Most organizations that deploy a Cloud Access Security Broker feel like they’ve closed the insider threat gap. They haven’t. The most damaging exfiltration campaigns, the ones that run for months before anyone resigns, operate below the cloud layer where CASB has no visibility at all.
This is a structural blind spot, not a configuration error. It explains why EmpMonitor, trusted by 15,000+ companies across 100+ countries, built its threat detection at the endpoint layer, not the API layer.
Listen To The Blog Post
The CASB Confidence Trap
CASB sits between users and cloud services. It sees API calls, login events, file shares to Dropbox, downloads from SharePoint. That’s useful. But a CASB only knows what travels through the cloud-facing gateway , it knows nothing about what happens on the machine before data touches the network.
An employee compressing a folder of contracts. Plugging in a USB drive. Taking screenshots of financial models at 11 PM. All of that happens at the OS level, before any API call, before any cloud event fires. CASB is architecturally blind to it.
This isn’t a knock on CASB , it’s the right tool for what it monitors. The problem is treating it as complete coverage when it isn’t.
What Low-and-Slow Exfiltration Actually Looks Like
The threat pattern organizations underestimate is methodical, not explosive. Bulk transfers get caught immediately , any adequate security tool flags them. Low-and-slow operates below that detection threshold on purpose.
EmpMonitor’s own NBFC insider-threat case study documented exactly this shape: employees serving their notice period were identified as a disproportionately high-risk cohort, with loan data and customer records the primary targets. The pattern wasn’t a single large transfer. It was incremental access to confidential files during the wind-down window before departure, each interaction individually unremarkable. No volume alert fired. The threat was visible only in behavioral sequence, not in any single event.
That real-world shape recurs across industries:
- Weekly USB copies in small batches sustained for months before a resignation, no single transfer large enough to trip a volume alert
- Systematic screenshots of proprietary pricing models or source code, accumulated over weeks, each capture file too small to register as anomalous
- Compressing project folders into archives during off-hours, a recognized precursor to exfiltration, when no one is reviewing activity logs
- Incremental accumulation of sensitive data in a personal drive, each individual transfer too small to register on volume-based rules
Each action in isolation looks benign. The pattern across time does not. A direct comparison of CASB versus user activity monitoring makes the architectural reason explicit. UAM detects gradual data hoarding and low-and-slow exfiltration tactics that cloud-layer tools miss by design, because UAM operates at the layer where those behaviors actually execute. That’s not a feature comparison. It’s a coverage map.
The Endpoint Layer: What UAM Actually Sees
User Activity Monitoring operates directly on the machine, below the cloud layer, below the API layer. That structural difference is what matters.
EmpMonitor’s Real Time Activities Tracking captures behavioral data continuously: application usage, file interactions, and operational sequences that never appear in a network log. Keystroke Monitoring adds a layer CASB fundamentally cannot replicate. Keystrokes reveal intent before any network event fires. An employee copying proprietary terminology into a personal document, or searching for a competitor’s data intake form, registers at the keystroke layer the instant it happens. Not a single byte has crossed the network yet. Screen Recording and USB device detection cover the remaining on-device vectors: visual capture attempts and physical exfiltration paths that cloud-layer tooling never sees.
EmpMonitor’s research on insider threat costs puts the stakes in concrete terms: negligent insider incidents cost organizations an average of $4.58 million per incident, while credential theft by privileged insiders costs 3× more per incident than accidental breaches. The Ponemon Institute found cybersecurity breaches increased 47% since 2018. These aren’t edge cases , they’re the baseline risk profile for any organization with elevated-access employees.
For forensic use cases, and EmpMonitor explicitly supports deriving evidence of malicious activity as an operational use case, this endpoint-level record is what produces audit-defensible logs. Without it, you reconstruct intent from incomplete network-layer breadcrumbs after the fact.
A Practical Detection Framework
Step 1: Map your coverage gaps honestly
List every action that happens on-device before a network call: file compressions, local USB copies, screenshot captures, keystrokes into local applications. That list is your UAM deployment scope. Anything on that list that your CASB doesn’t see is an active blind spot today.
Step 2: Baseline before you alert
Not all roles carry the same exfiltration risk. Finance teams, engineers with access to IP, and sales staff with full customer lists are higher risk than average. Use Real Time Activities Tracking to establish normal file transfer volumes and application usage patterns for those roles before setting alert thresholds. Thresholds built on baselines catch deviations. Thresholds built on assumptions generate noise and get ignored.
