PREVENT is a taxonomy of 1,060 indicators — observable
conditions and behaviours that, taken together, describe how insider risk builds
before anything harmful happens.
It is not a list of warning signs to memorise. It is a shared vocabulary,
and that is the entire point. A SOC analyst, a supervisor and an auditor all see
different things. Without a common frame those observations never meet. With one,
they can be compared, correlated, and acted on together.
Every indicator carries the same five fields
Tier 1
The broad family — ten of them
Tier 2
The specific subgroup — 68 in total
Domain
Who is most likely to see it first
Temporal Role
Where it sits on the path from condition to act
Signal Nature
Behavioural, Cyber, Structural or Operational
Classification means assigning all five, consistently, so that another analyst
would reach the same answer. Consistency is what lets a cyber signal and a
supervisor's observation sit in the same assessment.
You will have the full taxonomy in front of you today. Nothing here is a
memory test.
your notes
2 of 18
How today works
You will not use Glazer today
That is deliberate. Yesterday was the instrument; tomorrow you point it at
something. Today is the framework the instrument serves.
If you can only classify with the tool open, you have
learned the tool and not the framework. PREVENT has to work on paper, in a
meeting, and in an organisation running a completely different stack.
What you will do
Read observations and assign all five fields to each
Search the real taxonomy to find the indicator that fits
Argue for your answer — several are genuinely contestable, and the argument
is the exercise
Your work
Answers and notes are saved as you go and travel with you. Export at each break
— your facilitator will use the cohort's answers for group review, and where the
room disagrees is usually where the interesting discussion is.
One warning about today's subject matter. This framework describes
how ordinary people become vulnerable. Handled carelessly it becomes a way to
build suspicion about colleagues. Module 1.5 deals with that directly, but it is
worth carrying from the first page.
your notes
3 of 18
Three programmes, three signals, no shared frame
Most organisations already collect what they need to see insider risk coming.
The problem is that the signals never meet.
cyber
Authentication patterns, data transfers,
privilege use. Objective — and stripped of human context.
behavioural
Conduct shifts, workplace dynamics,
procedure adherence. Rich in context, hard to evidence.
organisational
Policy compliance, training gaps,
governance weakness. Verifiable, and usually ignored.
Each stream produces something useful. Each is assessed in isolation, by a
different function, against a different threshold.
The recurring pattern in post-incident reviews is not that the signs
were absent. It is that they were present, in different systems, held by
different people, and nobody was in a position to see them as connected until
afterwards.
PREVENT does not add a new sensor. It adds a common
frame, so that things already being seen can be seen together.
check yourself
Your SOC flags off-hours access. A supervisor separately notes a colleague has become withdrawn. Neither meets its own threshold for escalation. What has PREVENT changed?
your notes
4 of 18
Vulnerability is a condition. Intent is a state of mind.
This is the load-bearing sentence of the entire course, and everything else
rests on it.
Observable indicators can surface vulnerability — the
conditions that make harm more possible. They cannot reliably determine
intent, because intent is internal and unobservable.
A framework that infers intent produces three predictable failures:
False positives. Most people under financial stress do
nothing wrong. Treat stress as intent and you will accuse the innocent, often.
Loss of trust. Once a workforce believes the programme
judges character, reporting stops — and reporting is the highest-value input
you have.
Legal exposure. An adverse action justified by inferred
motive is difficult to defend anywhere, and indefensible in several
jurisdictions.
Phrase every finding as a condition, never a verdict.
"This person has unresolved financial stress and privileged access" is a
finding. "This person is a risk" is an accusation wearing a lanyard.
You will be tested on this repeatedly, in Lab 1.A today and in
every day after. The most common failure is not misclassification — it is a
correct classification phrased as a judgement.
your notes
5 of 18
Where PREVENT sits
PREVENT is not a replacement for the frameworks you already use. It occupies
a gap in front of them.
The conditions and observable indicators
before adversarial behaviour begins
SOFIT
Represents the insider-threat problem space —
behavioural, organisational and cyber together
ATT&CK
Adversary techniques during
active operations
INF1LTRATE
Insider tradecraft during active
operations
SOFIT improved how the problem is represented. PREVENT improves how it
is operationalised — signal, correlation, risk state, proportionate
action. Where SOFIT tells you what matters, PREVENT tells you what to do next.
Used together they cover the whole timeline. PREVENT reduces the conditions
that make a technique viable; it does not predict which technique.
your notes
6 of 18
Six stages, and it is a loop
1
Vulnerabilities Underlying conditions,
individual and organisational
Identify susceptibility, not blame
2
Indicators Observable signals across
three input domains
Stage 6 feeds back into Stage 1. This is not a pipeline with
an exit. Risk states are reassessed continuously, and the goal of an intervention
is to return someone to baseline — not to build a case.
Stage 3 is the analytic core. Stages 1 and 2 gather; Stage 3 is where judgement
happens and where the framework earns its keep.
your notes
7 of 18
Vulnerability exists at two levels
Stage 1 is where most programmes go wrong, because they look only at people.
