Opens in a new tab
vmblog logo 2024 wht (updated)

Expert Insights on National Insider Threat Awareness Month: Crucial for Cybersecurity in 2025

Share: 

David Marshall | Published: September 15, 2025

 

September marks National Insider Threat Awareness Month, a critical time for organizations to reflect on one of the most pressing yet often overlooked aspects of cybersecurity: insider threats.

Whether intentional or accidental, insider threats pose a significant risk to businesses of all sizes, from small startups to global enterprises. With cyberattacks becoming more sophisticated and data breaches more frequent, the potential damage caused by insiders-whether malicious employees, careless contractors, or compromised partners-can be devastating.

This expert commentary roundup brings together leading voices in the cybersecurity industry to shed light on the importance of insider threat awareness, explore the evolving landscape of these threats, and provide actionable strategies for mitigating the risks from within.

++

Jake Bell, Engineer Team Lead at Object First

This National Insider Threat Awareness month is a reminder that one of the biggest risks to an organization’s data often can come from within the company. Whether through malicious intent or simple human error, insiders can inadvertently open the door to catastrophic breaches. The most dangerous mindset for any organization is believing ‘it won’t happen to us.’ In today’s threat landscape, leaders must operate under the assumption that a breach is inevitable. This means that secure, tested, and adaptable backup strategies are non-negotiable. 
 
This month, IT teams should ensure Zero Trust Disaster Resilience (ZTDR) practices are incorporated into their storage infrastructure. With ZTDR, admins can truly harden their data protection architectures by segmenting backup software and storage, creating resilience zones, and leveraging immutable backups as the final line of defense when attackers slip past defenses. Whether through shadow IT, evolving AI tools, or the click of an unsuspecting employee, with immutable backups and ZTDR principles in place, organizations ensure recovery remains possible even in worst-case insider threat scenarios. Awareness is important, but resilience is essential.

++

Drew Bongiovanni, Technical Product Marketing Manager, Index Engines

Insider threats are some of the most challenging risks to defend against. That’s why building a culture of resilience is critical. Employees must know how to recognize warning signs, escalate concerns, and feel empowered to act. A resilient culture makes every employee part of the defense.

But resilience also means preparation for when threats succeed. Insider-driven incidents can cause severe damage because of the access and time an individual may have had. Organizations that plan ahead by knowing how to detect, respond, and recover will minimize impact, reduce downtime, and maintain trust even in the face of insider attacks. 

++

Riley Kilmer, founder, Spur

A decade ago, residential proxy networks were tools reserved for the most sophisticated threat actors. Today, they are mainstream and used in nearly every major campaign against corporations. Just because traffic comes from the right geographic location and a residential ISP does not mean it is trustworthy. Threat actors routinely co-opt these networks to make their activity appear as legitimate as possible, which turns what looks like normal employee or customer traffic into an insider threat. Security leaders should incorporate this knowledge into their security strategies and work with tools and vendors that prioritize residential proxy detection and visibility.

++ 

Ryan Sherstobitoff, Chief Threat Intelligence Officer at SecurityScorecard

Insider Threat Awareness Month serves as a timely reminder that some of the most damaging breaches often originate from within. Whether it’s a misstep by a well-meaning employee or a malicious actor with privileged access, insider threats often bypass traditional defenses and go undetected for weeks. This is especially true in hybrid environments where visibility is fragmented across endpoints, cloud services, and third-party vendors. 
 
To combat this threat, organizations should prioritize continuous monitoring and behavioral analytics. This means having tools in place to watch for unusual activity, such as an employee accessing sensitive data outside of normal work hours or attempting to bypass security controls. Organizations must also have a clear, documented incident response plan for insider threats, including who to contact and what steps to take. This plan should involve human resources, legal, and IT teams. Lastly, a crucial step is to encourage employees to report suspicious behavior via a clearly defined anonymous process. 
 
That effort must extend to the systems and vendors with access to your own environment, where risk often hides in plain sight. Surfacing these signals early helps prevent escalation into full-blown incidents. 
 
As insider threats grow more complex, blending human error with credential misuse and social engineering, smarter detection methods are essential. Insider Threat Awareness Month is not just about awareness, it is a call to action. The organizations that act now will be best equipped to protect their data, their people, and their reputation.

++ 

John Xereas, CIO, Nightwing

The recent Salt Typhoon campaign is a reminder that threats don’t always come from the outside. By living off the land, adversaries exploit our technical debt to blend in and persist. But the same ghosts in our networks are just as available to insiders, who already have legitimate access and knowledge of internal tools.

Insider threats can occur at any time and place. Far too often, organizations focus primarily on defending against malicious insiders, while inadvertent insiders pose just as great a danger. Something as simple as neglecting to patch a device, overlooking stale credentials, or leaving an end-of-life system connected to the network can provide the same foothold for an adversary.

The takeaway is simple: a patch is not a time machine. Forgotten assets and overlooked security practices create long-term risks, no matter who takes advantage of them. Defending against insider threats requires more than technology. It demands a culture of security where employees understand how to recognize potential threats, practice rigorous cyber hygiene, and feel empowered to report suspicious behavior without hesitation.

++

Patrick Harding, Chief Architect, Ping Identity

Insider threats have long been a security risk for organizations, but the attack surface is expanding into new territory: AI agents can now act like internal users with their own access and behavior patterns. With 79% of senior executives reporting that AI agents are already being adopted in their companies, we’re facing a very stark reality where determining human behavior from bot behavior might be the difference between securing your organization or falling victim to a nefarious attacker.