Step 3: Activate USB and web-app controls at onboarding, not reactively
EmpMonitor supports blocking web applications and detecting and blocking USB devices. These controls should be activated at the role level from day one, not after a suspected incident. A USB block on roles with no legitimate need for external drives eliminates an entire exfiltration vector before it’s exploited. Reactive controls leave a window. That window is where low-and-slow campaigns live.
Step 4: Use stealth mode when an investigation is active
When a specific employee is under investigation, switching to invisible background monitoring changes the behavioral dynamic entirely. The subject does not alter behavior because they do not know they are being watched. EmpMonitor’s Stealth/Un-stealth mode supports this workflow, and it is a capability directly suited to formal workplace investigations. Behavioral authenticity is what makes the resulting evidence useful. The moment a target suspects monitoring, the pattern changes, and what you capture after that point tells you less.
Step 5: Feed endpoint data into your broader security stack
UAM data isolated in a separate console is less useful than UAM data correlated with your existing signals. EmpMonitor supports exporting data to threat analytics platforms via Syslog and integrates with Active Directory and REST-based APIs for security orchestration. Endpoint behavioral data can then be layered alongside network-level signals from CASB, giving your security team a unified picture rather than two partial views that never quite align.
Ready to see how this integration fits your environment? Explore EmpMonitor pricing and plans; the Gold tier covers teams of 51–200 at $3/user/month on an annual plan, with full access to Syslog export and API integration features.
What Commonly Goes Wrong
The most common mistake is deploying UAM and then treating it as static infrastructure. Alert thresholds go stale. A role that was low-risk last quarter may be high-risk now because of a reorg, a promotion, or access permissions that weren’t cleaned up when someone left. Behavioral baselines need to be revisited.
The second mistake is applying monitoring uniformly across an entire organization without role differentiation. Broad, undifferentiated deployment generates compliance friction and morale concerns without improving detection quality. Focused deployment on genuinely high-risk roles, informed by a compliance monitoring workflow that tracks access, data transfers, and audit-ready reports, produces actionable signal rather than noise.
The third mistake is the most expensive: waiting for a CASB alert to trigger a UAM investigation. By the time a cloud-layer alert fires in a low-and-slow campaign, the data is already staged or gone. Endpoint monitoring catches preparatory behavior. That’s the window where intervention is still possible.
The Transparency Question You Still Have to Answer
Employee monitoring is now widespread enough that most jurisdictions have developed specific legal requirements around disclosure, policy documentation, and employee acknowledgment, requirements that vary sharply by country and state. Stealth mode is a legitimate investigation tool, but it functions within a policy context, not instead of one. Organizations that deploy UAM without a documented monitoring policy and legal review are creating a different category of risk while trying to reduce another.
The point is not to avoid monitoring. The point is to have the compliance scaffolding in place before you rely on UAM evidence in a formal proceeding. If you need to produce that endpoint record as evidence of malicious activity, which is a real, named EmpMonitor use case, the data needs to be collected under a legally defensible framework to hold up. EmpMonitor retains keystroke and activity data for up to 180 days per individual user, which matters when an investigation requires reconstructing a behavioral timeline weeks after the fact.
The Endpoint Is Not Optional
CASB and UAM cover different layers. The endpoint layer is where low-and-slow insider threats actually operate. The question is whether your current stack has visibility there at all, and if not, what behavioral patterns are running undetected right now.
For distributed and hybrid teams, the challenge compounds. Endpoint devices outside the corporate network boundary lack the natural network-layer visibility that on-premises machines have. That makes endpoint-level monitoring more important as work becomes more distributed, not less.
According to SpyCloud’s 2025 Insider Threat Pulse Report, 56% of organizations experienced an insider threat incident in the past year. Separately, 93% of security leaders say insider threats are as difficult or harder to detect than external attacks, per the 2025 Insider Risk Report from Cybersecurity Insiders. EmpMonitor is deployed across 500,000+ employees in 100+ countries, a scale that reflects a consistent conclusion reached across thousands of security teams: the endpoint is where you have to watch.
Start your free EmpMonitor trial and close the endpoint visibility gap before a low-and-slow campaign runs to completion.