Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should insider risk teams detect time fraud…
Cyber Security

How should insider risk teams detect time fraud without relying on pre-identified risky users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Cyber Security

Insider risk teams should monitor for risky behavior patterns, not just named users or static watchlists. Time fraud often involves authorized access being misused to let someone else perform the work, so detection should focus on screen sharing, unusual desktop control, and corroborating activity across systems. Dynamic policies are useful because they surface unknown risk while preserving a defensible investigation trail.

Why pattern-based detection matters more than watchlists for time fraud

Time fraud is hard to catch with static watchlists because the abuse is often hidden inside legitimate access: a valid employee session, a shared desktop, or a remote-control tool used for a purpose that does not match the work being paid for. Insider risk teams get better results when they look for behavior patterns that indicate substitution, concealment, or off-hours proxy activity rather than trying to predict the exact person in advance. That approach also aligns better with NIST Cybersecurity Framework 2.0 because the problem is as much about continuous detection and response as it is about identity assignment. In practice, many teams only realise the signal after a timekeeping dispute has already turned into a broader integrity review.

What investigators should correlate when the user is not pre-flagged

Detection works best when teams combine endpoint, collaboration, and business-system evidence into one view. Screen sharing, remote desktop use, mouse and keyboard activity, application focus changes, VPN timing, badge events, and task-system updates can reveal whether a person is actually present and performing the claimed work. The goal is not to infer misconduct from one weak indicator, but to identify consistent mismatches across systems that are difficult to explain away.

A useful operating model is to start with expected workflow norms and then look for deviations that persist over time. For example, repeated remote sessions with little local interaction, activity bursts that align with check-in moments rather than working periods, or desktop control by another individual during logged work can all be clues. Those clues become stronger when they line up with payroll records, shift schedules, or project timestamps. Where your evidence stack is immature, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful for thinking about logging, monitoring, and auditability as separate control objectives rather than a single feed.

  • Compare session timing with approved work windows and expected task cadence.
  • Correlate remote-control activity with application use, document edits, and ticket updates.
  • Look for repeated substitutions where one device or account appears active while another person is likely doing the work.
  • Preserve evidence in a way that supports review without over-collecting unrelated employee data.

The guidance breaks down when telemetry is sparse, when remote work is normalised without clear activity baselines, or when teams treat a single tool event as proof instead of a corroborated pattern.

Where time-fraud detection gets noisy, and how to handle the edge cases

Tighter monitoring often improves detection but increases the chance of false positives, so teams have to balance investigatory value against acceptable employee privacy and operational overhead. That tradeoff is especially visible in hybrid environments where screen sharing, assistive tools, or pair work can look similar to concealment if the business context is missing.

One common edge case is legitimate delegation. Another is shared access in operational roles, where multiple people may touch the same workflow during a shift. In both cases, the question is not whether another person was involved, but whether the involvement was authorised, observable, and consistent with the record of work. Teams should also treat unusually clean activity as a signal only when it contradicts the role, because some workstreams genuinely produce long quiet periods.

Teams that rely on pre-identified risky users tend to miss the most adaptive fraud patterns, because the better approach is to detect behaviour that no ordinary workflow can easily justify. That means the detection logic should be grounded in repeatable activity patterns, not suspicion about a named person.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM — Continuous MonitoringTime-fraud detection depends on correlating activity across systems.
Recommendation — Correlate endpoint, collaboration, and business-system telemetry to surface anomalous work patterns.
CIS Controls v88 — Audit Log ManagementInvestigations need auditable evidence of user, session, and device activity.
12 — Network Infrastructure ManagementRemote-access patterns and session paths often reveal substitution or proxy work.
6 — Access Control ManagementAuthorised access can still be misused when sessions are shared or delegated improperly.
Recommendation — Centralise and retain logs that show session timing, remote control, and task activity. Review remote-access pathways and restrict uncontrolled desktop-sharing routes. Enforce unique, accountable access paths so shared sessions cannot mask work substitution.
MITRE ATT&CKT1219 — Remote Access SoftwareRemote-control tools are a common mechanism for hidden desktop use and substitution.
T1078 — Valid AccountsAbuse here often uses legitimate credentials rather than obviously malicious access.
Recommendation — Detect and investigate remote-access tooling that coincides with suspicious work timing. Hunt for legitimate-account sessions that do not align with the expected worker activity.

Practitioner Guidance

What to prioritise: Build detections around mismatched activity sequences, not isolated events. A single remote-control session or a single quiet period rarely means anything on its own; the stronger signal is repeated inconsistency between presence, interaction, and output across more than one system.

What to verify: Confirm that the business context can explain the pattern before escalating. Teams should check whether the role is shift-based, delegated, customer-facing, or otherwise likely to produce legitimate exceptions, because those conditions change the meaning of the same telemetry.

Practitioner takeaway: The most effective time-fraud programmes look for corroborated behaviour that should not coexist in an ordinary work pattern, and they treat unknown-risk detection as a monitoring design problem rather than a watchlist problem.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org