LHB2Taylor, P. J., Dando, C., Ormerod, T., Ball, L., Jenkins, M., Sandham, A., & Menacere, T. (2013). Detecting insider threats to organizations through language change. Law and Human Behavior, 37, 267-275.

Summary Employees’ malicious use of their access to organisational information costs industry billions of dollars a year. This paper outlines a system that uses subtle, unconscious changes in an insider’s verbal behaviour to catch them in the act.

| Link to article in Law and Human Behaviour |

Abstract The act of conducting an insider attack carries with it cognitive and social challenges that may affect an offender’s day-to-day work behavior. We test this hypothesis by examining the language used in e-mails that were sent as part of a 6-hr workplace simulation. The simulation involved participants (N = 54) examining databases and exchanging information as part of a four-stage organized crime investigation. After the first stage, 25% of the participants were covertly incentivized to act as an “insider” by providing information to a provocateur. Analysis of the language used in participants’ e-mails found that insiders became more self-focused, showed greater negative affect, and showed more cognitive processing compared to their coworkers. At the interpersonal level, insiders showed significantly more deterioration in the degree to which their language mimicked other team members over time. Our findings demonstrate how language may provide an indirect way of identifying employees who are undertaking an insider attack.

Description Employees’ malicious use of their access to organisational information costs industry billions of dollars a year. This paper outlines a system that uses subtle, unconscious changes in an insider’s verbal behaviour to catch them in the act.