Security Experts Discuss CISA’s Insider Threat Guide Updates

The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Insider Threat Mitigation Guide, providing a better understanding of indicators potentially signaling risk.
Key updates include:
- Updated case studies and statistics, keeping the publication relevant in a dynamic and complex threat environment
- New insights from evolving workplace trends (such as artificial intelligence, remote/hybrid word, and more)
- Resources to support organization preparedness
Security Leaders Weigh In
Aviv Nahum, Co-founder and CEO at Above Security:
What I like about CISA’s framing is that it gets away from the outdated idea that insider threat means a disgruntled employee stealing files on the way out. An insider can be malicious, careless, compromised, coerced or completely unaware that they are helping an attacker. The common denominator is trusted access being used in a way that creates risk.
The practical gap in most organizations is that they still treat insider risk as an incident-response problem. Something happens, HR or Legal raises a concern, and security starts reconstructing the story after the fact. That model does not scale. Organizations need to continuously understand behavior in context: who is acting, what changed, what data and systems are involved, and whether multiple weak signals form a meaningful pattern.
CISA is also right that this cannot live entirely inside the SOC. Insider risk sits at the intersection of security, HR, legal and the business. The goal is not blanket employee surveillance. It is to build enough context to intervene proportionately — sometimes that means investigation, sometimes coaching, sometimes restricting access — before a concern becomes a breach.
Rex Booth, Chief Information Security Officer at SailPoint:
An insider is no longer limited to a company’s full-time employees. It can be anyone with legitimate access or trusted proximity to your systems, data, and processes, including contractors, vendors, and partners. These incidents typically involve malicious individuals intentionally causing harm, negligent users making honest mistakes, or external attackers compromising legitimate accounts. Insiders can also be non-human: machine accounts or AI agents operating within the enterprise. We see these breaches consistently emerging as a significant, common challenge across all industries. This frequency makes sense because modern enterprises rely heavily on granting broad access to empower dynamic human workflows.
Insider threats are uniquely challenging because they don’t look like typical attacks, often blending seamlessly into the everyday, authorized workflows organizations rely on. When someone uses legitimate credentials to access a system, it’s incredibly difficult to decipher whether their actions stem from malicious intent, a simple human mistake, or a compromised account. This complexity multiplies when you factor in the realities of modern work, where remote teams, rapid SaaS adoption, third-party vendor access, and fragmented visibility create a massive security challenge. To protect your enterprise, you need unified visibility that continuously monitors how identities behave across your entire ecosystem, allowing you to stop threats without slowing down the business.
A malicious insider can easily cause more harm than a zero-day — or vice versa. CISOs need to always maintain awareness of all dimensions of risk. However, insider risk deserves an equal level of ongoing operational focus because it’s a persistent, frequent, and deeply embedded challenge tied to your everyday identity and access workflows. You can’t patch human behavior, but you can build an identity strategy that stops a simple mistake from becoming an enterprise crisis. Prioritizing continuous identity security empowers your people to do their best work confidently and safely.
Organizations need to focus on both the technical and cultural aspects of insider threats. Technical controls might include a strict least-privilege architecture and strong identity security programs. But no less important are the relationships a CISO needs to curate with business units and HR to understand what normal behavior looks like and train managers and employees to serve as the early detection system for suspicious behavior. Equally critical is fostering a culture of transparency where employees feel safe reporting their mistakes early, which can stop a minor error from turning into a major breach.
Morey Haber, Chief Security Advisor at BeyondTrust:
An insider threat is any security risk originating from an individual who has been granted legitimate access to an organization’s systems, applications, data, or facilities. The term extends far beyond disgruntled employees and includes contractors, consultants, third party vendors, temporary staff, business partners, and increasingly, machine identities and AI agents operating with delegated privileges. The common denominator is trust and authorized access for an identity that has access into resources insider the organization or trusted cloud environment.
Insider cybersecurity incidents typically fall into three categories:
- Malicious insiders who intentionally abuse access or negatively manipulate systems.
- Negligent insiders who make mistakes and inadvertently conduct malicious activity.
- Compromised insiders whose credentials or devices are compromised by threat actors and provide an entry point into the organization.
The last category is particularly important because many modern ransomware campaigns begin by compromising a user’s identity or assets rather than breaching perimeter defenses directly.
Insider related breaches remain among the most common and costly security incidents because nearly every successful attack eventually leverages a trusted identity. Whether through credential theft, privilege escalation, accidental data exposure, or intentional sabotage, the attack path almost always becomes an insider problem once legitimate access is obtained and abused. Insider threats are difficult to detect and prevent because they often appear indistinguishable from normal business activity from an asset and identity perspective. Traditional security tools were designed to detect threat actors attempting to gain access through some form of credential attack or exploit. Insider threats typically originate from users who already possess authorized credentials, understand corporate processes, and know where sensitive information resides.
Their activity initially appears like legitimate access and acceptable user behavior for the business role they are assigned. An employee downloading customer records, accessing source code repositories, or transferring files may simply be performing their job but an insider threat does it with malicious intent. Distinguishing normal productivity from malicious intent requires contextual understanding of behavior, risk, privileges and business purpose.
Modern threat actors further complicate detection by stealing credentials and operating under the guise of trusted users. Security teams may log legitimate authentication, approved device usage, and authorized application access while an attacker quietly moves laterally through the environment. Human behavior also introduces unpredictability through fatigue, stress, poor training, social engineering, or simple mistakes that can transform trusted employees into accidental threat actors. No security awareness program can eliminate human error entirely.
