Insider Threat Matrix™Insider Threat Matrix™

Testing Security Controls

A subject deliberately performs a limited technical action to determine whether a security control, detection rule, workflow, or investigative process will identify, block, or escalate the behavior. The action may appear minor in isolation, but its purpose is to validate whether a later, more serious infringement can be conducted without detection or consequence.

 

This behavior is distinct from the Motive ‘Boundary Testing’, which describes the subject’s motive for testing organizational tolerance. 'Testing Security Controls' is the preparatory action itself: the subject probes a specific technical or procedural control to assess whether the organization detects, prevents, or responds to the activity.

 

Testing may involve sending a small file to a personal email account, uploading non-sensitive material to an unapproved cloud service, installing a minor unauthorized tool, accessing a restricted repository, printing a low-value document, using an unapproved browser extension, or attempting to bypass a proxy, DLP, CASB, EDR, or identity control. The subject may then wait to see whether they are contacted by security, management, HR, or another authority, or simply confirm whether the action succeeded.

 

Successful testing may increase confidence, refine the subject’s method, or identify a viable path for later data exfiltration, unauthorized access, policy circumvention, sabotage, or another infringement.

 

Investigative Relevance

Testing security controls is often visible through low-volume, low-impact actions that precede more serious activity. The key investigative feature is not the technical action alone, but the pattern of deliberate probing, success validation, delay, and later escalation.

Investigators should assess whether the subject conducted a small-scale action before a larger attempt, repeated similar activity across different channels, or paused after the test to observe whether a response occurred. A delay between the test and later infringement may indicate that the subject was assessing organizational reaction time, alert handling, or enforcement consistency.

 

Example Scenarios:

  • A subject emails a harmless internal document to a personal account and waits several days before attempting to transfer sensitive files.
  • A subject uploads a small non-sensitive file to an unapproved cloud storage platform to test whether DLP, proxy, or CASB controls block the upload.
  • A subject accesses a repository outside their normal role scope and monitors whether an access review, manager notification, or security alert follows.
  • A subject installs an unauthorized browser extension to determine whether browser or endpoint controls detect unapproved extension use.
  • A subject compresses, renames, encrypts, or stages a small test file before applying the same method to sensitive data.

Subsections (6)

ID Name Description
PR040.002Testing Access Controls

A subject attempts to access a system, repository, application, physical area, account, record set, or other restricted resource to determine whether the applicable access control prevents entry or generates a response.

 

The subject may use their own identity to request or attempt access slightly outside their normal responsibilities, test an expired or unauthorized physical identity token, navigate directly to a restricted application resource, or attempt to view information associated with another team, customer, case, or business function.

 

The action may be deliberately limited so that it can be described as accidental if challenged. Repeated denied attempts, access testing across several resources, or a later successful entry may indicate that the subject is mapping authorization boundaries before conducting unauthorized access or another infringement.

PR040.001Testing Data Transfer Controls

A subject conducts a limited transfer of non-sensitive or low-value data to determine whether organizational controls detect, block, quarantine, or escalate the activity.

 

The subject may send a file to a personal email account, upload content to an unapproved cloud storage service, transfer data through a messaging platform, or use another external destination before attempting a larger or more sensitive transfer. They may vary the file type, size, classification, destination, compression, encryption, or transfer method to identify which conditions trigger Data Loss Prevention (DLP), web proxy, email gateway, or cloud access security controls.

 

The behavior may include a pause after the test while the subject waits to determine whether security personnel, management, or another authority responds. A successful test may establish a viable exfiltration route or reveal thresholds that can be avoided during a later infringement.

PR040.003Testing Endpoint and Application Controls

A subject performs a limited action on an organizational endpoint to determine whether software restrictions, endpoint security controls, browser management, device controls, or application policies prevent or report the behavior.

 

The subject may install a low-impact unauthorized application, add a browser extension, execute a portable utility, alter a minor endpoint setting, or attempt to run software from an unusual location. They may also connect a removable device or use a test script to establish whether application allowlisting, Endpoint Detection and Response (EDR), antivirus, mobile device management, or device-control policies are active.

 

The test may be designed to resemble ordinary experimentation or troubleshooting. Investigators should consider whether the subject subsequently used the same installation method, application type, device, or control weakness to support data collection, persistence, circumvention, or another infringement.

PR040.006Testing Monitoring and Response Processes

A subject conducts a minor policy violation or suspicious action to determine whether the organization detects the behavior, how quickly it responds, and which personnel or processes become involved.

 

Unlike testing a particular technical control, the subject is assessing the organization’s wider investigative and enforcement response. They may perform an observable but low-impact action, wait to see whether they are contacted, and use the absence, timing, or nature of the response to estimate alert-review practices, escalation thresholds, investigative coverage, or Organizational Tolerance.

 

The subject may repeat similar tests through different systems or channels to establish whether detections are centrally correlated. They may also deliberately pause before escalating, allowing time to determine whether the test has produced a security, management, Human Resources, or compliance response.

 

Investigators should look for a sequence consisting of a minor test action, an observation period, and a later increase in severity or volume. Repeated low-level infringements without corrective intervention may provide the subject with confidence that more serious activity will also go undetected or unenforced.

PR040.004Testing Network Security Controls

A subject performs limited network activity to determine whether firewalls, network segmentation, Domain Name System filtering, web proxies, intrusion detection systems, or protocol restrictions identify or block the connection.

 

The subject may attempt to reach a prohibited domain, connect to a restricted port, access another network segment, use an unapproved protocol, configure a proxy, or send a small amount of traffic through a normally restricted route. The objective is to establish whether the network path is available and whether the activity produces an alert or investigative response.

 

Testing may be repeated across different destinations, ports, protocols, systems, or times of day. A subject may use the results to select a less monitored network route, bypass segmentation, communicate with external infrastructure, or prepare a data-transfer channel.

PR040.005Testing Physical Security Controls

A subject performs a limited physical action to determine whether access controls, security personnel, surveillance, visitor procedures, alarms, or other physical safeguards prevent or identify unauthorized presence.

 

The subject may test a restricted door, present a credential at an unauthorized area, follow another person through a controlled entrance, remain in an area after their approved access period, or enter a sensitive location without a clear operational reason. They may also observe whether security personnel challenge unfamiliar subjects or whether physical access violations generate follow-up activity.

 

The behavior is distinct from general physical exploration because the subject actively interacts with or crosses a security boundary to evaluate the result. The test may support later unauthorized entry, physical sabotage, theft, access to infrastructure, or facilitation of another person’s presence.