Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ManagementPhysicalSecurity Leadership and Management

Preserving employee trust with increasing insider threats

By Findlay Whitelaw
People working together in office

Image via Unsplash

November 22, 2023

Research has shown that insider threats can have a seismic impact on organizations of all sizes. When employees feel that their boss is watching their every move, it can reduce trust, create resentment and raise concerns about privacy rights. 

As the threat landscape continues to evolve, insider threats have increased in frequency and complexity. They’ve progressed from petty theft and sabotage to full-scale ransomware attacks against their own employer. Business and security leaders are feeling the pressure to shore up security programs and quell insider security threats without risking established relationships with employees. It is more important than ever for organizations to bolster security by developing and implementing a proactive insider threat program that preserves the trust of their teams. 

Understand the nature of insider threats 

An insider threat is defined as a perceived threat that comes from a person or cohort of people within an organization, who have intimate knowledge of the security practices, data or computer systems. An insider will use their authorized access, intentionally or unintentionally, to harm the department’s mission, resources, personnel, facilities, information, equipment, networks or systems. 

Insider threats can manifest in several ways. For example, an employee may accidentally send an email to the wrong person or improperly share sensitive company information due to negligence. However, in other instances, an employee may deliberately act against their current or former employer with malicious intent. There are many distinct types of insider threats, including theft of intellectual property or sensitive data, fraud and sabotage of systems, among others.

It’s important to differentiate the types of insider threats and manage each accordingly. Accidental threats can be mitigated with a combined effort of security protocols and education because employees are likely unaware of the potential harm they are bringing to the organization. Malicious threats need to be met with firm resistance and a strong, comprehensive insider threat program. 

Demystify preconceived fears

As organizations work to implement an insider threat program, one often overlooked area is employee trust. While companies must adhere to legal, regulatory and ethical considerations when setting up their insider threat programs, they also need to ensure that their security monitoring and countermeasures are legitimate, purposeful and compliant. Most importantly, business leaders must also respect the personal privacy of one of their most valuable assets — their people.

Employees are often wary that their supervisor may be using tools to monitor their productivity or micromanage, so it is important to reiterate that this is not the purpose of an insider threat program. The goal is to identify any misuse or conduct issues, intentional or accidental, and swiftly take the appropriate remediation strategies. These measures should be established within all conduct policies and procedures to ensure the well-being of all employees, customers and stakeholders. In addition to detective controls, insider threat programs should also provide preventive and supportive measures that proactively answer questions and enable positive employee sentiment.

Establish a long-term strategy

Human elements significantly contribute to the complexity of insider threats and each individual employee has a role to play in safeguarding an organization. While traditional, compliance-based security training and awareness programs provide a good framework for managing risk, they do not fully engage employees. These can quickly become remedial tasks that employees undertake on an annual basis, which has minimal positive impact on an organization’s security goals.

It is critical to approach insider threat program implementation and training with long-term security hygiene in mind. This requires sustained behavioral and cultural changes. Leaders should aim to continually educate and provide advice on emerging threats, with real-life, industry trends and examples. For instance, if a competitor just faced an insider threat attack, it is the perfect opportunity to talk with employees about what went wrong, how it could have been prevented, and reiterate the controls your organization has in place. 

Like anything new, enhanced security protocols can come with challenges and resistance. Communicating the intention of an insider threat program is the best way to introduce employees to the idea, establish a baseline of trust and foster cooperation. The overall goal is to reduce insider risk by ensuring the entire organization is safer, empowered and educated. The most effective way to accomplish this is by being clear and transparent in the program’s aims, objectives and requirements of employees. An open line of communication plays a pivotal role in the success of an insider threat program because it makes employees feel informed, engaged and aligned with organizational security goals. 

KEYWORDS: employee training insider threats risk management security strategy threat mitigation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Findlay Whitelaw is Field CTO, Insider Threat Program & UEBA Solutions at Securonix.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Enterprise Services
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

Laptop with coding on ground

Stepping Into the Light: Why CISOs Are Replacing Black-Box Security With Open-Source XDR

Gift cards and credit cards

Why Are Cyberattacks Targeting Retail? Experts Share Their Thoughts

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

July 17, 2025

Tech in the Jungle: Leveraging Surveillance, Access Control, and Technology in Unique Environments

From animal habitats to bustling crowds of visitors, a zoo is a one-of-a-kind environment for deploying modern security technologies.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • insider threats

    Half of U.S. companies hit with privileged credential theft, insider threats in last year

    See More
  • 5_minutes_with_Jaros_1121_900px.jpg

    5 minutes with Stephanie Jaros: Identifying and addressing insider threats

    See More
  • 5 Minutes with Logo Hodson photo

    Addressing increased potential for insider threats with ChatGPT

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk-Analysis.gif

    Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing