When the Enemy Is Already Inside the Dealership: Insider Threats You Can’t Ignore

By Richard Foster - Retired UK Cop, Ransomware Negotiator & Cybercrime Specialist from Brainstorm Security Ltd.
Have you noticed that when there is a major criminal heist or a large high value burglary, that often the bad guys had a ‘Inside man’? That's what I want to talk about…the threat from the inside man.
I can explain this best by telling you a tale from my youth. When I was a teenager, one of my best friends Matty, had a real crush on a girl. She was going to the Lake District in the UK on a field trip with her college, which was about 100 miles away. I quite fancied her friend, so we cooked up a plan to drive over to the Youth Hostel where they were staying, so he could declare his undying love for her.
The trouble was, we were only 17 or 18 years old at the time and didn't have a car. Luckily for us, Matty's dad owned a large premium car dealership at the time, and Matty had started work there as a mechanic. He asked his dad if he could borrow one of the ’pool’ cars used by customers who were getting a car serviced or repaired, for the weekend trip away. To my astonishment, he agreed!
On the day of the trip, Matty drove to collect me from my house. Instead of the expected ‘pool car’ he arrived with a massive beaming smile in a brand new, top of the range sports car! This was the 1980s, so it even had pop up lights at the front! He was out to impress this girl! Off we drove on a wild weekend trip, not thinking about the consequences.
Now with my law enforcement head, Matty had technically stolen the car and would not have been insured in the event of an accident. It could have cost the dealership dearly had something gone wrong.
He had unknowingly become an insider threat to his dad's car dealership. Although he was a trusted family member and employee, he had gone against the policies and procedures set out by the dealership and his father, which was wrong, (even for love!)
This kind of threat doesn't come wearing a ski mask or hiding behind a shady email address. Nope. This type has a keycard, a company polo shirt, and maybe even your old parking spot. They are employees.
I’m talking about insider threats, and I don’t mean someone stealing paperclips from the parts counter. I’m talking disgruntled employees, contractors, and staff who know your systems better than most hackers ever will.
And if you're thinking, "That wouldn’t happen at my dealership!" - friend, I’ve got news for you.
We have probably all worked with someone who we know are unhappy. Maybe they don't like someone else at your work place, a colleague or a line manager? They might already be job hunting and looking for new opportunities away from their current employee. What would be of use to them in a new role? Customer data, insider information or maybe data on pricing with suppliers? What is stopping the employee extracting the data now before they leave?
Another example would be an employee who is excellent at their job, well liked and productive. But what if they were being blackmailed? They had been told to obtain that same sensitive data for a criminal gang, or face being exposed in the blackmail? It sounds like a nightmare, but it happens and insider threats can be really difficult to identify.
I read recently that an independent threat intelligence team raised the alarm with the US Treasury Department. Their concern? That individuals connected to Elon Musk’s "Department of Government Efficiency" were posing a serious ‘insider threat’. Now, whether or not there’s weight to that specific claim, the bigger takeaway is this: insider threats are very real, and they’re finally starting to get the attention they deserve. The warning kicked off a flurry of conversation online, and rightly so. It opened up an important discussion about how we protect ourselves, not just from hackers on the outside, but from people already inside the building.
Now, here’s the thing most folks don’t realise—insider threats aren't the most common cyber risk, but they’re by far the trickiest to guard against. Think about it: even if your recruitment process is watertight and you’ve got proper background checks in place, how do you guarantee the person walking through your front door is actually who you hired? And what happens if that person, for whatever reason—grievance, ideology, or just plain malice—decides to turn on you?
We’ve seen in law enforcement that it only takes one disgruntled employee with access and a bad attitude to do real damage, whether that’s stealing data or something far worse like an act of violence. Thankfully, there’s some clever kit out there these days—identity validation tools, advanced threat detection systems, and even AI-powered tech that can spot someone carrying a weapon before it’s too late. It's a far cry from the old days of a CCTV camera and a security guard with a clipboard.
Let’s not forget the broader landscape either. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches involved a non-malicious human element—someone making a mistake or falling victim to social engineering. That figure excludes malicious privilege misuse. And that’s the distinction worth pausing on. An employee making a mistake is one problem. Someone deliberately abusing their access is another—and that’s the threat we’re talking about here.
