Every September, National Insider Threat Awareness Month serves as a timely reminder that some of the most damaging security incidents don’t originate from external attackers breaching the perimeter — they come from within. Whether through malicious intent, negligence, or simple human error, insiders with legitimate access to systems, data, and facilities remain one of the most persistent and difficult-to-detect risks facing organizations today. As hybrid work, AI-powered tools, and increasingly complex IT environments reshape the workplace, the insider threat landscape continues to evolve in ways that demand fresh attention from security professionals.
This year, that conversation feels more urgent than ever. Economic uncertainty, workforce turnover, and the rapid adoption of generative AI have all introduced new variables into how organizations assess and manage insider risk. At the same time, security teams are being asked to balance vigilance with trust, building programs that protect the business without alienating the very employees they’re meant to safeguard.
To mark National Insider Threat Awareness Month, we reached out to cybersecurity leaders, insider risk experts, and industry practitioners for their perspective on where the threat is headed and what organizations should be doing about it.
++
MICHAEL MARINO, SVP OF STRATEGY, IDENTITY SECURITY, KEEPER SECURITY
Privileged Access Management (PAM) was initially designed to protect against insider threats from human administrators. Today, the insider threat comes from compromised service accounts, unauthorized AI agents and machine identities that legacy PAM was never designed to govern. Perhaps an administrator reuses a production password across personal systems and it gets stolen, or legitimate users’ credentials are compromised and weaponized without their knowledge. While these aren’t intentionally malicious acts, they cause the same damage. The reason organizations are still suffering from insider threats is because the threat landscape evolved, infrastructure changed and PAM stayed the same.
Legacy PAM solutions were built when privileged users were few, access patterns were static and the threat surface was bounded. Today, AI agents autonomously execute commands without human operators, service accounts run across hundreds of systems and machine identities authenticate to each other without a human in the loop. Legacy PAM was not built for this reality. Organizations cannot see who has access to what, when that access is being used or what actually happens when someone exercises it. That blindness persists until after the breach, which means the detection mechanism is always hindsight.
The core problem is you cannot stop what you cannot see. Modernizing insider threat defense means abandoning the assumption that you can manage access through credential distribution alone. Organizations building comprehensive identity security programs must shift to zero standing privilege through time-limited access that expires automatically, step-up authentication for sensitive actions and complete command recording for audit purposes. This means no privilege credentials sit idle and no attack vector persists between access grants. Instead of reactive forensics investigating breaches after the fact, organizations achieve proactive control, where privileges simply don’t exist when they’re not needed. To achieve this, apply the same zero-trust verification you’re supposed to use on your network perimeter to your privileged infrastructure. When every access request is verified and every session is logged and analyzed in real time, insider threats become visible the moment they occur.
++
Michael Centrella, Head of Public Policy at SecurityScorecard
National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.
Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.
Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.
++
John Bruggeman, vCISO at CBTS
National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.
With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?
Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.
Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.
++
Max Gannon, Cyber Intelligence Team Manager at Cofense
Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.
Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.
++
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ
An insider already has what an external attacker usually wants first: access.
That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.
Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.
This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.
Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.
++
Ross Filipek, CISO at Corsica Technologies
The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.
Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.
Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.
Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.
++
Kevin Kirkwood, CISO at Exabeam
We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.
Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.
Now organizations have another insider entering the workforce: AI agents.
Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.
Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.
The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.
++
Kevin Mata, Director of Cloud Operations and Automation at Swimlane
One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.
That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.
AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.
That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.
++
Piyush Sharrma, co-founder and CEO at Tuskira
Insider risk gets much more complicated once you stop looking at permissions as a flat list.
A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.
Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.
AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.
With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.
++
Clyde Williamson, senior product security architect, Protegrity
Insider threats are usually pictured as a malicious employee stealing data on the way out the door. That happens, but the bigger day-to-day risk is legitimate access, exposing more information than someone needs.
Once a user logs in, many systems still display sensitive data simply because that is how the application was built. AI makes that easier to get wrong. An employee can paste customer data into a chatbot in seconds, and an AI agent with broad permissions can move information across systems faster than any human ever could.
Organizations should focus on reducing unnecessary visibility after access is granted. Tokenization, encryption and masking can help keep sensitive values protected even when a person or AI system has legitimate access.
