Table 1.

Behaviours and events identified through the grounded theory analysis

Behaviour/eventDefinition
Approached by rival organisationApproaches to the insider by another company
Approached competitorContact with potential, sponsors or other employers
ArrestedBeing detained in relation to the IP theft
CollectionAttempts to gather data of interest to the insider's goal
Concealed conflict of interestsDishonesty concerning affiliations with another organisation
Communication of intentStatements referring to future involvement in insider activity
Communications relating to offendingIn-person or electronic discussions that refer to the theft
Damaged data/infrastructureDamage, including manipulating and destroying data
Data to another governmentThe provision of stolen data to a foreign government
Data to another organisationProviding the victim organisation's data to another company
Data to storage – online/ removable storageMoving to online storage or to detachable devices, such as a USB, CD or floppy disk
Data to storage – personalMovement of data to the insider’s own device
Data to storage – photographCopying data using photography
Data to storage – physicalConversion of data to a printed format
Downloading – organisationDownloading the victim organisation's data using its network
Deleted files from serverConcealment of insider activity through the removal of files
Delivered presentationsDelivering talks or speeches, especially to potential sponsors
Destroyed physical documentElimination of data in a printed format
Detection – before resignationDiscovery before the insider departure
Detection – during attackDiscovery during the commission of the offense
Detection – external notificationDiscovery following advice provided by an outsider
Detected – following resignationDiscovery of the IP theft after the insider had given notice
Detected – internal notificationDiscovery based on information from another employee
Employment terminatedDiscontinuation of the insider’s employment
Found guiltyBeing found guilty of wrongdoing in court
Insider publicised activityDiscovery after the insider made details of the theft public
Left organisation – not abruptlyDeparting the victim organisation in a typical manner
Lied to investigators/courtDishonesty during legal or investigative processes
Misused systemsUnauthorised use of the organisation's systems
Overseas travelMoving outside the country of victim organisation
Prepared to abscondTaking steps to flee, including by purchasing flights
Recruited co-offenderInvolving, or attempting to involve others in the theft
Reluctantly continued employmentExpressions of a desire to depart the victim company, but continuing to work for the victim company
Resigned and separatedGiving notice, then departing the victim organisation
Sold data/assetsProfiting from the organisation's data or assets
Sought other workAttempts to obtain alternative employment
Started new organisationEstablishing another organisation, especially a competitor
Stole equipment/assetsTheft of an organisation's physical assets
Summoned to courtBeing directed to attend court
Unauthorised accessViewing or using data or systems without permission
Worked for rival organisationCommencing work with another organisation
Source: Created by authors

or Create an Account

Close subscription notice
Close access options