Not character flaws. Circumstances that create pathways.
organisational conditions
Inconsistent policy enforcement · training gaps · access-control gaps ·
governance weaknesses surfaced by audit
Can be exploited knowingly or unknowingly.
Neither level alone is a threat. An employee under financial
stress in a well-governed organisation is an employee under financial stress. An
access-control gap with nobody motivated to use it is a finding for the auditors.
It is the combination that constitutes meaningful vulnerability.
This cuts both ways, and the second direction is the one
people forget: you can reduce risk without touching the individual at
all. Closing the access gap works. It is often faster, cheaper and
considerably less damaging than any intervention aimed at a person.
Hold that thought for Lab 1.A. Two of the observations you will
classify have their strongest indicator at the organisational level, and learners
who look only at the individual will miss the most important finding available
to them.
check yourself
An employee with financial stress works in a team where privileged access is never reviewed. Which is the more actionable finding?
your notes
8 of 18
From signals to action
Stage 2 — three streams, one catalogue
Cyber — logs and monitoring. Objective, and blind to context.
Individual — workplace observation, supervisory and formal
reporting. Supplies the context the cyber stream lacks.
Organisational — audits, training records, access reviews.
Explicit and independently verifiable.
All three map against the same 1,060 indicators, and all three enter as
equal inputs. No domain is primary. A supervisor's observation is
not lesser evidence than a log line — it is different evidence.
Stage 3 — correlation, then triage
Correlation looks for three things: temporal alignment (did these
happen together?), pattern aggregation (is this recurring?), and
cross-domain reinforcement (do independent streams agree?).
Triage then deprioritises the isolated and transient, and elevates the
recurring, clustering and cross-domain. It is not mechanical — it needs judgement
informed by your environment and your workforce's actual baseline.
Stages 4 to 6
The risk state classifies the pattern. The intervention is calibrated to the
state. The outcome feeds back.
The goal of Stage 5 is to fix the
vulnerability, not to log that you found it. An intervention that
documents a condition and changes nothing has not reduced risk — it has only
created a record.
your notes
9 of 18
The five fields
Classification means assigning all five. Here is a real indicator with its
fields, so you can see the shape before you try it.
TECH-AUTH-039
The individual accesses systems from unmanaged devices.
Tier 1TECH
Tier 2TECH-AUTH
DomainIT
Temporal RolePre-Attack
Signal NatureCyber
Read it back: this is a technical indicator about authentication,
most likely to be caught by IT, sitting at the preparation stage
of the pathway, and it is a cyber signal.
The two that get confused
Domain is not Signal Nature. Domain says who sees it.
Signal Nature says what kind of thing it is. A behavioural signal can sit
in the SOC domain; a cyber signal can be surfaced by a supervisor. They vary
independently, and conflating them is the most common classification error.
Consistency matters more than any individual answer. The
framework's value comes from two analysts reaching the same classification — which
is why arguing about a contested one is worth more than silently picking.
your notes
10 of 18
Ten families, 1,060 indicators
Search it. Filter it. Get a feel for how big each family is and what kind of
language the indicators use — you will need that fluency in the lab.
1 Which Tier 1 family is largest? Does
that surprise you?
2 Filter to Latent Condition. What do
almost all of those have in common?
3 Search credential. Note how many
different families it appears in.
Task 2 has a striking answer. All 130 Latent Conditions
sit in ORG — every single one. They are things the organisation is
doing, or failing to do, rather than anything a person did. That is not an
accident of drafting: a condition nobody created by acting is, definitionally,
structural.
your notes
11 of 18
Temporal Role — the hardest field
Tier 1 and Signal Nature are usually obvious from the text. Temporal Role is
not, and it is where classifications diverge.
Latent Condition
A standing state that raises
susceptibility. Usually organisational. Nobody did anything.
Drift
Movement away from an established baseline.
Change is the signal, not the behaviour itself.
Pre-Attack
Preparation. Capability or access being
assembled.
Execution
The act, or its immediate conduct.
Constraint or Inhibitor
Something that would
reduce risk and is absent or failing.
Risk Amplifier
Something that makes an existing
condition worse.
Two tests that resolve most disputes:
Did anyone do anything? If not, you are almost certainly in
Latent Condition.
Is the signal the behaviour, or the change? If a person has
always worked late, that is a baseline. If they started three weeks ago, that is
Drift.
check yourself
"The organization does not review privileged access on a recurring basis." What is the Temporal Role?
your notes
12 of 18
Lab 1.A — classification
Eight observations from a single organisation. For each, find the indicator and
assign the fields.
They come from Quillon Grid, a fictional operator you will meet
again tomorrow — when you will collect several of these findings yourself rather
than being handed them.
Two things worth knowing before you start. Some
observations have their strongest indicator at the organisational
level. And one of the eight has no indicator at all — recognising
that is the point of it being there.
