Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Talk ColumnSecurity Enterprise ServicesSecurity Leadership and ManagementSecurity & Business ResiliencePhysical Security

When it comes to insider risk, not all employees are equal

By Maggie Shein
SEC0421-Talk-Feat-Slide1-900px

Jacket photograph by Steven Meckler Jacket images; Anastasiia Guseva/Shutterstock (background); Glitterstudio/Shutterstock (texture)

SEC0421-talk-slide3_900px
wolf-in-sheeps-clothing-2577813_1920
SEC0421-Talk-Feat-Slide1-900px
SEC0421-talk-slide3_900px
wolf-in-sheeps-clothing-2577813_1920
April 6, 2021

As a young boy, Frank Figliuzzi had a sense of right and wrong, good and bad. He was so interested in criminal justice that at the age of 11, he wrote a letter to the head of the Federal Bureau of Investigation (FBI) asking for advice on a career in the field. He received a handwritten response and was so inspired that more than a decade later, he would pursue a life-long career in criminal justice and security.

Retired from the FBI, Figliuzzi previously served as Assistant Director for Counterintelligence and spent 25 years as a Special Agent. He held senior FBI leadership positions in major American cities and was appointed the FBI’s Chief Inspector by then Director Robert Mueller to oversee sensitive internal inquiries, shooting reviews and performance audits. Following his FBI career, Figliuzzi became a corporate security executive for a Fortune 10 company and led global Investigations, insider threat, workplace violence prevention, and special event security for 300,000 employees in 180 countries. He now works as a respected National Security Analyst, appearing weekly on live television for NBC and MSNBC news.

Figliuzzi recently published a book drawing on his distinguished career, titled THE FBI WAY: Inside the Bureau’s Code of Excellence. In the book, he discusses everything from training new recruits, to creating a code of excellence, to maintaining standards as a security leader. One of the major points of the book is what Figliuzzi calls “The Seven C’s”: Code, Conservancy, Clarity, Consequences, Compassion, Credibility and Consistency. These demonstrate how business and security leaders can create a code of conduct and solicit performance within the organization that matches their core values.

While an explicit code of conduct is important for any team or organization, a critical step in maintaining such a code is ensuring that the team you have set in place shares those same values and won’t work against them. This is easier said than done of course and becomes all the more complicated when the subject of insider threat – which Figliuzzi says is the biggest threat aside from foreign adversaries facing enterprise security leaders, their organizations, as well as the U.S. and nations around the world – is broached.

The insider threat is an unpleasant topic and one where business and security leaders must admit that some people pose a greater threat to an organization than others, depending on their rank, their role, and their access, Figliuzzi says.

“Detecting bad actors within ranks is complicated for a number of reasons,” he says. “First, it involves a very holistic approach. By that, I mean the answer is not entirely a security answer; it’s a human resource issue, an IT challenge, a labor and employment law challenge, a challenge within the engineering and research functions of a company, a sales function, a supply-chain problem. It requires all hands on deck.”

 

Frank Figliuzzi

SEC0421-Talk-Slide2-900px

Frank Figliuzzi
Photograph by Steven Meckler/Courtesy of Figliuzzi

 

Figliuzzi says that mitigating the risk requires security leaders to focus on the what, where and who.

  • What are you protecting?
  • Where is the element(s) you are protecting?
  • Who has access?

The what is the essential element(s) of the enterprise that would put the entire organization at risk if it were to be compromised. “It’s fascinating how few security professionals truly understand what merits the most protection within their organization in regards to an existential threat to the company,” he says.

Once you’ve established the what, leadership needs to determine where that all-important element resides within the organization. Is it in a specific folder on the cloud? Is it data that researchers, scientists and engineers around the world have access to? Is it a specific plant or office location that houses trade secrets or critical equipment?

Lastly, the question of who may be particularly uncomfortable for a corporate environment, Figliuzzi says, as leaders need to admit that some people may be more valuable within an organization, or alternatively, pose a greater threat than others.

“It’s a tough question in a multi-faceted, massive global corporation, but the organization must deeply understand what the crown jewels of the organization are and which people are more essential than others. Not letting it walk out the door must be the focus,” he says. “This can be politically incorrect for a company to indicate that some people are more essential, but it’s the people within an organization that hold the keys to the kingdom and those people have to be your partners in security.”

But when it comes to insider threats, identifying the who may be easier than the delicate dance that must ensue of keeping watch on those all-essential figures while simultaneously welcoming them into the folds of the security team. It’s imperative that an organization makes those critical employees a part of the team, a part of the security of the entire enterprise, while also being closely watched and monitored in the event something goes awry.

“Show them the intelligence that shows their job, their research or the data they have access to could be targeted by adversaries and competitors. Tell them how important they are. But at the same time, they need to be monitored because, if they go south, if they lose their laptop or have a drinking problem or depressor in their life, you have to be alongside them and you better be paying attention,” he says.

KEYWORDS: cyber security enterprise security insider threats risk management threat management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Maggie shein

Maggie Shein was Editor in Chief at Security magazine. She has been writing, editing and creating content for the security industry since 2004. She has an experienced background in publishing, communications, content creation and management. Within her role at Security, Maggie handled the overall direction of the brand, organized and executed the annual conference, facilitated Solutions by Sector webinars, researched and wrote exclusive cover stories, managed social media, and authored the monthly Security Talk column. She has both an undergraduate degree and master's degree in journalism.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Glasses in front of coding on screen

The Good Hackers Security Leaders Can’t Afford to Ignore

Coding

6 Data Breaches to Know About (June 2026)

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • cyber software freepik

    When it comes to cyber risk, company size doesn't matter

    See More
  • Increase in Cybercrime Demands Fresh Attention to Employee Onboarding and Training

    When It Comes to Employee Security Awareness Training - Should You be Phishing or Teaching?

    See More
  • How Continous Is Continous Monitoring?

    Many organizations have room for growth when it comes to using identity to prevent data breaches

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing