Insider Threat / IP Theft
Operation Quiet Exit
A senior platform engineer submitted his two-weeks notice yesterday afternoon. Overnight, DLP tooling flagged an unusual bulk clone of the proprietary risk-scoring codebase and an attempted export of a customer PII table, both from his account, outside business hours.
Setting: Meridian Analytics, a mid-size fintech SaaS provider (~600 employees) building a cloud-native trading risk platform
Objectives
- Detect and contain unauthorized data exfiltration before it can be completed or the evidence destroyed.
- Preserve a legally defensible chain of custody throughout the investigation.
- Balance investigative advantage against the company's disclosure and notification obligations.
- Close the access-control gap that allowed the exposure, not just the individual incident.
Four Roles, Four Vantage Points
Each participant sees only what their role would realistically know — the exercise is as much about getting the right information to the right person in time as it is about the technical response.
Chief Information Security Officer
You are the CISO. Your focus is executive risk decisions, HR/Legal coordination, and protecting the company's IP and reputation.
SOC Incident Commander
You are the SOC Lead. Your focus is DLP alert triage, access log correlation, and real-time monitoring of the insider's activity.
Chief Compliance Officer
You are the GRC Chief. Your focus is evidentiary chain of custody, employment law exposure, and regulatory notification obligations if customer data was exposed.
VP of Platform Engineering
You are the VP of Engineering. Your focus is access revocation, credential rotation, and closing the architectural gap that let this happen.
Five Acts
A Real Decision, Illustrated
This is the actual first decision the Chief Information Security Officer faces in Act 1 — no two playthroughs go the same way after this.
How do you direct the initial response?
-
Authorize SOC to quietly monitor his account in real time to gather full evidence of intent before acting.
You build a stronger case, but he has more time to cause damage undetected.
-
Order immediate access revocation the moment HR confirms his resignation is real.
You stop further exfiltration fast, but risk losing the ability to prove intent.
What You Get At The End
Every completed run generates an After-Action Report — executive summary, full decision timeline, performance scoring mapped to NIST CSF 2.0, and a concrete improvement plan. See a sample report (PDF).