A perfect audit trail explaining how your data left the building is still an explanation of how your data left the building. The better outcome is making sure less sensitive data was exposed in the first place.
++
Shiv Agarwal, CEO & co-founder, Singulr AI
As AI becomes embedded in everyday workflows, insider risk is evolving faster than most organizations realize. Employees are adopting shadow AI tools at a pace that outstrips governance – often with good intentions, but with real exposure: sensitive data flowing into unvetted tools, and no visibility into what those tools can access or do.
The stakes rise sharply as organizations deploy AI agents with authority to access data, invoke tools, and act across systems. The question is no longer just whether your people are following policy; it’s whether your AI is. And as agents operate with greater autonomy, unchecked AI spend becomes its own category of insider risk. Token costs scale with agent activity, and without attribution down to the team or workload driving that spend, organizations discover the exposure after the fact.
Insider Threat Awareness Month is a timely reminder that AI governance isn’t a deployment checklist – it’s an ongoing discipline. Organizations need to know which AI systems are operating in their environment, what they can access, what actions they can take, and what they are spending. Guardrails must be in place before deployment, and continuously verified as AI workflows evolve. Visibility, control, and accountability across every AI system aren’t optional; they’re the foundation.
++
Jay Bavisi, founder and group president, EC-Council
We are moving from AI 2.0 to AI 3.0, and I think the most important change is being underestimated. AI 2.0 gave us tools. Generative AI could create, summarize, analyze and assist.
AI 3.0 is giving us actors. Reasoning and agentic systems can pursue objectives, use tools, navigate workflows and act with increasing autonomy.
That distinction matters enormously for insider threat.
A tool waits for you. An agent acts for you. Once AI can operate inside enterprise systems, interact with applications, access data and make decisions across a workflow, the security question changes from what AI knows to what authority AI has.
That is an important part of the thinking behind EC-Council’s Adopt. Defend. Govern. framework. In the agentic era, adopting AI is no longer simply choosing a technology. You are deciding what agency enters the enterprise. Defending it means challenging what that agency can be made to do. Governing it means deciding where its authority begins, where it ends and when it should be taken away.
Insider Threat Awareness Month becomes particularly interesting in the transition to AI 3.0. Insider risk is beginning to include something organizations have never had to manage at this scale: autonomous digital actors operating legitimately inside enterprise trust boundaries.
The real question is no longer whether AI belongs inside enterprise workflows. That decision is already being made. The question is whether organizations are defining the boundaries of machine authority as deliberately as they once defined human access.
In AI 3.0, insider risk will not only be shaped by who is trusted, but by what is trusted to act.
++
Cyrus Robinson, SVP, security operations, C3
A common mistake is treating insider risk as either a malicious employee problem or an annual awareness exercise. Many incidents begin with routine actions by people using legitimate access. That may be a misdirected email, an overly broad file share, a personal cloud account or an unapproved AI tool. A malicious insider may use many of those same paths. Intent matters during the investigation, but access and data protections need to contain the impact in either case. For defense contractors, a routine mistake involving sensitive information can create risk beyond one company and into the wider supply chain.
Technology can correlate identity, endpoint, email, cloud and data activity and surface behavior that deserves attention. An unusual login or a large download is a signal, not a verdict. There may be a legitimate business explanation, so security operations teams need thresholds that reflect the environment, clear escalation paths and analysts who can validate what happened. Automation can accelerate triage, but the SOC’s role is to establish context and escalate what matters. Intent and response should be assessed through the organization’s broader insider threat process, with the appropriate security, legal, HR and operational leaders involved.
Strong insider threat programs come back to disciplined fundamentals. Keep access aligned to job need, review it when roles change and remove it quickly when someone leaves. Protect privileged accounts and monitor the movement of sensitive data. Training should be recurring and tied to the employee’s responsibilities. Employees also need a simple way to report mistakes or concerns without feeling as though they are automatically being treated as suspects. The goal is to identify issues early and keep mistakes or misuse from becoming larger incidents.
++
Jon Guild, senior penetration tester, Securin
When organizations hear ‘insider threat,’ they often focus too narrowly on a malicious employee. That framing is increasingly wrong at both ends. A stolen credential, an over-permissioned contractor, a misconfigured privilege and an honest mistake all arrive at the same place. A valid identity reaching something the business never intended it to reach.
