24.06.2025
QKS Review
QKS Review: Insider Risk Management - Vendor Strengths and Gaps in Behavioral Analytics
Author:
Venkatesh Kopparthi
Executive Summary:
As the Information Security market faces rising pressure from increasing data exposure risks, hybrid workforces, and stricter compliance mandates, organizations are moving beyond traditional DLP and UEBA tools.
This review blog by QKS Group assesses whether Insider Risk Management (IRM) vendors are truly innovating to meet these demands - or merely making incremental updates.
What Modern Insider Risk Management Platforms Should Deliver:
Today’s platforms must offer more than basic alerting and rule-based monitoring. Critical next-gen capabilities include:
• Behavioral analytics enriched with identity, HR, and contextual signals
• Risk-scored activity baselining and intent detection using AI/ML
• Automated mitigation and response across endpoint, email, and cloud systems
Key Findings:
• Leading vendors (Cisco/Splunk, Gurucul, Mimecast) stand out with enterprise-grade behavioral models, multi-signal correlation, and actionable insider risk scoring.
• Capable vendors (Microsoft, Netskope, OpenText) show strong performance in specific domains like email, identity, or cloud, but may lack full-stack behavioral depth.
• Lagging vendors (Cyberhaven) offer novel approaches like data lineage tracking but currently lack integration breadth and cross-domain behavioral coverage.
Introduction
The biggest threat to any organization is not always from external bad actors. Insiders remain the biggest threat to company data. Insider Risk Management (IRM) tools help them keep their data safe. Behavioral analytics is a big part of these tools. It watches what users do and flags anomalies indicating risks like data leaks or policy breaks. This blog explores different vendors’ behavioral analytics capabilities offered by insider risk management vendors, pointing out what they’re good at and where they’re not.
Top Performers
Cisco (Splunk), Gurucul, and Mimecast are some of the top vendors. They bring strong solutions that tie into other systems well.
Cisco (Splunk) mixes Splunk’s User Behavior Analytics with its Security Information and Event Management (SIEM) setup, enabling the user organizations to see what’s happening with users, devices, and apps across their network. Furthermore, Splunk's integration with Cisco Talos threat intelligence enriches security findings with critical details like threat levels, categories, and descriptions. Security teams can prioritize and respond to threats with greater speed and precision by embedding Talos intelligence directly into their analysis workflows. The combination of Splunk UBA's machine learning driven anomaly detection with the contextual insights from Cisco Talos provides a robust approach to identifying and mitigating insider risks within complex organizational environments.
Gurucul’s Insider Risk Management (IRM) solution is powered by REVEAL, a data and security analytics platform. REVEAL uses data from security, identity, and HR systems to add context for detecting likely anomalies. The platform analyzes various data types, including user and entity behavioral data (UEBA) to detect anomalies, identity data to assess access entitlements and privileges, data from HR applications and public sources to understand employee sentiment, and traditional security data from SIEMs or data lakes to identify external threats disguised as compromised insiders. Gurucul’s IRM solution provides user risk scoring from these combined inputs. Incorporating advanced AI and ML analytics through HR related events and external factors enables the platform to deliver a more layered risk assessment, potentially predicting behaviors that might lead to compromise or data exfiltration.
Mimecast focuses on email and cloud security. It offers analytics that trigger automatically for identified or pre defined anomalies. Mimecast’s acquisition of Elevate Security in January 2024 and Code42 in July 2024, are critical steps in its strategy towards management and mitigation of human centered security risks, including insider threats and data loss. The Elevate Security platform gathers context from a wide variety of sources, including Mimecast, web activity, IAM systems, SIEMs, endpoint data, DLP solutions, HR systems, and Zero Trust platforms. This integration helps it to cater to use cases such as gaining risk visibility across email and other security tools, creating a unified view of user and device risk posture to automate responses, enhancing user engagement through personalized feedback based on email actions, and protecting sensitive data by implementing adaptive security policies. Furthermore, Mimecast’s acquisition of Code42 and its Incydr product will allow it to provide enhanced insider threat detection and data loss protection capabilities, which is integrated into the Mimecast platform. This evolution indicates that while Mimecast, while the company initially focused on email and cloud security, it is now actively building a comprehensive human risk management platform with significant capabilities in detecting and mitigating insider threats across various collaboration channels and endpoints.
Emerging Vendors
Netskope, Microsoft (Purview Insider Risk Management), and OpenText offer decent analytics, but they have some limits.
Netskope’s insider risk features are delivered through its broader SSE/SASE platform (not a standalone IRM product), relying on its SWG/CASB controls and device context. Netskope does a good job tracking user behavior in cloud for like SaaS and IaaS, but it’s not as strong for on premises systems, so organizations might need another tool to cover everything. While Netskope's core strength lies in cloud security, the company offers an integrated Zero Trust Hybrid Security approach, which combines cloud-based security services with on- premises security measures. This indicates that Netskope does have capabilities that extend to on premises environments, such as their Device Intelligence feature, which calculates risk scores for devices based on customizable parameters. However, their primary focus and the depth of their behavioral analytics capabilities are more heavily weighted towards cloud activities.
Microsoft’s Purview integrates with Microsoft 365 and offers customizable analytics templates. The platform utilizes machine learning based detection controls and integrates with Microsoft Purview Data Security Investigations (DSI) for deeper content analysis. Features like Alert Triage Agents, powered by Security Copilot, improve alert prioritization and streamline response times. Furthermore, Purview IRM brings insider risk user analytics to Microsoft Defender XDR and is adding DLP alerts as IRM indicators, demonstrating an increasing sophistication in its ability to detect and correlate risky activities. But it doesn’t have endpoint agents, so it can miss some user actions and leave blind spots. Its dependence on the Microsoft ecosystem and Copilot is optional but integrated.
OpenText offers a comprehensive insider threat prevention suite; the solution spans behavioral analytics, endpoint, and network detection capabilities. Core Behavioral Signals, OpenText’s UEBA module, leverages unsupervised machine learning to detect anomalous behavior and maps it to frameworks such as MITRE ATT&CK. Combined with OpenText Endpoint Investigator and Network Detection & Response, the platform offers end to end visibility across on-premises and cloud environments. These tools are integrated with Microsoft Defender, Entra ID, and Copilot, and support automation through SOAR. Rather than requiring multiple standalone products, OpenText provides a cohesive platform for behavioral based insider risk detection. However, organizations still need to carefully plan the orchestration and deployment of these integrated tools to ensure seamless coverage across all environments.
Challenger
While CyberHaven incorporates behavioral signals, their primary focus appears to be on events surrounding data rather than a comprehensive analysis of all user behaviors. They score users not only based on their actions but also on the type of data impacted, incorporating details like watchlist membership and risk groups based on factors such as employee performance. Their solution can also flag filenames or extension changes to sensitive data and track modifications to sharing permissions. CyberHaven's incident response view provides analysts with a trace of every step and action related to a piece of data leading up to an incident, aiding in understanding user intent. While they offer user activity monitoring and track data/file movement, comparisons with other solutions suggest that their behavioral analytics might be more focused on data centric events rather than a broad spectrum of user behaviors. CyberHaven is designed for inline prevention (block/coach) of data exfiltration actions, and it does not offer the full scope of typical UEBA (no network logs, no HR signals).
Conclusion
Behavioral analytics is key for handling insider risks. It helps spot and deal with internal threats fast. Cisco (Splunk), Gurucul, and Mimecast offer strong tools with good integration and smart insights, making them a solid pick for complicated setups. Netskope, Microsoft, and OpenText have capable tools but focus on certain areas, so they might leave gaps. Cyberhaven does okay but lacks depth or focus, so organizations might need to evaluate the offerings based on their requirements. When picking a platform, organizations need to think about what their company needs, how mature their security is, and what it has to work with.
Disclaimer:
This blog is based on independent research and publicly available information. The insights presented reflect the views of QKS Group and are for informational purposes only. While we strive for accuracy, we do not guarantee completeness or absolute correctness. Vendors are welcome to provide clarifications or updates. If any vendor listed in this analysis wishes to provide additional context or clarification, we welcome a briefing call and will consider incorporating relevant updates. This analysis is not intended to disparage any vendor but to provide an informed, balanced perspective. We encourage open and constructive dialogue to foster transparency and a deeper understanding of the industry.
Author: Venkatesh Kopparthi, Analyst - Security Analytics and Automation at QKS Group
Vendors: