. Verizon’s 2025 DBIR found 60% of breaches involved the human element, and training programmes had no measurable effect on click rates.
- Compromised insiders. Legitimate credentials in attacker hands. Stolen credentials were the initial access vector in 22% of 2025 breaches per the same DBIR.
The malicious one needs deterrence. The negligent one needs friction and faster detection. The compromised one needs the system to stop trusting the credential just because it works. The point: same architecture answers all three, if it is applied consistently. The trouble starts when it is applied to some assets and not others.
Why Perimeter Security Fails Against Insiders
Perimeter security operates on a binary. Inside is trusted. Outside is not. The model assumes the attacker is somewhere out there, and the defence is to keep the perimeter intact. It is a useful model for buildings. Less so for a cloud estate where the perimeter is twelve concurrent OAuth tokens.
Insiders sit on the trusted side by definition. The malicious leaver already has the VPN profile. The negligent clicker already has corporate credentials. The compromised account is, by every system’s measure, the genuine user.
Verizon’s 2025 DBIR notes that 88% of basic web application attacks involved stolen credentials, and that traditional MFA bypass through token theft and prompt bombing is now common. APAC reported 1% of breaches as insider-led in the 2025 dataset, though that figure understates the reality, because negligent and compromised insiders are usually classified under their external trigger. Perimeter security catches none of these patterns reliably.

Five Zero Trust Principles for Insider Risk
- Verify identity continuously. Authenticate on every request, not once a day. Use phishing-resistant MFA (hardware keys, passkeys) for privileged accounts.
- Least-privilege access. Grant the minimum permissions needed for the task, time-boxed where possible. Standing admin access is the single largest insider risk lever.
- Micro-segmentation. Network paths between workloads default to denied. Lateral movement, the standard playbook for compromised insiders, stops at the segment boundary.
- Encrypt everything in transit and at rest. Encryption is table stakes. Key management is where it earns its keep. Separate the people who hold data from the people who hold keys.
- Assume breach. Design controls on the basis that a credential is already compromised. Behavioural analytics flag the privileged session that suddenly downloads 50,000 records at 2 a.m.
Most enterprises already do two or three of them, on the assets they remembered to apply them to. Zero trust is the discipline of doing all consistently, across identity, network, data, and workload layers, on every asset.
A 90, 180, 365-Day Implementation Roadmap
- First 90 days. Inventory privileged accounts. Enforce phishing-resistant MFA on every admin role. Map the top 10 data assets, classify them, and apply default-deny network policies around them.
- First 180 days. Roll out conditional access policies based on device posture, location, and behaviour. Implement just-in-time access for production systems. Stand up centralised logging into a SIEM with insider-specific detection rules.
- First 365 days. Extend micro-segmentation across the cloud estate. Operate a Security Operations Centre with insider behavioural baselines per role and per business unit. Run tabletop exercises against the three insider archetypes.
Malaysian enterprises starting from a baseline perimeter model typically clear the first 90 days with focused effort. The 180- and 365-day stages need sustained capacity, which is where most internal teams run out of bandwidth.
Four PDPA-Aligned Monitoring Controls
Insider monitoring sits in PDPA territory. Four controls work without crossing the line:
- Notice and consent. Privacy notices state what is monitored, why, and on what basis, in line with PDPA Section 7. Employment contracts back this with documented consent, or rely on Section 6(2) where processing is necessary for the employment relationship.
- Proportional monitoring. Behavioural analytics flag anomalies on data movement, privilege escalation, and unusual session times. Routine activity is not stored or reviewed. Malaysian legal commentary frames the test as necessity, proportionality, and consent; monitoring that fails any of the three sits on weak ground.
- Role-based access to monitoring data. SOC analysts see anonymised alerts. Identifying details require named, logged approval to access. This reflects the PDPA Security Principle, which now binds data processors directly under the 2024 Amendment.
- Retention limits. Monitoring logs follow the PDPA Retention Principle: personal data is not kept longer than necessary, with deletion after the defined period.
The PDPA Amendment 2024 raised fines to RM1 million per offence. Insider-monitoring programmes designed without legal input may increase your organisation’s risk.
Building Zero Trust That Holds
Zero trust is an operating model that holds across identity, network, data, and behavioural layers, and it needs continuous tuning as the threat surface shifts.
Cue Net Onboard, where AmplifyControl runs the design, the deployment, and the 24×7 detection-and-response capability for Malaysian SMEs and enterprises in regulated sectors.
Talk to our team about managed cyber security services that hold up against the insider threats that may already be in your vicinity.
