Security Leaders Share Advice for Insider Threat Awareness Day

Insider threats can come in a variety of forms. Sometimes it's a bad actor seeking to harm an organization, and sometimes it's a well-meaning employee who makes an honest mistake. Regardless, the result is the same.
This Insider Threat Awareness Day, security leaders share their thoughts alongside advice on how to reduce insider threats.
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ:
“An insider already has what an external attacker usually wants first: access. That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.
Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.
This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them. Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”
Ross Filipek, CISO at Corsica Technologies:
“The insider threat problem isn't always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren't shut down until days later. Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.
Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way. Insider threat programs don't have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”
Kevin Kirkwood, CISO at Exabeam:
“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.
Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.
Now organizations have another insider entering the workforce: AI agents.
Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.
Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority. The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”
Kevin Mata, Director of Cloud Operations and Automation at Swimlane:
“One strange login probably isn't enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.
That's a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it. AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.
That last part matters with insider risk. Security isn't always the only team involved. HR or legal may need to participate. The best response isn't necessarily the fastest one. It's the one where everyone is working from the same evidence before a judgment is made.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







