When the Only Control Is the Audit Log
Key Intel / TL;DR
  • An officer explained running a license plate reader against a woman he did not know by saying he saw a shiny thing, and the system returned the answer.
  • Logging records a misused query after it completes, which makes it evidence rather than a control.
  • Most internal lookups are free to perform, invisible while happening, and reviewed by nobody, which is a design choice somebody made without deciding it.
  • The control that changes behaviour is a small cost at the moment of the query, most often a required reason and a visible name.
  • Watch what your organization rewards, because a team measured on lookup volume will produce lookup volume.

An officer ran a query against the license plate reader network for a woman he had never met. Asked to explain the decision afterward, he said that he saw a shiny thing.

I have been sitting with that sentence for a few days, because most of the commentary about it has gone straight to the officer, and the officer is the least interesting part of the story. He is one person. What produced the query was a terminal that would answer any question he typed, at two in the morning, with nobody in the building and no field asking him why he wanted to know. The system worked exactly as designed, which is the part worth your attention rather than the man who typed it.

A Log Is Evidence, Not a Control

Every organization I talk to about internal data access eventually says the same reassuring thing, which is that everything is logged. It usually is, and the logs are often very good.

What a log does is describe an action after the action finished. Somebody looked up a customer, opened a patient record, pulled a plate, exported a contact list, and the log knows. The lookup already happened, the data is already on a screen, and the person already read it.

That makes logging a forensic capability rather than a preventive one, and those two things get filed under the same heading in most security programs. If the only thing standing between a curious employee and a record is a log entry that nobody will read until an investigation, then functionally there is nothing standing there at all.

Britain’s criminal records office is the version of this I keep returning to. Their antivirus quarantined four separate attempts to install a credential-stealing tool during an intrusion that ran across two years, so the detection worked every single time, and the regulator’s finding was that the organization could not establish what business process existed for handling those alerts. The record was perfect and it was also a filing cabinet.

Why the Query Is Free

This is the part that gets misdiagnosed. When somebody misuses a lookup, the organization treats it as a character problem, fires the person, and writes a memo reminding everybody that misuse is prohibited. Then it happens again, because nothing about the conditions changed.

Look at what an internal lookup costs the person doing it in most systems. It costs a few keystrokes, it produces no visible signal to anyone else, it requires no explanation, and it carries no realistic chance of anyone asking about it. The employee who wants to check on an ex, an address, a neighbour, or somebody they saw on the news is standing in front of a system that has made that as easy as the legitimate version and has made no distinction between them.

Compare that with the physical equivalent. If the same records lived in a filing cabinet in a supervisor’s office, the person would have to walk in, be seen walking in, pull a drawer, and be seen carrying paper. None of that is a technical control, and all of it is friction that a person weighs before doing something they should not. We digitised the record and removed the walk without noticing that the walk was doing work.

What Changes the Number

The interventions that reduce misuse are small and cheap, and what they have in common is that they operate at the moment of the query rather than in a review afterward. None of them require a new platform.

Require a reason, in a free-text field, before the result appears

This is the highest-return change available here and it sounds far too simple to work. It works because it converts an anonymous act into an authored one. The person has to type something, and typing a false reason is a different psychological event than typing nothing at all.

Most people who would have made the questionable lookup do not, and the ones who proceed have now written a sentence that reads badly in a hearing. Nobody needs to validate the field, it only needs to exist.

Show the person that their name is attached

A small banner naming the user and noting that the query is recorded against them changes behaviour more than a policy document does. Policies are read once at onboarding, and a banner is read at the moment of decision.

Sample and follow up, visibly

Pull a handful of queries a month, ask the person about them in an ordinary tone, and let the fact that this happens become known. The point is that everyone learns lookups get looked at, which is something they currently have no evidence for, rather than that you catch anybody.

If you do this, do it evenly. A review process that only ever examines junior staff teaches a specific and unhelpful lesson about who the rules are for.

Alert on the shape, not the volume

The queries worth surfacing are the ones with a pattern a person can recognise: repeated lookups on the same subject over weeks, a search on a record with no matching case or ticket, activity outside the hours that person normally works, or a lookup on somebody sharing the searcher’s home address or surname. None of that requires a large investment, only somebody to write four rules and own the output afterward.

The Part Nobody Wants to Hear

Watch what your organization rewards, because behaviour follows the reward rather than the policy, and the reward is usually a number on somebody’s dashboard. A support team measured on tickets closed will pull whatever record closes the ticket fastest, including ones outside the scope of the question they were asked. An investigations team measured on cases advanced will run the query that advances the case. When the metric counts output and the control asks for restraint, the metric wins, and it wins quietly, in a way that shows up as productivity rather than as a finding.

I would rather see an organization ask what its incentives are producing than buy another monitoring tool that reports on it afterward. The tool tells you what happened, which you can also learn from the log you already have. Changing what the workflow makes easy is the part that changes the number.

Where This Sits

Access misuse looks like a security problem, and most of it is a design problem in an access system, plus an incentive problem in the team using it. Our insider threat program guide covers the structural version, what to fix first in identity and access management covers who should hold the access at all, and detection nobody reads covers the same failure on the alerting side.

For the surveillance systems specifically, the plate reader arc we have been tracking since readers started fingerprinting the devices inside the car keeps producing this exact category of incident, which is worth remembering when somebody proposes a new one.

Start Here

Pick the system in your organization that holds the most sensitive records about individual people, then go and run a query on it yourself and count what it asked you for. If it did not ask why you wanted the record, did not show you that your name was attached, and did not create anything a colleague would ever see, then you have learned what your control amounts to, and the honest answer is a log nobody has opened.


Want to know what your people can look up and what the system asks them first? Contact Grab The Axe for a behavioral and access assessment, or start with our free Human Attack Surface Score.

Distribute Intel
Marie Welch
Director of Behavioral Security Operations
Marie Welch
The Operational Backbone.

With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.

View Author Page →