Insider Threat and Human Factors in Cyber Fraud
Most cyber frauds need a person to act. Sometimes that person works for the bank.
Unit 13 of the syllabus is called simply 'Human Traits', and it covers the part of cyber security that no firewall fixes. Most cyber frauds in banking need a person to do something: a customer to read out an OTP, a teller to skip a verification step, an officer to approve a change of mobile number without checking. Sometimes that person is deceived. Sometimes they are the fraudster.
RBI's 2016 Cyber Security Framework put it directly: managing cyber risk needs the commitment of the entire organisation and a high level of awareness among staff at all levels. This page looks at the human side from inside the bank: why staff make mistakes, why some turn into insiders, what the warning signs are, and which controls work.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Four Kinds of Insider Risk
An insider is anyone with legitimate access: employees, contract staff, vendors and business correspondents.
- Malicious insider
- Misuses access on purpose, for money or revenge. A branch employee who changes the registered mobile number on a dormant account so an accomplice can take over net banking.
- Negligent insider
- Means no harm but creates the opening. An officer who writes the core banking password on a sticky note, or shares it with a colleague to clear a queue.
- Compromised insider
- A genuine user whose credentials or device have been taken over, often through a phishing email. The attacker then acts with that employee's access.
- Third-party insider
- A vendor, outsourced service provider or business correspondent with access to systems or customer data. The bank remains responsible for what they do with it.
Why People Commit Fraud: The Fraud Triangle
A long-standing model in fraud risk management. Fraud usually needs all three; controls work by removing the one the bank can reach, which is opportunity.
Pressure
What it means
A financial or personal need the person cannot share
Bank example
Heavy personal debt, gambling losses, unrealistic targets
Opportunity
What it means
A weakness that lets the fraud happen and stay hidden
Bank example
No maker-checker on a change of contact details; the same person never goes on leave
Rationalisation
What it means
A story that makes it feel acceptable
Bank example
'I'll put it back before the audit', 'the bank owes me'
| Element | What it means | Bank example |
|---|---|---|
| Pressure | A financial or personal need the person cannot share | Heavy personal debt, gambling losses, unrealistic targets |
| Opportunity | A weakness that lets the fraud happen and stay hidden | No maker-checker on a change of contact details; the same person never goes on leave |
| Rationalisation | A story that makes it feel acceptable | 'I'll put it back before the audit', 'the bank owes me' |
Warning Signs
- check_circleBehaviour: avoids taking leave, resists job rotation, stays late or logs in at odd hours, insists on handling certain customers personally, lives beyond known means.
- check_circleSystem activity: access to accounts with no business reason, bulk downloads of customer data, repeated overrides, changes to customer mobile numbers or email IDs followed soon after by large debits.
- check_circleProcess: customer complaints clustered around one employee, unexplained reversals, suspense entries that keep ageing.
- check_circleCredential misuse: the same user ID active from two places at once, or used while the employee is on leave.
Quick practice on banking operations. No signup.
Controls That Address the Human Factor
- checkLeast privilege: each user gets only the access the role needs, reviewed periodically and removed the day someone leaves or moves
- checkSegregation of duties and maker-checker on sensitive changes such as mobile number, email, nominee and limits
- checkJob rotation and mandatory leave, so a hidden fraud surfaces when someone else does the work
- checkLogging and monitoring of privileged users, with alerts on unusual patterns
- checkBackground checks for staff and vendors, and contractual data protection terms for third parties
- checkRegular, practical awareness training built around real incidents, including simulated phishing
- checkA whistle blower channel staff trust, which RBI's fraud rules require banks to have and act on (the July 2024 Master Directions, carried into the July 2026 Directions that replaced them)
- checkExamination of staff accountability in every fraud case, also required by those Directions
What an Insider Faces Legally
Copying or altering customer data without authority is a section 43 contravention and, if done dishonestly, a section 66 offence under the IT Act (up to 3 years). Disclosing personal information obtained under a contract, with intent to cause wrongful loss or gain, carries a penalty up to ₹25 lakh under section 72A. Misappropriating money entrusted to an employee is criminal breach of trust under BNS section 316(4), up to 7 years, and up to life where it is committed by a banker in the way of business under section 316(5). Under section 85 of the IT Act, those in charge of the company can be held liable too unless they show due diligence.
How the IIBF Exam Tests This
- check_circleControl matching: job rotation and mandatory leave are detective controls against insider fraud; maker-checker and least privilege are preventive.
- check_circleInsider categories: an employee whose password was phished is a compromised insider, not a malicious one.
- check_circleFraud triangle: the element a bank's controls can remove is opportunity, not pressure or rationalisation.
- check_circleScenario questions: a sudden change of registered mobile number on a dormant account, followed by a large transfer, is a classic insider red flag.
FAQs
What is an insider threat in banking?expand_more
The risk that someone with legitimate access, an employee, contractor, vendor or business correspondent, misuses it, whether on purpose, through carelessness, or because an attacker has taken over their credentials.
What is the fraud triangle?expand_more
A model that says fraud usually needs three things: pressure on the person, an opportunity to commit and hide the fraud, and a rationalisation that makes it feel justified. Bank controls work mainly by removing opportunity.
Why do banks insist on mandatory leave and job rotation?expand_more
Many insider frauds need the fraudster to be present every day to keep them hidden. When someone else does the job, discrepancies surface. That makes these controls detective as well as deterrent.
Can a bank employee be punished for leaking customer data?expand_more
Yes. Depending on the facts, they can be prosecuted under IT Act section 66 and under the Bharatiya Nyaya Sanhita for criminal breach of trust or cheating, and made to pay compensation or a penalty under IT Act sections 43 and 72A (72A has been a monetary penalty, not imprisonment, since 30 November 2023), in addition to disciplinary action by the bank.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