The difference between them is intent, and intent is invisible to your stack. Credentials leak. Contractors retain access. Privileges get misconfigured. Sometimes nobody gets breached at all. The access you intended can be more useful to an attacker than any exploit.
Awareness training is a layer, and layers are good, but the layer people skip is figuring out how far an ordinary account gets once someone is already inside. Blast radius is the question, and blast radius comes from combinations. A stale delegation nobody remembers configuring. A group whose membership made sense in 2019. A forgotten asset. Individually, low. Together, a path to critical systems.
Most organizations can state their policy on least privilege. Very few can tell you what a contractor account or a standard employee account actually reaches when someone tries. Only one of those is evidence.
++
Michael Lebowitz, National Security & Cyber Attorney | USAR Judge Advocate | Author, Second Wave (2026)
An insider threat is not always a malicious employee deliberately stealing information. AI now allows criminals to scrape personal information from the internet in bulk and create highly personalized messages that appear to come from a supervisor, colleague or trusted vendor. An employee with legitimate access can become an unintentional insider by clicking a malicious link, sharing sensitive information or approving a fraudulent request.
Organizations should treat manufactured urgency and resistance to independent verification as serious warning signs. If a request seems out of character, demands immediate action or discourages the employee from calling the purported sender directly, the employee should stop and verify it through a known channel. Insider-threat training should give employees both a clear verification process and permission to slow down. In an environment where AI makes fraudulent communications increasingly difficult to distinguish from legitimate ones, that moment of hesitation can be an important security control.
++
Yulia Plugatyreva, Senior IT Auditor, Chime
The next insider threat may not be an employee. It may be an AI agent acting with an employee’s access.
As a Senior IT Auditor in fintech, I assess the systems and controls behind high-impact decisions. My question is always the same: who—or what—can make this change, what evidence would show it happened, and would the organization know before it caused harm?
Organizations are connecting agents to security tools, code repositories, cloud environments, and internal data so they can investigate alerts and take action faster. That creates a new version of a familiar problem: a trusted identity with broad access can make a high-impact change before a human understands what happened. The risk is not that AI is inherently malicious. It is that an agent can inherit too much authority, use it at machine speed, and leave teams without a clear record of why an action was taken.
For Insider Threat Awareness Month, companies should expand the question from “Who has privileged access?” to “What can every human—and every agent acting for them—actually do?” AI agents need the same discipline as privileged employees: least-privilege access, short-lived credentials, clear approval boundaries for sensitive actions, and an audit trail that makes every decision traceable. The goal is not to slow adoption. It is to make the safe way to use AI the easiest way.
++
Anant Adya, Executive Vice President & Head of Americas Delivery of Infosys
Organizations preparing for cyberattacks
AI is changing the cyber threat landscape by giving threat actors the ability to operate with greater speed, scale and sophistication. For consumers, that means phishing, impersonation and other forms of fraud can become more convincing and harder to detect. At the same time, financial institutions are using AI to strengthen their defenses, identify vulnerabilities, detect suspicious activity and respond to threats faster.
The focus now needs to be on cyber resilience. Organizations should be prepared for attacks and have the right controls in place to protect identities and critical systems, limit unauthorized access and recover quickly from an incident. As AI accelerates activity on both sides of cybersecurity, strong security fundamentals and effective recovery capabilities become even more important.
How consumers can protect themselves
Consumers should remain vigilant, particularly when receiving unexpected communications involving money, passwords or account access. AI can make phishing and impersonation attempts more sophisticated, so people should be cautious when someone creates urgency or pressures them to act quickly. Verify unusual requests through a trusted channel before providing information or taking action.
The fundamentals continue to matter. Use multifactor authentication, avoid reusing passwords, keep devices and software updated, monitor accounts for unusual activity and be thoughtful about the personal information you make publicly available. Taking the time to independently verify a suspicious request can also provide an important layer of protection as cyber threats become more sophisticated.
++
Matthew Carr, Co-founder / Head of Research & Technology, Atumcell Group
In most insider threat cases I’ve seen, the issue was not intentional misconduct. More often, it involved a contractor still having VPN access months after a project ended, or an engineer still holding admin rights that were never revoked. From an offensive perspective, the first priority is often identifying access that should have been removed but wasn’t.