Finally, the latest challenge comes from AI agents and non-human identities (NHIs). Organizations are rapidly deploying autonomous systems with broad permissions to access data, APIs, and automate business workflows. If improperly governed, lacking secure by design principles, these identities can unintentionally expose sensitive information or execute actions beyond their intended scope.
Preventing insider threats requires shifting from reactive detection to proactive risk reduction. The most effective strategy is minimizing opportunities for misuse before they occur by managing identities and privileges appropriately. Consider these recommendations:
- Organizations should embrace least privilege and just in time access. Users, administrators, contractors, and AI agents should receive only the permissions necessary to perform specific tasks for a limited duration. Standing privileges create unnecessary attack surface and increase insider risk.
- CISOs should invest in identity security analytics capable of continuously evaluating user behavior, entitlements, privilege accumulation, toxic combinations of access policies, and anomalous activity. Modern insider threat programs focus on identifying risky conditions before incidents occur rather than merely investigating them after an incident has been detected.
- Organizations must strengthen governance around non-human identities, service accounts, API keys, AI agents, and Agentic AI workflows. These identities often possess extensive privileges but receive far less oversight than human users. This can lead to a myriad of insider attack vectors including confused deputies and the introduction of malicious code in a supply chain attack.
- Behavioral monitoring should be paired with adaptive controls and high risk actions such as mass downloads, unusual data transfers, or privileged system changes. These types of sensitive events should trigger additional verification, approvals, change control ticket verification, and session monitoring to verify appropriate behavior.
- Security awareness programs should evolve beyond annual training into continuous education that reinforces accountability, reporting, and responsible access practices. Employees should view themselves as active participants in cyber defense rather than potential liabilities.
The future of insider threat prevention is not surveillance. It is intelligent identity governance and by reducing excessive trust, continuously validating access, and limiting privileges, organizations can stop many insider threats before they ever become documented incidents.
Mika Aalto, Co-Founder and CEO at Hoxhunt:
I don’t anticipate the balance of insider threats to ever shift from negligence to malicious activity. It doesn’t make sense from any perspective, psychological, technical, economic or otherwise. This puts insider risk management at the top of the security risk totem, which makes fundamental security measures like good training, endpoint detection and response, signal-driven human risk management, identity access management, and browser defense clear priorities.
Insider threats aren’t needles inside haystacks; they are needles in boxes of needles. The fundamental challenge is that you are dealing with authorized users doing their daily jobs, which can push them to hastily engage with a malicious message or perhaps use risky shadow AI. From a technical perspective on malicious insiders, it’s difficult for traditional security tools to distinguish between an employee downloading 50 files because they’re working on a weekend presentation, versus downloading 50 files because they are stealing them. It’s an issue of context and intent. Heavy-handed cyber restrictions will be a business blocker, so we’re playing a constantly changing game of security tooling versus risk assessment.
The biggest shift in cybersecurity over the past decade has been the ability for organizations to stop obsessing about security awareness compliance and start measurably improving online behaviors. For decades, the industry’s answer to human behavior was fear-based monitoring and punitive, once-a-year-or-quarter compliance training. It doesn’t work. To truly protect against insider risk, organizations need to rely on behavioral science, positive reinforcement, and real-time visibility that give each person the right training at the right time.
First, you need visibility into where the risk is happening, be it the sales department or at the browser layer. By deploying advanced training platforms and lightweight browser defenses, security teams can detect when an employee accesses an unapproved SaaS tool or handles data carelessly, and instantly deliver a positive, in-the-moment ‘nudge’ or micro-training without disrupting their workflow.
Second, rethink your people as a security asset, not a liability. Believe in their abilities to recognize and report social engineering threats and give them the tools to do so. Focusing on and rewarding a few measurable core behaviors like threat reporting and MFA use establishes a cultural bedrock of secure behaviors. When an employee makes a mistake in training, like clicking a simulated phishing link or using an unsecured device, it shouldn’t be a ‘gotcha’ moment; it should trigger automated, contextual training that serves as a constructive learning opportunity.
By replacing fear and heavy-handed surveillance with fun, continuous learning, and automated behavioral interventions, you don’t just reduce the likelihood of negligence. You fundamentally transform your workforce into an active, intelligent human sensor network that catches the threats your technology misses.
Carl Windsor, Chief Information Security Officer at Fortinet:
Insider risk has become one of the most pressing cybersecurity challenges and should be at the top of the priority list when it comes to achieving and upholding strong cybersecurity posture. The impact can be severe.
Insider risks are often woven into daily workflows, frequently resulting from employee negligence that organizations may not have control over or visibility into, such as sending a sensitive data file through email, downloading to USB, uploading information to personal cloud storage, or using unsanctioned SaaS or AI tools. There are so many options organizations must scrutinize every single data flow.
Organizations should invest in capabilities that combine visibility, analytics, and automation to identify risk before data leaves the environment. Organizations that follow the following steps report stronger detection, fewer false positives, and improved collaboration across departments:
- Ensure visibility and monitoring across users, devices, SaaS, and GenAI to identify the use of unsanctioned applications.
- Analyze behavior, not just movement. Go beyond file transfers to detect unusual access patterns or misuse of sensitive data such as financial information, personally identifiable information, source code, etc. through data leak prevention.
- Ensure protection to everyday tools. Email, collaboration apps, and personal cloud accounts remain the most common points of egress.
- Assume this kind of malicious activity will happen in your organization and set up monitoring through deception technology to identify users looking to access systems or gather data and use behavioral analytics to hunt for unexpected activity that may indicate gathering or exfiltration of data.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







