
The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Insider Threat Mitigation Guide with new case studies, statistics and guidance on hybrid and remote work, artificial intelligence, and adverse employee separations. The guide aids critical infrastructure stakeholders in comprehending the concept of insider threats, identifying the various forms these threats can take, and implementing best practices to establish or enhance an insider threat mitigation program.
The guide is intended to give employees an understanding of behavioral indicators that may signal a risk. It also points to newly released CISA resources supporting preparedness and early risk detection, which the agency framed as the practical route into the material for organizations without an existing program.
The agency added that the update acknowledges the growing impact of insider threats, many of which are unintentional, on critical infrastructure and adds use cases for what it called a dynamic and evolving operational landscape. On artificial intelligence, CISA said the new material covers AI used to manipulate or deceive. CISA also added content on access control, visitor screening and mitigating the risk of adverse employee separations.
Recent global research found that 41 percent of respondents reported that their most serious insider incident cost between $1 million and $10 million, while another nine percent reported losses even higher. These costs include immediate remediation and downtime, as well as regulatory penalties and reputational damage.
The research further revealed that 77 percent of organizations experienced insider-related data loss over the last 18 months, with 21 percent reporting more than 20 incidents during that period. Industry stakeholders offered the following thoughts.
Aviv Nahum, Co-founder and CEO at Above Security
"What I like about CISA’s framing is that it gets away from the outdated idea that insider threat means a disgruntled employee stealing files on the way out. An insider can be malicious, careless, compromised, coerced or completely unaware that they are helping an attacker. The common denominator is trusted access being used in a way that creates risk.
"The practical gap in most organizations is that they still treat insider risk as an incident-response problem. Something happens, HR or Legal raises a concern, and security starts reconstructing the story after the fact. That model does not scale. Organizations need to continuously understand behavior in context: who is acting, what changed, what data and systems are involved, and whether multiple weak signals form a meaningful pattern.
"CISA is also right that this cannot live entirely inside the SOC. Insider risk sits at the intersection of security, HR, legal, and the business. The goal is not blanket employee surveillance. It is to build enough context to intervene proportionately — sometimes that means investigation, sometimes coaching, sometimes restricting access - before a concern becomes a breach."
Rex Booth, CISO at SailPoint
"An insider is no longer limited to a company's full-time employees. Insiders can also be non-human: machine accounts or AI agents operating within the enterprise. We see these breaches consistently emerging as a significant, common challenge across all industries. This frequency makes sense because modern enterprises rely heavily on granting broad access to empower dynamic human workflows.
"Insider threats are uniquely challenging because they don't look like typical attacks, often blending seamlessly into the everyday, authorized workflows organizations rely on. When someone uses legitimate credentials to access a system, it’s incredibly difficult to decipher whether their actions stem from malicious intent, a simple human mistake, or a compromised account.
"This complexity multiplies when you factor in the realities of modern work, where remote teams, rapid SaaS adoption, third-party vendor access, and fragmented visibility create a massive security challenge. To protect your enterprise, you need unified visibility that continuously monitors how identities behave across your entire ecosystem, allowing you to stop threats without slowing down the business.
"Insider risk deserves an equal level of ongoing operational focus because it’s a persistent, frequent, and deeply embedded challenge tied to your everyday identity and access workflows. You can’t patch human behavior, but you can build an identity strategy that stops a simple mistake from becoming an enterprise crisis. Prioritizing continuous identity security empowers your people to do their best work confidently and safely.
"Organizations need to focus on both the technical and cultural aspects of insider threats. Technical controls might include a strict least-privilege architecture and strong identity security programs. But no less important are the relationships a CISO needs to curate with business units and HR to understand what normal behavior looks like and train managers and employees to serve as the early detection system for suspicious behavior. Equally critical is fostering a culture of transparency where employees feel safe reporting their mistakes early, which can stop a minor error from turning into a major breach."
Morey Haber, Chief Security Advisor at BeyondTrust
"Insider breaches remain among the most common and costly security incidents because nearly every successful attack eventually leverages a trusted identity. Whether through credential theft, privilege escalation, accidental data exposure, or intentional sabotage, the attack path almost always becomes an insider problem once legitimate access is obtained and abused.