This risk is even greater in operational technology environments. On a corporate network, a rogue account may expose data, but on a plant floor, leftover access can let attackers into equipment controlling critical physical processes. In several engagements, the quickest path to a production system was not a technical vulnerability, but an active, unused login.
Awareness campaigns help, but the real solution is straightforward: keep clear records of who has access to each system, and promptly revoke access when it is no longer required. While most organizations track current employees, far fewer can account for all active badges, logins, or VPN profiles belonging to former staff.
++
Andrew Park, CISO of UltraViolet Cyber
Insider threat programs succeed or fail on two fronts: who you let in and how closely you watch what they do inside. Thorough background checks — with re-screening at role changes, not just at hire — and behavioral interviews that probe how candidates handled sensitive access raise the cost of getting in (And make sure to ask whether the candidate thinks the North Korean dictator is indeed a dictator). But the harder discipline is the watchful eye on the login activities. Some identity providers flag things like impossible travel logins, high-risk logins and unfamiliar devices; that’s table stakes, and capable adversaries stay under those thresholds. Thus, one must develop higher login sensitivity by building behavioral baselines per identity — typical hours, application access, data volumes, peer-group activity — and detect the deltas: a valid login followed by first-time access to a repository the role never touches, dormant credentials waking up, a service account authenticating interactively.
Correlate authentication with the HR context and validate that they have the business reasons to cause those activities; a clean login from a soon-to-depart employee pulling unusual data volumes is the signature insider event, along with a new hire going through every single SharePoint site and starting to replicate the data, and no IdP flags it alone.
Pair that signal with a smart, thorough DLP implementation around your most sensitive data. Classify what actually matters, then enforce at the egress points insiders use — email, cloud sync, removable media, personal webmail — so the anomalous login and the attempted exfiltration light up together. Finally, validate that these detections fire: simulate credential misuse and data theft, and confirm the SOC sees, triages, and escalates. Offense informs defense — testing insider tradecraft is what closes the gap between tested and detected.
++
Amit Shuster, VP, Product and Engineering, Vetric
Executive impersonation is a growing insider threat method, as attackers can now combine publicly available video with knowledge of an organization’s leadership, processes and culture to create highly convincing requests. A familiar face and voice can make an urgent instruction from a CEO, for example, to transfer funds, disclose sensitive information or bypass a control feel legitimate, particularly when it appears through the video platforms employees already use and trust. Falsified videos floating online could also cause unfounded internal AND external reputational concern, depending on the content.
This Insider Threat Awareness Month, organizations should focus on understanding how legitimate insiders can be manipulated or even tricked into believing fraudulent information. They need verification processes that do not depend on a video’s apparent authenticity. Investigators, meanwhile, need visibility into how impersonation content is created, distributed and coordinated across difficult-to-monitor platforms.
Video intelligence tools can help investigators close those coverage gaps and identify patterns of harmful activity, enabling organizations to respond before a convincing impersonation causes widespread damage.
++
Mike Wade, VP, Customer Success, Gravwell
Insider threat activity often originates from people and systems that are already trusted. The warning signs rarely live in a single alert or data source, making them particularly challenging to detect. They emerge when security teams can connect activity across identity, network, endpoint, cloud and other telemetry over time. That makes broad, full-fidelity visibility especially important. If critical data was filtered out, discarded or never collected because of cost or architectural limitations, teams may discover during an investigation that the context they need is simply gone.
Insider Threat Awareness Month highlights the need for organizations to think beyond collecting alerts and focus on whether investigators can actually access and interrogate the data when it matters.
Security teams need the freedom to retain diverse telemetry, look back historically, and ask new questions of that data as an investigation evolves. You can’t predict which piece of information will prove decisive in advance, so building a security data strategy around preserving visibility gives defenders a much stronger foundation for detecting, investigating and responding to insider activity.
++
Arvind Parthasarathi, CEO and founder, CYGNVS
September is Insider Threat Awareness month, and this year, there’s a new insider threat to watch…and many companies don’t even realize it. Organizations are giving AI agents broad access to corporate systems and data, and unlike human insiders, they move at machine speed. On top of that, they don’t even need malicious intent to cause serious damage. An agent pursuing the wrong objective (or the right objective without proper guardrails) can create a security, legal or regulatory crisis before the human response team even understands what happened. That gives Insider Threat Awareness Month a new twist.
Different human insider situations require different response playbooks, and AI now makes that challenge far more complex. Organizations are deploying agents faster than they’re developing playbooks for when those agents cause harm, if they’re building them at all.
Response teams need answers before an incident occurs: Who has the authority to stop an agent? How do we contain it? What evidence do we preserve? What legal or regulatory obligations are triggered?
And they need a trusted place to run that response. If the systems and communications you normally rely on are implicated in an AI incident, you don’t want to collaborate on your response inside them. An out-of-band command center gives security, IT, legal, communications and executives a separate environment to take control, contain the incident and make decisions when speed and trusted coordination matter most.
++
Gunter Ollmann, CTO, Cobalt
Organizations are now giving AI agents credentials, access to internal systems and authority to take actions. Those agents are now effectively non-human insiders. While we saw rogue agents in the OpenAI Hugging Face incident, AI agents can also operate exactly as designed but with more privilege and agency than anyone realized.
That changes what insider-threat testing needs to look like. Going beyond identity access management, we need to understand what that identity can ultimately accomplish once it gets in. Autonomous pentesting gives defenders a way to safely test that blast radius, emulating what an over-privileged or compromised agent could discover, access, chain together, modify or exfiltrate at machine speed.
The biggest lesson for this year’s Insider Threat Awareness month: before you give AI autonomy, test its authority. Monitoring can tell you what an agent did, but adversarial testing tells you what it could do.
++
Monzy Merza, Co-founder and CEO of Crogl
There are more insider threat actors in your org today than there were last year. And this is the fewest insiders your org will ever have. I am not talking about hellfire and damnation. AI Agents. More and more AI agents are being used every day. Agents can spawn other agents. They access your org’s resources, they take on permissions, they read documents, pass credentials, create summaries and they take actions from emailing to approving transactions. And if you are using a non-sovereign AI with SaaS services and frontier models, your data has already leaked to third parties who are creating derivative products and services.
Reducing insider threat risks means you’ll have to get visibility on agent behavior. And this means employing other agents. If you are on the fence about using AI and maturing your insider threat program, you are already behind. This isn’t just hand-waving. Your organization’s agentic work is someone else’s training data. You need a plan now.
What’s the solution? Start with using sovereign AI capabilities. Partner with vendors who don’t take your data and who can provide details on how their agentic tech handles data access. You’ll need new visibility, new detections, a fast investigation-and-hunt capability. You’ll need more people. And you’ll want to partner with vendors who have predictable pricing models, so you don’t get charged for every investigation or every new use case.
++
Pieter Danhieux, CEO & Co-Founder, Secure Code Warrior
When we talk about insider threats, the conversation almost always defaults to malicious actors or developers with low security awareness. But the fastest-growing blind spot is much simpler: employees in marketing, finance, HR, and operations who are already building AI automations, feeding company data into AI tools, and granting those tools system access — without ever being trained on the risk that creates. They aren’t acting maliciously and they’re certainly capable, but they’re unprepared to mitigate the security risks that exist within their role. That gap is exactly what security teams can’t see with the controls they already have.
An organization’s insider threat program is incomplete if it only accounts for developers and malicious intent. The employee who unknowingly connects an AI agent to sensitive systems, or shares confidential data with a chatbot, is now one of the most common — and least monitored — sources of organizational risk. Closing that gap starts with treating AI literacy as a workforce-wide security investment, not just an engineering and technically-driven one.
++
Eric Polet, Director of U.S. Operations, Arcitecta
National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.
Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.
At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.
++
Jim Routh, Chief Trust Officer at Saviynt
Insider threat prevention starts with identity and access. Organizations need to reduce standing privilege and ensure users only have the access they need, while continuously evaluating how that access is being used. Excessive permissions can create unnecessary exposure, particularly when an identity is compromised or access is misused.
Behavioral analytics can also help organizations move beyond relying on a single authentication event. By establishing patterns around an individual’s normal IT activity, security teams can identify meaningful deviations and trigger automated action, including revoking access when behavior indicates an entitlement may no longer be in the hands of the person it was originally granted to. The goal should be continuous oversight that allows organizations to identify and address risky access before it leads to a larger compromise.
