Risk AssessmentHigh riskComparison recommended

AI Playbook for Insider Threat Data Exfiltration

A defense contractor's DLP system flagged 4.2GB of data transferred to a personal cloud storage account by a senior engineer 3 days before their resignation date. The engineer had access to controlled unclassified information (CUI) and export-controlled technical data.

When to use this playbook

  • Use this playbook when the decision looks like the situation above: A defense contractor's DLP system flagged 4.2GB of data transferred to a personal cloud storage account by a senior engineer 3 days before their resignation date.
  • It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Insider Threat Data Exfiltration".
  • Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.

What you'll need

  • DLP alert log with file names, sizes, and destination URLs
  • Employee's access log (90 days: badge, system, VPN, print)
  • File classification inventory for accessed files
  • HR records: resignation date, notice period, any performance issues
  • CMMC and ITAR classification for the flagged files

Attachments: Documents (Documents)

The Prompt

You are a cybersecurity analyst investigating potential insider threat data exfiltration at a defense contractor. I am attaching:

Work only from the attached source files. If a conclusion is not supported, say so.

Produce:
1. Identify all data transferred in the 30 days before resignation: volume, file types, classification level, and destination (personal vs. competitor vs. foreign entity).
2. Assess whether any transferred files contain CUI or ITAR-controlled technical data and what the export control exposure is.
3. Reconstruct the access pattern in the 90 days before resignation—did the employee systematically access files outside their normal work scope?
4. Identify whether any files were accessed, copied, then deleted from company systems (evidence of cover-up).
5. Tell me whether this requires a mandatory DCSA report, what the employee device preservation steps are, and whether law enforcement referral is warranted.

Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.

What to expect

  • Data transfer inventory by classification level
  • Export control exposure assessment
  • Access anomaly timeline
  • Deletion cover-up analysis
  • DCSA reporting obligation and law enforcement referral checklist

Review before you act

  • Validate this output against source files before relying on it: Identify all data transferred in the 30 days before resignation: volume, file types, classification level, and destination (personal vs. competitor vs. foreign entity).
  • Validate this output against source files before relying on it: Assess whether any transferred files contain CUI or ITAR-controlled technical data and what the export control exposure is.
  • Validate this output against source files before relying on it: Reconstruct the access pattern in the 90 days before resignation—did the employee systematically access files outside their normal work scope?.
  • Validate this output against source files before relying on it: Identify whether any files were accessed, copied, then deleted from company systems (evidence of cover-up).
  • Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
  • Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
  • Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.

Why compare models on this

For Insider Threat Data Exfiltration, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface data transfer inventory by classification level; export control exposure assessment; access anomaly timeline; deletion cover-up analysis. Those are comparison artifacts — they only exist if more than one model runs. Models disagree on blast radius, attribution confidence, and whether a vendor finding is theoretical or exploitable. Those disagreements mark where an analyst should slow down.

CybersecurityIncident ResponseRisk AssessmentHighDocuments

See governed multi-model AI on your own prompt

Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.