Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR040.001
  • Created: 02nd August 2026
  • Updated: 02nd August 2026
  • Contributor: The ITM Team

Testing Data Transfer Controls

A subject conducts a limited transfer of non-sensitive or low-value data to determine whether organizational controls detect, block, quarantine, or escalate the activity.

 

The subject may send a file to a personal email account, upload content to an unapproved cloud storage service, transfer data through a messaging platform, or use another external destination before attempting a larger or more sensitive transfer. They may vary the file type, size, classification, destination, compression, encryption, or transfer method to identify which conditions trigger Data Loss Prevention (DLP), web proxy, email gateway, or cloud access security controls.

 

The behavior may include a pause after the test while the subject waits to determine whether security personnel, management, or another authority responds. A successful test may establish a viable exfiltration route or reveal thresholds that can be avoided during a later infringement.