article · East African Journal of Information Technology
Predicting insider threats before an incident occurs provides critical value in East Africa, where internal fraud incidents often conclude within hours. Standard machine learning models designed to detect gradual personal grievance or escalation struggle in the region, because East African financial institutions, mobile money operators, and government bodies frequently confront organised criminal networks that rapidly co-opt employees for swift, targeted fraud. Deployment faces four primary structural challenges: incomplete activity logging, sparse labelled incident datasets, high staff turnover disrupting behavioural baselines, and uncertain regulatory limits on employee surveillance. To counter these limitations, a five-stage deployment framework outlines log auditing, behavioural baselining, model selection, dual-threshold calibration for timely warnings, and operational governance. Because organisations can adopt the framework progressively at any stage, even resource-constrained entities can establish incremental defences against rapidly unfolding internal threats.
Digital organisations in East Africa, particularly mobile money services and banks, risk rapid financial losses from employees recruited by criminal syndicates. Moving from reactive detection to genuine prediction helps stop fraud before it concludes. Tailoring deployment frameworks to regional infrastructure constraints ensures institutions with limited resources can implement effective early-warning safeguards without needing complete log systems immediately.
The work outlines an operational deployment framework intended for security practitioners in East African financial institutions, mobile money operators, and government bodies. While the framework offers practical steps for modular adoption, the underlying predictive machine learning models remain at an early review and conceptual stage, requiring new co-option-aware threat models and standardised evaluation protocols before robust commercial or operational software can be fully deployed.
AI-generated from the published abstract. Always read the original work before citing.
Insider threat prediction, defined as identifying users whose behaviour patterns suggest approaching malicious activity before an incident starts, offers more practical value than reactive detection in East Africa, where fraud incidents are often over within hours. This paper reviews published machine learning approaches to insider threat detection, draws a clear operational line between reactive detection and genuine pre-incident prediction, and assesses how well each approach fits the East African deployment environment given its specific infrastructure constraints. East African financial institutions, mobile money operators, and government agencies face a specific threat pattern: organised criminal groups recruiting employees to carry out targeted, time-limited fraud. This co-option pattern differs from the gradual personal escalation that published predictive models are trained to identify, which means those models may not generalise well to the regional context. The paper further identifies four structural barriers to deploying predictive models across East African organisations: partial activity log coverage, limited labelled incident data, high staff turnover that destabilises behavioural baselines, and regulatory uncertainty around employee monitoring. Based on these findings, a five-stage deployment framework is proposed, covering log infrastructure audit, user behaviour baselining, model selection, dual-threshold calibration for early warning, and operational governance. The framework is designed to be entered at any stage, so that organisations with limited resources can still achieve partial protection. The paper concludes with recommendations for ML researchers, security practitioners in East African financial and government institutions, and policymakers, identifying the design of co-option-aware threat scenarios and standardised pre-incident evaluation protocols as the most pressing research priorities.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.37284/eajit.9.2.5716
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.