Whether it’s a malicious insider, a negligent employee, or an ungoverned AI agent behaving unexpectedly, the fallout from insider threats can be disastrous and long-lasting. That’s why early detection, including identifying unusual patterns like unexpected login attempts or unusual data access, is critical. However, detection alone isn’t enough. Real time risk assessment is essential to immediately identify and prioritize the most urgent threats. Finally, decisive actions, including escalating to security operations or enforcing stricter policies, must follow. 

This month is an important reminder to recognize that every identity – human or AI – needs to be treated with the same level of caution and verification.

++ 

Mark Wojtasiak, VP of Product Research and Strategy, Vectra AI

Insider Threat Awareness Month is a reminder that the challenge isn’t just at the perimeter, its inside organizations, where identities, networks, and everyday user behavior are constantly at play. Security teams are inundated with thousands of alerts daily, yet only a small fraction represent real threats. This noise leaves many analysts unable to review more than a third of alerts, and the fear of missing an attack is a weekly reality for most SOC professionals. Ultimately, this noise drowns out the signal that matters most – the activity rooted in how identities are used and how they traverse the network.

Compounding this, recent industry research shows that insider threats, particularly non-privileged users whose accounts are compromised or misused, are now the most prevalent attacker profile. Nearly two out of five prioritized threats are tied to insider behaviors. The reality is that user and identity misuse is inevitable in today’s complex networks and environments. That’s why security leaders need to focus on detection and response strategies that look beyond the perimeter and zero in on how accounts, identities, networks, and data are actually being used. Reducing noise while elevating the signal that matters most is critical to empowering SOC teams to catch what could otherwise slip through the cracks.

++ 

John Wilson, Senior Fellow, Threat Research, Fortra

Cloud-Native Access as a Weak Point
 
Remote and hybrid work models have fueled a surge in BYOD and shadow IT. Employees often use personal cloud apps or unmanaged devices, which can unintentionally turn them into insider threats. This cloud-based drift can be avoided as work-from-home models continue to expand.   

  • Scan for Cloud Assets | Use a data discovery tool to find all unknown digital assets in the cloud, then make sure they all have strong access policies around them. Implement data classification in the cloud to ensure that you have ongoing visibility and automated protection, as cloud-based assets are sure to scale quickly.
  • Explicitly Communicate a Digital Services Policy | Assume no security initiative is automatically understood if you haven’t explicitly stated it. Many people are still reusing personal passwords for work logins. Gather department heads, talk to HR, get CISO buy-in – any or all of it – and explicitly state the policy on downloading SaaS and other digital services. Make IT permission mandatory and configure security controls and permissions to reflect that if necessary.
  • Decide If BYOD is Right for You | While allowing employees to bring their own devices has obvious monetary benefits, consider the wide-swinging door of risk and whether it is worth it to your enterprise. Even if you can police behavior at work, users will always do what they like out of hours. An investment in company machines could be an investment in cybersecurity.

++ 

Steve Wilson, Chief AI and Product Officer at Exabeam

The danger from insider threats continues to grow in the modern cyber landscape, particularly as AI accelerates their speed, stealth, and sophistication. With 64% of cybersecurity professionals now viewing insiders as a greater risk than external actors, Insider Threat Awareness Month serves as a critical opportunity to emphasize proactive defense strategies. 

While 88% of organizations have insider threat programs, many lack behavioral analytics needed to detect AI-enhanced attacks that exploit trusted access and mimic legitimate user behavior. As threats intensify across sectors like government, healthcare, and manufacturing, this initiative provides an opportunity to call for stronger governance, cross-functional collaboration, and real-time detection capabilities to stay ahead of both human and AI-driven insider risks.

++

Aditya Sood, VP of Security Engineering and AI Strategy at Aryaka

Insider Threat Awareness Month is a critical initiative for raising awareness about the unique security risks posed by internal actors. There have been several examples of insider threats wreaking havoc on major corporations, with Elon Musk’s X being the most prominent recent example. 

A malicious insider is a significant cybersecurity risk, as such individuals can steal intellectual property, exfiltrate confidential information, sabotage systems, or manipulate business operations for personal gain or in collusion with outside threats. The impact can range from financial losses and reputational damage to regulatory penalties and national security risks. 

Awareness about malicious insider activities is crucial because employees and stakeholders must understand the importance of safeguarding credentials, and the necessity of reporting suspicious activity. By teaching employees to recognize the signs of suspicious behavior and reinforcing the importance of strict access controls and reporting protocols, organizations can transform our entire workforce into a crucial line of defense against internal threats. Employees’ role in this is not just important: it’s indispensable. They are the first line of defense, and their commitment to this cause is what will keep organizations secure.

++

Joshua Roback, Principal Security Solution Architect at Swimlane

Insider threats have always been one of the hardest challenges for security teams because they originate from people with legitimate access. Unlike external adversaries, they don’t have to find a way in. They already have the keys. That makes their actions harder to spot and far more damaging when they turn malicious or careless.

It’s up to organizations to ensure their security systems are well-protected, starting with determining who has access to which systems. Poorly managed access controls creates an environment for insider threats to sprout and thrive. Implementing a mature identity access management solution is the most powerful weapon in mitigating insider threat risks. User behavioural analytics (UBA) can provide proactive detection of anomalous user behaviors, giving security teams a leg up against unannounced attackers.

The rise of insider threats has resulted in the development of security measures which can ensure that threats are monitored, analyzed, and neutralized before they escalate into catastrophic breaches. Building resilience has required organizations to combine continuous monitoring, automated response, and a strong security culture to reduce the window of opportunity for insider abuse.

++

Pete Luban, Field CISO at AttackIQ

Insider threats, whether from disgruntled employees or compromised credentials, are difficult to detect and prevent with traditional security measures. Insider Awareness Month serves as a reminder to security teams about the importance of simulating real-world insider attack scenarios to assess the effectiveness of their security controls and response protocols. 

Recent spikes in shadow AI usage and lack of proper cyber hygiene increase the likelihood of insider threats. Use of unauthorized tools or platforms can unknowingly expose sensitive data or create exploitable vulnerabilities, as well as poor security practices, like maintaining out-of-date software or weak passwords.

By integrating techniques, such as adversarial emulation, into the security lifecycle, organizations can uncover gaps in their detection and mitigation strategies before a real attack occurs. Simulated, continuous testing can ensure that security teams can mitigate attacks before insider threats sidestep defenses and steal valuable company data.

++

Richard Copeland, CEO, Leaseweb USA 

Insider threats aren’t always some mastermind with a grudge – more often, it’s a coworker trying to fix something fast or a partner skipping a step to save time. It’s human. We’ve all made a call in the moment that, looking back, perhaps wasn’t the best. That’s why at Leaseweb USA, we try to make security part of our everyday conversations, and not just a checklist you see during training once a year. We ask questions, we double-check each other, and we make sure no one feels like they’re on their own when it comes to protecting our customers.
 
For us, the key is trust – not the blind kind, but the kind built by explaining why the guardrails are there in the first place. When people understand the why, they make better choices, and they speak up faster if something seems off. National Insider Threat Awareness Month might come once a year, but keeping our people, our partners, and our customers safe? That’s an all-day, every-day thing.

++

Roger Brulotte, CEO, Leaseweb Canada

Not every insider threat is malicious, sometimes it’s just a well-meaning person making a decision that quietly opens the door to risk. At Leaseweb Canada, we don’t wait for that moment to happen. We set expectations right from the start with our teams, with our partners, with our customers so everyone knows how we’ll protect data together. We bake it into the way we work, before the first handshake or signed contract. 
 
True protection, however, is established in the in-between moments: the brief hallway catch-ups, the late-night ‘Does this look right?’ messages, and the culture that encourages people to speak up. We’d rather hear a hundred cautious questions than miss the one warning that really matters. National Insider Threat Awareness Month is a good reminder to keep those conversations going; however, to be honest, it’s how we operate all year long. 

++ 

Bryan Sacks, Field CSO, Myriad360
 
When we think about insider threats, the image that comes to mind is often a disgruntled employee acting out near the end of their tenure. In reality, most incidents are unintentional, stemming from carelessness, excessive permissions, or weak operational controls. More concerning in 2025 is the rise of insiders who were never legitimate employees to begin with: contractors, vendors, or new hires who enter organizations under false pretenses. Deepfakes, remote work, and globalized hiring pipelines have made it easier than ever for bad actors to slip through.

The most damaging insider threat breaches are likely to come from those with malicious intent from the start. These threats demand a stronger response: tools for deepfake detection, more rigorous identity validation, and continuous oversight of contractor and vendor access. Insider risk has evolved, it’s no longer just about keeping honest people honest, but about recognizing that some individuals never belonged inside your walls in the first place. 

++

Hüseyin Can Yüceel, Security Research Lead at Picus Security

Organizations thrive on trust, believing people and processes will operate as intended. In cybersecurity, however, that very trust can be exploited. Insider threats pose a particularly dangerous challenge because they understand internal systems, are aware of existing vulnerabilities, and have trusted access that allows them to blend in and evade detection.

In the latest Picus Security Blue Report, we found that organizations fail to prevent 98% of attacks leveraging the Valid Accounts (MITRE ATT&CK T1078) technique. As the most common method used by insider threats, this technique takes advantage of legitimate credentials, making malicious activity nearly indistinguishable from normal user behavior. In effect, valid accounts become the perfect vehicle for insiders to exploit privileged access and inflict maximum damage.

To reduce this risk, organizations must rethink how they manage accounts and access. Implementing separation of privilege ensures no single user can carry out critical actions unchecked, while rotating privileges limits prolonged exposure of high-level access. By enforcing these principles, organizations create friction for potential insider threats, making it significantly more challenging for them to operate unnoticed. Awareness is the first step; strong access controls must follow.

++ 

Tom Findling, CEO of Conifers.ai

The rise of insider threats is based on the reality of account compromise, credential misuse, and privilege abuse, representing real threats to organizations. By the time a behavior is detected as suspicious and an alert gets triggered, the damage has already occurred. Most SOC workflows are constructed to respond to alerts but aren’t designed to answer who, what, when, and why.

More companies are leveraging AI to help their teams identify insider threat signals at scale. AI gives teams the power to build a more complete picture of user behavior. It can show unusual access activity, lateral movement, or even slow data leaks, which would take teams hours to process and stitch together if not with AI. Getting that visibility enables teams to find and respond earlier in the kill chain, with or without the insider’s awareness.

The goal is to put analysts in a better position to make faster and more confident decisions. SOCs need a process that relies on human oversight of AI-driven investigations. That model gives teams the best chance to observe what is going on before access is lost.

++ 

Craig Birch, Principal Technologist for Cayosoft

As we observe National Insider Threat Awareness Month, it’s crucial to recognize that insider threats extend far beyond malicious actors within our organizations. A significant and often overlooked category of insider risk emerges from the very people tasked with protecting our systems: IT administrators whose everyday actions can unintentionally create serious security and operational vulnerabilities.

There’s a real issue related to privileged group membership changes. Every day, administrative actions can unintentionally create serious security and operational risks. For example, an IT admin might temporarily disable multi-factor authentication (MFA) for a user under pressure to complete a critical task.

If that exclusion is forgotten, the account becomes a weak point, vulnerable to phishing and potentially granting attackers access to sensitive applications.While not malicious in intent, these everyday admin changes are a form of insider-driven risk, arising not from attackers, but from human error, pressure, or incomplete understanding of the impact of a configuration change.

Similarly, small configuration changes in tools like Intune can have wide-ranging effects. Accidentally disabling encryption, for instance, could leave every corporate laptop unprotected, exposing the business to data theft if devices are lost or stolen.

These scenarios highlight how tenant-level settings and quick band-aid fixes, even when well-intentioned, can either: Weaken the security posture by introducing vulnerabilities, or create operational risks by over-restricting access and disrupting business processes.
To address this issue, organizations should implement continuous monitoring and automated controls around privileged group membership and administrative configuration changes. To reduce this risk, enterprises should:

  • Enforce policy guardrails to ensure critical security requirements cannot be disabled without approval.
  • Enable continuous visibility through deployment of monitoring and alerting tools that detect and report privileged group membership changes in real time.
  • Automate recovery through automated rollback or policy enforcement to rapidly restore secure defaults when unauthorized or risky changes occur.
  • Educate administrators through ongoing training to help IT staff understand the broader security implications of everyday admin actions. 

++

Yakir Golan, CEO and Co-founder, Kovrr

Insider threats have notoriously been one of the most challenging aspects of enterprise risk management, proving extremely costly, with recent studies finding that their annual impact extends into the multimillion-dollar range. Now, with the emergence and rapid adoption of GenAI in the workplace, this exposure is only amplified. Insiders, whether they’re negligent, malicious, or otherwise, are materially equipped to act with a speed and scale that was previously unheard of.  

This convergence of human access and highly advanced technology creates a novel risk profile that traditional monitoring and assessment tools were not designed to address. Making the issue even more complex is the fact that the consequences of an AI-related incident often remain uncertain until they unfold, at which point, risk management becomes reactive rather than proactive, and, by all accounts, more costly. 

This situation, much as it did with cyber risk, demands that GRC leaders quickly implement an evaluation process that allows them to anticipate how insider-AI scenarios could unfold and the range of outcomes they might trigger. It starts with an assessment framework, such as the NIST AI RMF, which provides a systematic way to measure safeguards. Those maturity insights should then be extended into quantifiable terms that reveal potential losses and enable stakeholders to direct resources where insider risks are most acute. 

++

Todd Moore, Vice President, Data Security Products, Thales

Most insider threats aren’t malicious, rather, they stem from good employees making mistakes or AI agents operating with broad access but too little context. Human factors remain one of the top causes of breaches because people aren’t fully trained, or they cut corners to save time. Meanwhile, the explosion of unstructured data such as emails, shared files, collaboration tools, creates even more risk.

Unlike external attacks, internal risks strike at the core issue of trust, a topic which can be difficult for CISOs to raise. But without visibility into where data exists and who’s accessing it, organizations can’t secure it. The answer is to get proactive: identify your most critical data, monitor it continuously, and respond quickly when something doesn’t add up, whether it’s caused by a human or a machine. 

++

Jamie Moles, Senior Technical Manager at ExtraHop

This year’s theme for National Insider Threat Awareness Month, Partnering for Progress, is a timely reminder that managing insider risk is not the job of one team alone. It requires alignment across security, leadership, and the entire organization.
 
The threat landscape is advancing at a rapid pace as attackers weaponize ransomware, target supply chains, and use AI to sharpen tactics like phishing and social engineering. These attacks can quickly snowball into larger issues, providing cybercriminals with direct access to the network, where they can move laterally to further access critical systems, escalate privileges, and compromise sensitive data. 
 
Insider threats are uniquely dangerous because they can move past traditional perimeter defenses and be difficult to detect. It’s essential to build a culture of security awareness through continuous employee education and partners. It’s also important for organizations to invest in post-compromise security detection, like strong network visibility, to catch anything that slips through the cracks. Insider risk isn’t just a cybersecurity problem, it’s a business resilience imperative. 

++

Eric Polet, Director of Product Marketing, Arcitecta

National Insider Threat Awareness Month (NITAM) serves as an important reminder that some of the most damaging security incidents start inside an organization. These risks aren’t limited to malicious insiders. Simple mistakes and lapses in judgment account for more than half of reported cases, often costing millions to fix. By strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance, organizations can fortify the protection of their sensitive information. At a time when cyberattacks are more frequent and data environments are larger and more complex, the message of NITAM is clear: organizations must stay alert, employ robust protections, and take proactive steps to reduce insider-driven risks.  

++

Jim LaRoe, Symphion

If an insider intended to inflict harm on a business, the first stop would be the business’ printers. They are the softest targets of all and are jackpots for bad actors.  Best of all, it only takes one printer to bring down an entire business with a front-page news event or quietly stealing valuable data or just plain sabotage. It starts with the fact that printers receive, transmit, process and store the business’ (and its customers) most sensitive data. They are core technology and account for 20% of the network endpoints. Yet, 99% of them are unprotected. No one hardens them and no one is monitoring them. The printer OEMs have loaded them with business enabling features, but they aren’t being used because there has been no vendor agnostic software to control across the different brands or even same brand different models (they are IoT). So, nothing had been done. The print industry (which has sold printers, toner and service to supply chain/procurement for 40 years) also has an engrained habit of resetting back to factory default on even the few printers that get hardened. Patching (firmware updates) is not being done.  To top it all off physical access is not restricted, rather printers sit in common areas with unrestricted physical access and on wheels.

The threat surface from just one printer is 360 degrees. The threats range from physical or remote access by logging in using factory default administrator passwords published on the internet, to physical access through unprotected USB ports to inject ransomware to stored administrator credentials for adjacent enterprise systems to harvest such as for the business’ email system, the credentials system and file server system. The sky is the limit on how they can be exploited. Pass back attacks, data theft, ransomware injection, virus injection and others have all been reported with printers. However, in most reported hacks, the bad actor simply looked up the administrator password and logged into the printer.

The reasons for this needless exposure include 1) the fact that there is no designated owner or corresponding budget for print fleet cyber security and 2) there is no prevalent understanding of printers, the associated risks and their protection. The current print service actors have different priorities. The printer OEMs sell features, the managed print services industry is focused on cost elimination not security and so is the supply chain buyer.  

This year during National Insider Threat Awareness Month 2025, education is a top priority. From what we see across the organizations we serve with a few hundred printers to tens of thousands in each print fleet, especially among the US’ largest healthcare systems, there is high variability in cyber security maturity, prioritization of addressing the associated risk and willingness to invest in even the most basic cyber hygiene for these numerous and riskiest endpoints across all industries. We do see some businesses running penetration tests on their printers (which accounts for less than 20% of the risk) to highlight risk. But, IT teams are unfamiliar with the differences involved in protecting printers from their PCs or servers. That is why we are out educating on these issues during National Insider Threat Awareness Month 2025 and year-round.  

++

Ira Winkler, Field CISO at CYE

Organizations should definitely heed this recognition of the insider threat. We are at a time where unemployment is increasing, while many employees are begrudgingly staying with their current employers. This means that employees will have reduced loyalty to their employers, while also trying to better position themselves for future positions.
 
In investigating insider-involved incidents in similar times, I’ve found that in many incidents, insiders are not aware of the fact that they don’t own their work and think they are entitled to things they are not. Then there are also the malicious employees who refer to stealing information and taking other harmful actions as insurance. This assumes that they don’t outright cause harm. Organizations need to be on the alert for both types of activities.
 
Then even if you can implicitly trust the intent of your insiders, you must consider that the external attackers almost always obtain insider account access. Outsiders become the insiders and if you aren’t watching for insider abuse and misuse, you will fall prey to both skilled and unskilled outsiders.

++

Austin Berglas, Global Head of Professional Services at BlueVoyant and Former Head of Cyber, FBI NY

Insider threats primarily target an organization’s most valuable assets: intellectual property (including trade secrets and source code), sensitive customer Personally Identifiable Information (PII), critical financial and strategic data, and system credentials. Detecting these threats often relies on recognizing patterns of behavioral and technical anomalies rather than isolated incidents. Key warning signs include unusual data access patterns, large data transfers to unauthorized locations, attempts to bypass security, declining job performance, or expressions of severe financial distress or dissatisfaction. These indicators, especially when correlated, can signal an elevated risk of malicious or accidental insider activity.

Preventing insider threats hinges on robust organizational policies and practical security measures. Policies such as the Principle of Least Privilege, Segregation of Duties, comprehensive Data Classification, and rigorous Onboarding/Offboarding procedures form the foundation by limiting access and forcing accountability. Typically, organizations implement Data Loss Prevention (DLP) systems, User and Entity Behavior Analytics (UEBA), Multi-Factor Authentication (MFA), and ongoing security awareness training. Lessons from past incidents emphasize that effective protection requires a holistic approach, acknowledging that many incidents stem from negligence rather than malice – “witting vs. unwitting” employees. Early detection through continuous monitoring and fostering a culture of trust and well-being are paramount to mitigating damage.

The landscape of insider risk is evolving rapidly with generative AI and new collaboration tools, presenting both challenges and opportunities. These tools increase risk by facilitating easier data exfiltration (e.g., pasting sensitive info into public GenAI, or sharing across numerous collaboration platforms), obfuscating malicious intent through AI-driven content rephrasing, and accelerating attack and tool development. However, AI also serves as a valid defensive tool; AI-powered UEBA can detect subtle deviations from normal user behavior, Natural Language Processing (NLP) can analyze communications for intent or sensitive data leakage, and predictive analytics can correlate disparate signals to provide early warnings. Leveraging AI defensively allows organizations to shift from reactive incident response to proactive threat detection, identifying nuanced signs of insider activity far more effectively than traditional methods.

++

Masha Sedova, VP of Human Risk Strategy at Mimecast

The growing complexity of cyber threats has permanently changed how organizations approach workforce security. More recently, there’s been many conversations happening around a greater need for closer collaboration between security teams and HR professionals to prevent outgoing workers from leaking sensitive company information. 
 
As job roles evolve, organizations are increasingly challenged by the risks departing employees pose to company data. With 1 in 3 employees taking IP when they leave and 75% of companies not knowing what data is taken – this opens blind spots for bad actors to access highly sensitive material such as customer lists, financial data, source code, or proprietary methodologies. To combat this, enterprises are needed to act swiftly when employees are in the process of leaving, regardless of the manner of their departure. This means, taking a tight and coordinated approach across HR, IT and security departments and establishing workflows for resignations, redundancies, and terminations to ensure everyone knows their role. 
 
It’s important to recognize that not every case stems from malicious intent (and in fact most do not) but the consequences can still be serious if strong offboarding and oversight isn’t a priority. When the functions of these three departments operate within a shared workflow, insider threat risks such as the loss of trade secrets to competitors, regulatory breaches, and reputational damage from exposed confidential data can be significantly reduced.

++
 
Eric Ewald, Chief Engineer, Booz Allen Hamilton

Reflecting on the past several years, this National Insider Threat Awareness Month feels different. Since the COVID-19 pandemic, our industry has witnessed steep increases in the volume, scale, and complexity of impactful insider threat events that make their way into the public sphere. According to Gurucul’s 2024 Insider Threat Report, 76% of organizations attribute growing business and IT complexity as key drivers of increased vulnerability to insider risks. So, the typical technological advancements that organizations put in place to future-proof businesses – such as the dissolving of traditional network perimeters, the explosive adoption of cloud services, and rapid shifts toward SaaS-based tools – are fundamentally changing how we work and engage with the workplace, all sharing a part of the blame.
 
The rapid evolution of technology has many people searching for an AI silver bullet to solve their problems – and insider risk management is no different. Even with the best technology, the core challenge is still human (which is an operational issue that lives between the chair and keyboard). Technical controls no matter how sophisticated, fall short if their operational impact isn’t understood – they risk being rolled back for disrupting workflows. It’s also critical to distinguish between detecting insider threats and managing insider risk. We need integration across business functions to provide real-time context, enabling adaptive, sustainable controls that go beyond the cybersecurity team and into the broader enterprise.
 
Advances in insider threat technology – from AI-driven analytics to real-time risk detection – are transforming how organizations manage insider risk. But these tools reach their full potential only when aligned with collaboration across Legal, HR, Security, and business leadership. Working together ensures risk strategies reflect real business needs, balancing security with operational agility. This approach makes technology adoption more effective and sustainable, helping organizations protect their people and data without slowing innovation or daily operations. 

++

Mark St. John, Co-Founder and COO, Neon Cyber

The era of a distributed workforce has introduced significant challenges in managing insider risk. IT and Security teams are finding it increasingly difficult to monitor who is accessing which external sites and what they are doing there. The rapid adoption of new SaaS and GenAI tools by users is outpacing many organizations’ ability to maintain an accurate inventory and ensure that data is handled safely after user interactions. Whether the risk stems from intentional wrongdoing or accidental data disclosure, it is becoming essential to create a comprehensive catalog of the sites users interact with. Additionally, understanding these sites’ data retention practices, reselling policies, AI usage, and overall security posture is crucial for effective risk management. 

++

Shikha Sangwan, Senior Threat Researcher, Securonix

Insider threats are arguably one of the most dangerous and underestimated risks associated with businesses. Insider threats include both employee error and malicious employee action. 
The problematic nature of insider threats does not always come from a frustrated employee seeking to harm, but that does happen, though. More often, it is just an employee who has every intention of doing a good job makes a mistake, they click a malicious link, they send an email to the wrong person, or they lose a company laptop. 

Baseline practices can include a Zero Trust architecture. A zero-trust architecture, among other considerations, enforces the principle of least privilege. Another important one is UEBA, to detect anomalous activities that deviate from established baselines, signaling a potential threat.  DLP tools and processes are also really important to classify, monitor, and block the unauthorized exfiltration of sensitive data across all vectors. 

One of the most often overlooked vulnerabilities is a departing employee. A formal offboarding process that is automated is not just an HR function; it is also a necessary security control. When an employee leaves or is terminated, access to all corporate systems, applications, and data should be terminated effective immediately. This process should be auditable to ensure that there are no ghost accounts or lingering permissions where an employee has access.

++

Mike Malone, Founder and CEO, Smallstep

1. Bind identity to hardware
One of the most effective ways to prevent credential theft is to link user identity directly to the device itself. By utilizing hardware-based security features such as the Trusted Platform Module (TPM) or Secure Enclave, organizations can issue short-lived, non-exportable certificates or passkeys that remain within the chip. This ensures that even if attackers steal a user’s cookies, they cannot reuse credentials that do not exist outside the hardware. Combine this with continuous enforcement of device posture at both sign-in and session refresh, and you can be confident that only compliant, hardware-verified endpoints can access your sensitive systems.

2. Replace static SSH keys with short-lived certificates
Static SSH keys pose a security risk because they never expire, often spread across systems, and can quietly remain long after an employee leaves. A better solution is to replace them with role-scoped SSH certificates issued by your certificate authority (CA). These certificates can be created with short lifetimes, such as a few minutes or hours, logged for full accountability, and closely aligned with least-privilege policies. Since revocation is linked to offboarding, operational hygiene improves and the risk of “forever credentials” is eliminated. Importantly, this does not disrupt developer workflows. Engineers can still connect via SSH, but the credentials are safer and easier to manage.