++
Idan Plotnik, co-founder and CEO, Apiiro
As AI coding agents become a bigger part of the software development process, organizations need to rethink what an insider threat looks like. The coding agent is becoming the new enterprise perimeter, generating more code and introducing more risk at a speed that traditional security processes cannot keep up with. Security can no longer rely on manual, point-in-time reviews after code has already been written. Organizations need to understand their software architecture and move toward continuous prevention, with specialized security agents working alongside coding agents to identify and prevent risk as software is built. The principle is simple: the agent writing the code cannot be the one responsible for securing it.
++
Doug Kersten, CISO at Appfire
AI is accelerating and amplifying security threats, and insider risk is part of that equation. As employees use AI across more of their day-to-day work, every decision about where and how the company uses it introduces questions about risk, ownership and trust. An employee sharing sensitive information with an unapproved AI tool, for example, can create exposure without ever intending to put the organization at risk. AI can also be used to amplify and accelerate rogue insiders’ ability to harm an organization.
If you’re not thinking about AI governance, you’re not a modern CISO. AI is fundamentally changing the CISO’s role. Security operations will increasingly be automated by AI to amplify and accelerate responses to AI security threats. The value of the CISO is increasingly in understanding the business, shaping risk decisions and establishing accountability across the organization. At Appfire, we’re already bringing AI incident response and security incident response together and aligning our teams around the speed of response these threats demand.
Insider threat awareness has to become part of how people work, not something reserved for annual training or the security team. Employees are often the first to see when something looks wrong, and they need to feel comfortable raising their hand. The faster that information reaches security, the faster the organization can respond and limit the impact. Becoming a strategic risk advisor is no longer optional. The modern CISO has to help decide not just how the business is secured, but how the business moves forward.
++
Jason Sabin, CTO, DigiCert
National Insider Threat Awareness Month is a reminder that trusted access can create risk whether it belongs to a person or an AI agent. As AI agents become participants in business processes by accessing sensitive systems, retrieving data, and taking action on behalf of users, they introduce a new form of insider risk. An agent may not be malicious, but it can be compromised, misconfigured, or granted more authority than its task requires.
Organizations should apply established insider-risk principles to these non-human actors. Every agent needs a verifiable identity tied to an accountable owner, along with clearly scoped permissions defining which systems and data it can access and what actions it can take. AI Agent Passports can make that identity and authority independently verifiable, while continuous monitoring helps detect unexpected behavior, and immediate revocation provides a kill switch when an agent exceeds its boundaries. The goal is not to slow AI adoption, but to ensure trusted access remains visible, controlled, and accountable.
++
Arti Raman, CEO & Founder of Portal26
When we talk about insider threats, most organizations still picture a disgruntled employee stealing files on their way out the door. The bigger risk today is far less dramatic and far more common: well-meaning employees pasting sensitive data, source code, or customer information into GenAI tools because it’s faster than the approved workflow. That’s not malice, it’s a visibility gap, and it’s happening inside nearly every enterprise right now, often without security teams knowing the scale of it.
The organizations that get this right aren’t the ones trying to block AI use outright, because that never actually works. They’re the ones that build real visibility into how employees are using AI day to day, so they can spot risky behavior early and guide people toward safer alternatives before sensitive data walks out the door. Insider threat programs that ignore GenAI usage are already behind. This Insider Threat Awareness Month, my advice to security leaders is simple: you can’t manage what you can’t see, and shadow AI use is the fastest-growing blind spot most companies have.
++
Dr. Madhu Shashanka, CTO, Chief Scientist, and Co-founder of Concentric AI
Insider threats present an ongoing challenge for enterprises despite a proliferation of tools trying to help address the problem. What makes this particularly difficult is that insiders possess intimate knowledge of not just the information they are after but also the security posture, vulnerabilities and internal processes of the environment.
The answer lies in a multi-pronged defense in depth approach and continuous monitoring capabilities. Behavioral analytics tools that detect anomalies in the activities of users and other entities in an organization is a start but they create a different problem – too many false positives and alert fatigue for analysts. The reason is that humans exhibit a wide range of behaviors and most anomalies, are often benign and carry no malicious intent. Identifying the small number of true malicious signals among these behavioral deviations cannot be manual.
