The many minds of MITRE: building multidisciplinary human insider-risk research
Cybercrimeology1 Okt 2025

The many minds of MITRE: building multidisciplinary human insider-risk research

Trigger warning: This episode includes discussion of suicide in the context of researching measurable predictive indicators and the lack thereof in the context of cyber.

Episode Notes

  • Dr Caputo's path from social psychology to applied security, including intelligence analysis and building a behavioural-science team at MITRE.
  • What MITRE is: a not-for-profit operating six federally funded R&D centres that provide independent, public-interest research alongside government.
  • Why early “indicator” hunting on endpoints often chased the last bad case; shifting to experiments and known-bad/created-bad data to learn patterns of behaviour change.
  • The LinkedIn recruiter field experiment: ethically approved creation of recruiter personas, staged outreach in three messages, and follow-up interviews to understand reporting barriers.
  • What user-activity monitoring can and cannot tell you; the role of human judgement and programme design.
  • Insider-risk is not only “malicious users”: designing programmes for negligent, mistaken or outsmarted behaviours as well.
  • Current lines of work include improving employee recognition and reporting of malicious elicitations and exploring whether insider-risk telemetry offers early signals of suicide risk.
  • Why multidisciplinary teams beat solo efforts in insider-risk operations.

About our guest:

Dr. Deanna D. Caputo

MITRE Insider Threat Research & Solutions profile: https://insiderthreat.mitre.org/dr-caputo/

LinkedIn: https://www.linkedin.com/in/dr-deanna-d-caputo

Papers or resources mentioned in this episode:

Caputo, D. D. (2024). Employee risk recognition and reporting of malicious elicitations: Longitudinal improvement with new skills-based training. Frontiers in Psychology. https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2024.1410426/full

MITRE Insider Threat Research & Solutions. (2025). Suicide risk and insider-risk telemetry overview. https://insiderthreat.mitre.org/suicide-risk/

MITRE. (2024). Managing insider threats is a team sport. https://www.mitre.org/news-insights/impact-story/managing-insider-threats-team-sport

MITRE Insider Threat Research & Solutions. (2024). Capability overview two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-CapabilityTwoPager-24-0659_2024-02-01.pdf

MITRE Insider Threat Research & Solutions. (2024). Insider Threat Behavioural Risk Framework two-pager (PDF). https://insiderthreat.mitre.org/wp-content/uploads/2024/06/MITREInTResearchSolutions-InTFramework_TwoPager-24-0674_2024-03-18.pdf

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(129)

Public Interest Technology: Making Sense of Security in an AI World

Public Interest Technology: Making Sense of Security in an AI World

Notes: The conversation begins with his path into teaching public policy, despite never having planned a conventional academic career, and why translating technical subjects for non-technical studen...

1 Mai 34min

Who You Gonna Call?: Cybercrime Types and Expectations of Police Response

Who You Gonna Call?: Cybercrime Types and Expectations of Police Response

Notes: Cybercrime is often treated as a distinct phenomenon, but there are strong continuities with offline crime that are frequently overlooked. Digital technologies change behaviour and scale, bu...

1 Apr 30min

Disordered Sense-Making: Conflict Narratives in the Digital Era

Disordered Sense-Making: Conflict Narratives in the Digital Era

Notes: Dr Samuel Tanner began his doctoral research examining war crimes and armed militias involved in mass violence in the Balkans, conducting extensive fieldwork and interviews with participants ...

1 Mar 36min

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Beyond “The Cybercriminal”: Understanding Diversity in Cyber Offenders

Notes:Dr Bekkers describes his academic pathway from psychology to criminology and explains why his research focus has consistently been on offenders and their behaviour rather than on offences or tec...

1 Feb 25min

Systematically Improving Cybersecurity Training

Systematically Improving Cybersecurity Training

Notes:Julia Prümmer describes her transition from legal psychology into cybersecurity research and how psychological methods shape her approach to cybersecurity training.The discussion explores the ro...

1 Jan 49min

The Human beneath the Hoodie: Profiling pathways into cybercrime

The Human beneath the Hoodie: Profiling pathways into cybercrime

otes:Melissa completed her PhD after two decades of operational work, bringing a pracademic perspective to cyber profiling and offender pathways.Her research focuses on understanding the human behind ...

1 Des 202533min

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Courses, Clicks and Consequences: Empiricizing Enterprise Security

Episode Notes:Dr Ho describes an empirical research agenda focused on how security actually operates in organisations. He explains his experience with getting this research off the ground to allow the...

1 Nov 20251h 4min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
rss-bisarr-historie
foreldreradet
treningspodden
jakt-og-fiskepodden
rss-strid-de-norske-borgerkrigene
mikkels-paskenotter
rss-sunn-okonomi
sinnsyn
dopet
rss-kunsten-a-leve
rss-kull
hverdagspsyken
fryktlos
rss-sarbar-med-lotte-erik
hagespiren-podcast
lederskap-nhhs-podkast-om-ledelse
level-up-med-anniken-binz