3. Use mutual TLS with workload identity for services
When it comes to securing service-to-service traffic, trusting the network alone is no longer sufficient. By assigning cryptographic identities to workloads and using frameworks like SPIFFE, organizations can enforce mutual Transport Layer Security (mTLS) across their service mesh or ingress points. This ensures that each service can prove its identity with automatically rotated certificates rooted in trusted authorities. The benefits are twofold: IP allow list and shared secrets become optional, and attackers face much higher barriers to lateral movement. In practice, mTLS supported by workload identity enhances security and streamlines operations by automating identity lifecycle management at scale. 

++

Piyush Pandey, CEO, Pathlock

Over the past decade, the challenge of ensuring compliance and mitigating fraud risk has grown significantly more complex. The rapid digitization of critical business functions, coupled with the widespread adoption of enterprise applications, often results in users unintentionally receiving excessive access privileges. This not only violates compliance mandates such as SOX but also creates critical vulnerabilities in an organization’s governance framework.
 
While not every instance of excessive access implies malicious intent, the potential for a single individual to exploit elevated privileges for personal gain poses a risk no organization can afford to ignore. Yet, identifying and resolving these violations across sprawling digital ecosystems remains a persistent challenge. 

These risks underscore the urgent need for comprehensive governance frameworks to prevent insider threat incidents like internal fraud from occurring and ensure compliance. Inadequate access governance, lack of continuous monitoring, and fragmented control systems can expose even well-managed enterprises to significant financial and reputational damage. Business executives must prioritize strengthening internal controls, enforcing compliant access structures, and preserving governance integrity to safeguard their organization from these risks.  

++

Richard Bird, CSO, Singulr AI

There has been a significant increase in employees adopting unauthorized tools, using unsanctioned software, sharing sensitive or confidential data, or disregarding or altogether bypassing security protocols, all contributing to intentional as well as unintentional insider threats for enterprises. In all industries, but especially those that are highly regulated, like finance and banking, these kinds of incidents can lead to theft, accidental exposure, or misuse of confidential data, and be accompanied by substantial fines, loss of customer trust, and prolonged legal battles.
 
These individual behaviors, driven by a desire to improve work efficiency or streamline more menial tasks, can and do inadvertently compromise organizational security. The challenge lies in measuring the impact of these behaviors, because organizations currently lack visibility into how, when, or why these things occur. Basically, when it comes to things like AI, companies can’t see what their employees or partners are doing. Without proper governance, discovery, and oversight in place, it’s hard to assess whether these activities enhance productivity or expose the organization to risks.
 
To balance the benefits of employee-driven innovation with the need to mitigate insider threats, organizations must acknowledge that traditional security measures alone are insufficient. Insider threats, whether malicious or unintentional, require modernized approaches to detection and governance. Organizations need visibility into their digital ecosystems to understand the tools used by their employees, whether their data is at risk, and how digital security protocols can align with their organizational security policies. With the right culture of awareness and an understanding of how to leverage advanced technologies to monitor employee activity, enterprises of all sizes can ensure robust security while encouraging innovation and efficiency.

++
 
Sandy Kronenberg, CEO and Founder, Netarx

As we observe National Insider Threat Awareness Month, we must recognize that phishing is evolving faster than training can keep up. A recent Wall Street Journal article highlighted a UC San Diego Health study that tested nearly 20,000 employees with simulated phishing attacks. The results showed that mandatory cyber awareness training had little effect. Failure rates stayed flat regardless of how recently employees had completed their training. In many cases, employees spent less than a minute on training modules or closed them immediately.
 
We are now even seeing deepfakes used in hiring, where synthetic candidates attempt to fool recruiters during virtual interviews. If training cannot keep pace with phishing, it certainly cannot prepare employees to reliably identify fake applicants face-to-face.
 
The risks are rising fast. Deepfake fraud in North America has grown more than 1,700 percent. Losses may reach $40 billion by 2027. The average cost per incident is half a million dollars, and two-thirds of security professionals say they have already experienced deepfake incidents.
 
The real danger lies in trusting a single channel. A voice may sound authentic, a video may look real, and an email may feel urgent. When each is judged on its own, the attack succeeds. The answer is shared awareness. By connecting signals across email, voice, video and metadata like device location and biometrics, organizations can uncover anomalies invisible to the human eye.

Insider threat defense must now move beyond isolated training. It requires a collective approach where systems and people verify across every channel. Only then can we defend against deepfakes that are designed to exploit trust and bypass human judgment.

++

Dr. Srinivas Mukkamala, CEO, Securin

As we observe National Insider Threat Awareness Month, it’s critical to remember that humans remain the most overlooked vulnerability in cybersecurity. With unique access to sensitive data, employees, contractors and partners are equally essential to success and, unfortunately, potential risk factors.
 
The continuous advancement of AI has only amplified this challenge. Its ability to mimic human communication with unnerving accuracy through hyper-personalized phishing and social engineering tactics has made it harder than ever to separate real from fake. Moreover, with no clear AI-specific security regulations, organizations must take the lead: adopting AI responsibly, reinforcing accountability and strengthening defenses with advanced detection, access controls and multi-factor authentication.
 
National Insider Threat Awareness Month is not just about acknowledging risk; it’s about taking collective action. By focusing on both human and technological resilience, businesses can minimize insider threats and safeguard the trust that underpins every successful organization.

++ 

Clyde Williamson, Senior Product Security Architect, Protegrity

National Insider Threat Awareness Month reminds us that insider threats remain one of the most overlooked risks in cybersecurity. The danger is not only the rogue employee stealing data but also the well-meaning staffer who, with just a single click, share or upload, can put sensitive information at risk. In the age of AI, those mistakes are magnified. Generative AI can absorb leaked data in seconds, allowing malicious insiders to automate and scale their abuse of access. 
 
Perimeter defenses alone are not enough. Firewalls and identity checks cannot protect data once credentials are compromised. The only way to prevent insider risks is to make the data itself useless in the wrong hands. Encryption, tokenization and strict access controls ensure that even when access is misused, the potential damage is contained. 
 
Insider threats will always be a reality – but catastrophic breaches don’t have to be. The real difference lies with organizations that stop thinking of security as just building walls and start treating it as a daily commitment to protecting what matters most.

++
 
Josh Jacobson, Director of Professional Services, HackerOne

The fastest way to reduce insider risk is to build a culture where people feel empowered to report issues early and often, whether they’re employees, contractors, or security researchers. Clear vulnerability disclosure paths, continuous testing, and transparent remediation turn near-misses into opportunities to harden defenses. Vulnerability disclosure programs (VDP) provide clear guidelines for responsible disclosure and help organizations improve their cybersecurity posture.
 
Just as red teams stress-test AI systems, organizations must also simulate insider scenarios to expose blind spots, whether accidental misuse or intentional data leaks. Insider threat management can’t be reactive. This is where social engineering is important to stress test your policies, procedures, and safeguards. From phishing and smishing to onsite engagements, there are a lot of different ways to ensure that the human element in your threat landscape is not a weak link. The future is proactive: embedding continuous threat exposure management into the fabric of security and product design.

++
 
Sachin Jade, Chief Product Officer, Cyware

Insider Threat Awareness is a critical part of any modern security program, but awareness alone is not enough. One of the biggest challenges today in threat intelligence and security automation is an overload of data. Teams are inundated with information, often unable to identify what is relevant or how to act on it. Without the right context and workflows, organizations remain vulnerable to risks that originate from inside their own walls. 
 
Insider threats are uniquely difficult to detect because abnormal behavior often blends into normal business operations. A malicious insider, a careless employee or even a planted mole may move under the radar of traditional tools. Training teams to recognize risky behaviors is essential and so is equipping both people and AI systems to interpret insider activity with context. AI should augment analysts by surfacing anomalies faster, but always with human oversight to reduce noise and prevent mistakes.
 
Protecting against insider threats requires moving away from siloed defenses and adopting a collective defense mindset. Teams need to share intelligence across the enterprise and align detection programs with broader risk management strategies. Mid-tier organizations often struggle to get started, while larger enterprises with structured programs still miss opportunities to share information internally. Building diverse detection strategies, rather than relying on a single tool, is key to protecting assets from the inside out.

++
 
Jay Bavisi, Founder & Group President, EC-Council

As automation and AI become mainstream, insider risks are accelerating. What were once highly-skilled attacks are becoming more commonplace and turnkey: phishing emails that write themselves, malware that adapts on the fly, and even voice and image deepfakes. Even “basic” information like names and emails can be weaponized for credential theft, social engineering or misinformation campaigns. 
 
Insider risk cannot be reduced to a compliance exercise. Organizations need a workforce trained to anticipate behavior and counter emerging threats before damage occurs.  That means continuous learning through labs, simulations, and realistic training that allow you to pressure-test your skills against insider or AI-enabled threats. 
 
If leaders want to take a practical first step, they should invest in skilled, qualified cyber professionals certified and equipped with modern tools and ongoing assessments. Leaders should also support ongoing skill development, and upskilling those with access to the most sensitive systems. That way they’re leading from the top down. When employees are empowered with the right skills, they shift from potential liabilities to an active line of defense, building resilience that lasts.

++
 
Freddy Kuo, Chairman of Luminys and Special Office Executive Assistant at Foxlink

Insider Threat Awareness Month is a reminder that security is not just digital. It is physical too. Video security data has become one of the most overlooked and vulnerable assets organizations hold. As surveillance systems become more advanced and widely adopted, businesses are capturing large volumes of footage that may include sensitive operational workflows, employee activity, or personally identifiable information.
 
In one common example, employees have used access to video playback to retrieve customer credit or debit card details by reviewing footage of point-of-sale terminals after hours. While payment systems now include protections like address verification, there are still risks. A driver’s license, ID badge, or payment card flashed in front of a camera can be stored, replayed, and potentially misused if not properly protected.
 
The solution starts with smarter protection. Encryption is essential for safeguarding video data in transit and at rest. But organizations must go further by adopting a privacy-by-design approach. This means embedding access controls, audit logs, and permissions directly into video security systems, ensuring only authorized users can view or export footage.
 
Equally important is real-time monitoring and anomaly detection. Proactively flagging unusual access patterns or repeated viewing of sensitive areas helps identify potential misuse before it escalates. With these safeguards in place, organizations can reduce the risk of insider threats and turn video data from a vulnerability into a secure, trustworthy asset. 

##