Watchlists
Learn about watchlists in Behavior Threats and how risk amplifiers elevate risk
scoring for high-priority user groups.
| Where Can I Use This? | What Do I Need? |
|
|
Or any of the following licenses that include the Data Security license:
|
Watchlists in Behavior Threats® allow you to group and monitor users who represent
elevated risk to your organization. By assigning a risk amplifier to each watchlist, you
increase the weight applied to a user's risk score, ensuring that high-priority personas
receive proportionally higher scrutiny when policy violations occur.
Transition from Legacy Watchlist
If you previously used the legacy watchlist feature, all users from your existing
watchlist are automatically migrated to the High Risk Users predefined
watchlist in a disabled state with a default risk amplifier of 1. You can enable
this watchlist and adjust its settings at any time.
By default, four predefined out-of-the-box watchlists are provided. The platform supports
creating a maximum of 6 custom watchlists per tenant.
Predefined Watchlists
Behavior Threats includes the following four predefined watchlists that target common
high-risk personas:
- Departing Users—Employees who have tendered their resignation or are in the process
of leaving the organization. These users pose elevated data exfiltration risk.
- High Exec—Senior executives and leadership whose accounts, if compromised, could
cause significant organizational damage.
- Vendors—Third-party contractors or vendors with time-bound or limited access who may
not be subject to the same internal controls as full-time employees.
- High Risk Users—Users who have previously exhibited risky behavior or have been
flagged for investigation.
By default, you have to add users to all the watchlists manually. You can enable or
disable any predefined watchlist and modify its status, user list and risk
amplifier. However, you cannot delete them.
Custom Watchlists
In addition to the predefined watchlists, you can create a maximum of six custom
watchlists tailored to your organization's risk profile. You can create, edit, and
delete custom watchlists as needed.
Risk Amplifiers
Each watchlist has a configurable
risk amplifier that multiplies the impact of
policy violations on the risk scores of users in that group. If a user belongs to
multiple watchlists (for example High Exec), only the highest amplifier among those
watchlists applies to their score.