"Traditional security tools were designed to detect threat actors attempting to gain access through some form of credential attack or exploit. Insider threats typically originate from users who already possess authorized credentials, understand corporate processes, and know where sensitive information resides.
"Modern threat actors further complicate detection by stealing credentials and operating under the guise of trusted users. Security teams may log legitimate authentication, approved device usage, and authorized application access while an attacker quietly moves laterally through the environment. Human behavior also introduces unpredictability through fatigue, stress, poor training, social engineering, or simple mistakes.
"The latest challenge comes from AI agents and non-human identities (NHIs). Organizations are rapidly deploying autonomous systems with broad permissions to access data, APIs, and automate business workflows. If improperly governed, lacking secure by design principles, these identities can unintentionally expose sensitive information or execute actions beyond their intended scope.
"Consider these recommendations:
- Embrace least privilege and just in time access for users, administrators, contractors and AI agents. Standing privileges create unnecessary attack surface and increase insider risk.
- CISOs should invest in identity security analytics capable of continuously evaluating user behavior, entitlements, privilege accumulation, toxic combinations of access policies, and anomalous activity.
- Strengthen governance around non-human identities, service accounts, API keys, AI agents, and Agentic AI workflows.
- Behavioral monitoring should be paired with adaptive controls and high risk actions such as mass downloads, unusual data transfers, or privileged system changes.
- Security awareness programs should evolve beyond annual training into continuous education that reinforces accountability, reporting, and responsible access practices.
"The future of insider threat prevention is not surveillance. It is intelligent identity governance and reducing excessive trust, continuously validating access, and limiting privileges. Organizations can stop many insider threats before they ever become documented incidents."
Mika Aalto, Co-Founder and CEO at Hoxhunt
"Insider threats aren’t needles inside haystacks; they are needles in boxes of needles. The fundamental challenge is that you are dealing with authorized users doing their daily jobs, which can push them to hastily engage with a malicious message or perhaps use risky shadow AI.
"From a technical perspective on malicious insiders, it’s difficult for traditional security tools to distinguish between an employee downloading 50 files because they’re working on a weekend presentation, versus downloading 50 files because they are stealing them.
"It's an issue of context and intent. Heavy-handed cyber restrictions will be a business blocker, so we’re playing a constantly changing game of security tooling versus risk assessment.
"For decades, the industry's answer to human behavior was fear-based monitoring and punitive, once-a-year-or-quarter compliance training. It doesn't work. To truly protect against insider risk, organizations need to rely on behavioral science, positive reinforcement, and real-time visibility that give each person the right training at the right time.
"Think of your people as a security asset, not a liability. Believe in their abilities to recognize and report social engineering threats and give them the tools to do so. Focusing on and rewarding a few measurable core behaviors like threat reporting and MFA use establishes a cultural bedrock of secure behaviors.
"When an employee makes a mistake in training, like clicking a simulated phishing link or using an unsecured device, it shouldn't be a 'gotcha' moment; it should trigger automated, contextual training that serves as a constructive learning opportunity. By replacing fear and heavy-handed surveillance with fun, continuous learning, and automated behavioral interventions, you don't just reduce the likelihood of negligence. You fundamentally transform your workforce into an active, intelligent human sensor network that catches the threats your technology misses."
Carl Windsor, CISO at Fortinet
"Organizations should invest in capabilities that combine visibility, analytics, and automation to identify risk before data leaves the environment. Organizations that follow the following steps report stronger detection, fewer false positives, and improved collaboration across departments:
- Ensure visibility and monitoring across users, devices, SaaS, and GenAI to identify the use of unsanctioned applications.
- Analyze behavior, not just movement. Go beyond file transfers to detect unusual access patterns or misuse of sensitive data such as financial information, personally identifiable information, source code, etc. through data leak prevention.
- Ensure protection to everyday tools. Email, collaboration apps, and personal cloud accounts remain the most common points of egress.
- Assume this kind of malicious activity will happen in your organization and set up monitoring through deception technology to identify users looking to access systems or gather data and use behavioral analytics to hunt for unexpected activity that may indicate gathering or exfiltration of data."




















