MARATTO

article · East African Journal of Information Technology

Predicting Insider Threats in East African Digital Organisations: A Review of Approaches, Regional Challenges, and a Framework for Predictive Deployment

In plain language

Predicting insider threats before an incident occurs provides critical value in East Africa, where internal fraud incidents often conclude within hours. Standard machine learning models designed to detect gradual personal grievance or escalation struggle in the region, because East African financial institutions, mobile money operators, and government bodies frequently confront organised criminal networks that rapidly co-opt employees for swift, targeted fraud. Deployment faces four primary structural challenges: incomplete activity logging, sparse labelled incident datasets, high staff turnover disrupting behavioural baselines, and uncertain regulatory limits on employee surveillance. To counter these limitations, a five-stage deployment framework outlines log auditing, behavioural baselining, model selection, dual-threshold calibration for timely warnings, and operational governance. Because organisations can adopt the framework progressively at any stage, even resource-constrained entities can establish incremental defences against rapidly unfolding internal threats.

Key takeaways

  • Standard predictive models misalign with East African threat profiles because regional fraud commonly involves criminal syndicates co-opting employees for rapid attacks rather than gradual personal escalation.
  • East African organisations face distinct implementation hurdles including incomplete activity logs, scarce labelled training data, unstable behavioural baselines from high employee turnover, and regulatory ambiguity around workplace monitoring.
  • A proposed five-stage framework enables modular adoption across log auditing, behavioural baselining, model selection, dual-threshold calibration, and governance to support resource-constrained institutions.
  • Future research requires standardised pre-incident evaluation protocols and threat scenarios designed specifically to capture rapid employee co-option.

Why it matters

Digital organisations in East Africa, particularly mobile money services and banks, risk rapid financial losses from employees recruited by criminal syndicates. Moving from reactive detection to genuine prediction helps stop fraud before it concludes. Tailoring deployment frameworks to regional infrastructure constraints ensures institutions with limited resources can implement effective early-warning safeguards without needing complete log systems immediately.

Commercialisation angle

The work outlines an operational deployment framework intended for security practitioners in East African financial institutions, mobile money operators, and government bodies. While the framework offers practical steps for modular adoption, the underlying predictive machine learning models remain at an early review and conceptual stage, requiring new co-option-aware threat models and standardised evaluation protocols before robust commercial or operational software can be fully deployed.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

Insider threat prediction, defined as identifying users whose behaviour patterns suggest approaching malicious activity before an incident starts, offers more practical value than reactive detection in East Africa, where fraud incidents are often over within hours. This paper reviews published machine learning approaches to insider threat detection, draws a clear operational line between reactive detection and genuine pre-incident prediction, and assesses how well each approach fits the East African deployment environment given its specific infrastructure constraints. East African financial institutions, mobile money operators, and government agencies face a specific threat pattern: organised criminal groups recruiting employees to carry out targeted, time-limited fraud. This co-option pattern differs from the gradual personal escalation that published predictive models are trained to identify, which means those models may not generalise well to the regional context. The paper further identifies four structural barriers to deploying predictive models across East African organisations: partial activity log coverage, limited labelled incident data, high staff turnover that destabilises behavioural baselines, and regulatory uncertainty around employee monitoring. Based on these findings, a five-stage deployment framework is proposed, covering log infrastructure audit, user behaviour baselining, model selection, dual-threshold calibration for early warning, and operational governance. The framework is designed to be entered at any stage, so that organisations with limited resources can still achieve partial protection. The paper concludes with recommendations for ML researchers, security practitioners in East African financial and government institutions, and policymakers, identifying the design of co-option-aware threat scenarios and standardised pre-incident evaluation protocols as the most pressing research priorities.

Research topics

  • Cybercrime and Law Enforcement Studies
  • Information and Cyber Security
  • Software System Performance and Reliability

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.37284/eajit.9.2.5716

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.