Where you disagreed with the answer key, say so in your notes. Two
of these mappings are contested by the people who built the course, and the
framework's author is reviewing them. A well-argued disagreement is more useful to
us than a correct guess.
your notes
13 of 18
Four risk states
A risk state classifies a correlated pattern, never a single
indicator. One signal is never a state.
Baseline
Normal variation. Isolated or transient
signals, no reinforcement across domains.
Continue standard
posture
Elevated
Recurring or clustering signals. Some
cross-domain reinforcement.
Observe; verify context
Heightened
Sustained multi-domain pattern.
Vulnerability is compounding.
Engage; consider access
adjustment
Escalating
Reinforcing pattern with preparation
indicators.
Act; formal pathways
States move in both directions. Returning someone to Baseline is a
successful outcome, and if your programme never records one, that
is itself a finding about your programme.
your notes
14 of 18
Over-intervention erodes the programme
The temptation, having found something, is to act on it. Resist it.
An intervention disproportionate to the risk state does measurable damage:
The individual learns they are under suspicion, and behaviour changes in
ways that make future assessment harder
Colleagues notice, and reporting — your best input — dries up
The programme acquires a reputation, and reputations are very hard to
reverse
A programme that over-intervenes stops receiving the
information it depends on. You do not get a second chance at a workforce's
willingness to tell you things.
The response menu is graduated for a reason: observe → monitor → engage →
adjust access → formal action. Most patterns should be resolved in the first
two. If yours routinely are not, the problem is your thresholds, not your
workforce.
Tomorrow you will meet this as configuration rather than principle —
intrusive collection sits behind an escalation gate that only opens as the risk
state rises. The doctrine is enforced by the tool, not just recommended by it.
your notes
15 of 18
Vulnerability-not-intent, in practice
Everyone agrees with the principle. It fails in the wording.
"He seems disgruntled and has admin rights."
"Unresolved grievance recorded 12 March; retains
privileged access unreviewed since 2024."
"She's been acting suspiciously."
"Access pattern diverged from her established baseline in
three of the last four weeks."
"Financial problems — possible motive."
"Financial stressor present. Combined with unmonitored
access to payment systems."
The right-hand column states conditions, sources and dates. The left states
conclusions about a person. Only one survives being read aloud in a hearing.
What you owe the subject
Documentation — what you assessed and on what basis
Proportionality — an intervention matched to the state
Transparency, to the extent the situation permits
A route back — resolution must be possible, or the
programme is a one-way ratchet
your notes
16 of 18
Jurisdiction changes what you may do
This framework is used internationally, and the constraints are not the same
everywhere. These are illustrative anchors, not legal advice, and your counsel
decides.
EU / EEA
GDPR lawful basis, and in several states a
works council with real veto over monitoring
United States
State privacy law; sector regimes;
adverse-action procedure where a report informs a decision
Canada
PIPEDA, and provincial equivalents
Brazil
LGPD
China
PIPL, with data-localisation consequences
Sector frameworks add another layer — nuclear, aviation, and financial
personnel-reliability regimes each impose their own requirements on what you must
do, and on what you may not.
The question is rarely "can we technically collect
this?" It is "can we collect it, act on it, and defend both — here, under this
regime, for this person?" Those come apart more often than teams expect.
your notes
17 of 18
The trap
The failure mode of this framework is not that it misses things. It is that it
becomes an instrument for building suspicion about colleagues, with a taxonomy
attached to make it look rigorous.
Every indicator you have learned today describes something that happens to
ordinary people. Financial stress. Grievance. Withdrawal. Working odd hours. These
are features of normal working lives, and the overwhelming majority of people
exhibiting them will never do anything wrong.
PREVENT tells you where vulnerability is
concentrated. It does not tell you who is dangerous, and a programme that uses it
that way will be both wrong and harmful — usually to people already having a
difficult time.
Three habits that keep you honest
Write findings as conditions. If your sentence has an
adjective about a person in it, rewrite it.
Look for the organisational indicator first. It is often
the stronger finding and it never accuses anyone.
Record what you looked for and did not find. A file
containing only hits is not an assessment.
your notes
18 of 18
Where you should be
You should now be able to, without looking anything up:
Say what distinguishes vulnerability from intent, and why it matters
legally as well as ethically
Name the five fields and explain how Domain differs from Signal Nature
Assign a Temporal Role and defend it
Explain why an organisational indicator is often the more actionable
finding
State what a risk state classifies — and what it does not
Tomorrow you point the instrument at something. You will collect findings from
the same organisation you classified today, and you will map what you find back
into this framework. The classification discipline is what makes the collection
worth anything.
Export your notes before you leave. Your Lab 1.A answers feed
tomorrow's mapping exercise, and where the room disagreed today is where the
facilitator will start.
check yourself
Final one. A finding reads: "Subject has significant debt and access to financial systems; recommend removal of access." What is wrong with it?