So what's the bottom line? Spotting a potential threat early is miles easier than picking up the pieces afterward. Whether you're running a government department or a small business, if you're not thinking about your people as both your greatest asset and a possible risk, you’re leaving the door wide open.
It is important to consider ex-employees and your systems and procedures that are in place to revoke access to IT systems once they have left. They could still be holding the keys (well passwords) to your kingdom. You’d be surprised how many former employees still have access to:
CRM systems
Email accounts
Inventory platforms
Wi-Fi passwords
DMS logins
Alarm codes
Even the password to the general manager’s Netflix account (don’t judge)
Many company IT systems, still have active logins tied to people who haven't worked there in months. If they are ex-IT support staff, they might even have had admin privileges! You can almost hear the hackers salivating.
So why are insider threats so dangerous?
It’s simple: they already know where your vulnerabilities are. A disgruntled salesperson might export customer leads and take them to your competitor. A fired service technician could sabotage appointment logs or mess with warranty data. A part-time contractor with remote access might sell that login on the dark web for a few hundred bucks. They don’t need to guess how your systems work, or even map your network, they’ve been trained. If they left angry or feeling mistreated? Let’s just say revenge doesn’t always come with a note.
Who’s Most at Risk?
After reading this article, please don’t start looking at everyone with suspicious glances as you grab your morning coffee. Treat this as advice to continually ‘consider’ the threat. Don’t be blind to the damage it can pose. In an extreme example, access credentials sold or passed onto hackers, who then install ransomware can be catastrophic to a business.
So it is worth noting that some employees are more at risk than others.
IT Admins and Vendors: These folks can make or break your infrastructure. Vet them. Limit their access. And when they go - shut the door behind them.
Former Salespeople: Especially the high-turnover kind. They often keep customer contact info, and some don’t mind playing dirty.
Temporary Workers and Contractors: They might only be around for tax season or a parts inventory project - but if they get access and walk away with it? You’ve got a problem.
My 3 key takeaways to stop insider threats, before they start.
There are lots of different ways to try and minimise the risk of insider threats to your business. From my experience, these are my top 3 suggestions to reduce that risk.
1. Immediately Revoke Access Upon Termination
Don’t wait until “after the weekend” to shut off logins. When someone leaves — especially if it wasn’t friendly — disable accounts immediately. That means email, VPN, CRM, DMS, and any remote tools. Don’t forget to obtain any physical keys (Doors, lockers, desk drawers, vehicles and MFA - multifactor authentication keys) that need returning.
Pro Tip: Keep a "Digital Offboarding Checklist" with every role’s access points. HR + IT = best friends.
2. Audit Who Has Access - Quarterly
Every 90 days, do a user access audit across all systems. Ask yourself:
Does this person still work here?
Do they still need this level of access?
Should this be read-only instead of admin?
You’d be shocked how many “former” employees still have live logins. Treat it like recon on your digital perimeter. Know who’s on the inside.
3. Watch for Red Flags - Before They Walk Out
Angry outbursts. Sudden attitude changes. Employees working weird hours. These are the digital world’s version of someone casing the joint. If an employee has handed in a notice period to leave work, pay closer attention to them. Get the IT department to check logs for example, to ensure they are not accessing data or removing data.
Not everyone leaves quietly. Watch behaviour closely, especially after disciplinary action or layoffs.
Final Word from the Cyber Cop
In law enforcement, the scariest threats were always the ones who knew the victims routines. Who’d been inside, seen how the sausage was made, and knew just when to strike.
It’s no different in your dealership.
So don’t just build walls to keep the bad guys out. Make sure you’re not letting old ghosts roam the halls with a login and a grudge. Keep your digital doors locked, your team tight, and your eye on the logs.
Oh yes…..what happened on the road trip for love? You will be pleased to know it was a great success. Nobody got arrested, after a few well-timed words of advice from his dad, Matty ended up dating the girl after all.

authored by
Richard Foster
Get Curated Insights
Content worth the click