What is missing that can make the picture complete is context, especially context around data. One has to consider user activities in the context of signals such as what type of data they touch, how sensitive and business critical they are, and whether they align with the users’ department and role responsibilities. Unified data security governance platforms should be leveraged as part of the security tool stack to make insider threat detections effective and timely.
++
Dmitry Sotnikov, Chief Product Officer, Cayosoft
Insider-threat mitigation requires coordination across IT, HR, Legal and Compliance. From the IT and identity-security perspective, the most effective approach combines four disciplines: prevention, detection, disruption and remediation. Prevention starts with reducing standing privilege. Organizations should apply Zero Trust principles to Active Directory, Microsoft Entra ID and Microsoft 365 so users do not retain broad native administrative rights simply because of their role. Instead, privileged access should be delegated narrowly for the specific task, scope and duration required, within defined corporate policies. Automating routine administrative activities further reduces the number of people who need direct privileged access. The goal is to minimize the damage any single insider, whether malicious or merely careless, can cause.
Detection should focus on both suspicious activity and indicators of elevated risk. High-risk identities include administrators, contractors, employees who recently changed roles, service accounts and other privileged or non-human identities. Organizations should continuously audit identity, permission and configuration changes, while using integrated threat detection to flag anomalous or policy-violating behavior. Risk can also originate outside the corporate environment. For example, when an employee or partner uses a business email address with an external service that is later breached, exposed credentials can create opportunities for credential stuffing or abuse of federated access.
When suspicious activity is identified, disruption needs to happen quickly. Real-time alerting should be paired, where appropriate, with automated containment measures such as blocking or reversing unauthorized changes, revoking elevated permissions or suspending an account when the risk is severe. Organizations must also plan for remediation and recovery. Insider activity can involve sabotage, destructive changes or deliberate security misconfiguration, including privilege escalation or weakened identity controls. An effective insider-threat program needs to not only detect what changed, but also rapidly restore trusted identity configurations and recover affected directory services.
++
Danny Jenkins, CEO and Co-Founder, ThreatLocker
Addressing insider threats requires accepting an uncomfortable truth: there is no foolproof way to stop them, so the focus needs to be on limiting the damage a malicious or negligent insider can cause. Organizations should take measures to reduce the risk, including properly vetting new hires, requiring in-office visits even for remote workers, and training employees on digital safety, but none of those steps can guarantee there won’t be an insider incident.
Least privilege and Zero Trust is the right approach to dealing with insider threats. If an insider only has access to the exact resources they need to do their job, they can’t compromise the entire organization. Controls that tie device verification to identity can also help ensure that if a negligent insider gets phished, the stolen credential remains useless to the attacker without an approved device.
Organizations should also use controls like separation of duties and job rotation. Separation of duties means no single employee can authorize a major transaction or change without another team member reviewing or approving it. That principle can apply to everything from financial transactions to commits to code repositories. Mandatory vacation, where an employee periodically loses access and must step away from their responsibilities, can also help uncover ongoing problems when someone else has to take over their duties. The goal is to control what you can while limiting the blast radius when something does go wrong.
++
Mike Toole, Director of Security & IT, Blumira
Most Insider threat programs fail before they even start, and it’s rarely a tooling problem. The issue is that no one in the organization can answer the basic question regarding who holds access to what. In practice, that means three people are sharing the same admin login. An employee who changed roles back in 2022 still has finance access they no longer need and the export button works for everyone, regardless of role or risk.
Preventing insider threat risks is largely janitorial work. You don’t need a sophisticated platform to fix this. You need a spreadsheet, an honest access audit, and a process in place to review it regularly. Insider threat prevention demands deep context and established behavioral baselines to prevent over privileged access. This helps enforce least privilege and closes the operational gaps that allow misuse to happen at all.
Organizations are focused heavily on building advanced detection tools while overlooking foundational cybersecurity basics. Leaders need to prioritize establishing proper access hygiene to proactively reduce the insider threat attack surface before it can become a concern.
++
John Wilson, Senior Fellow, Threat Research, Fortra
Insider threats remain one of the most difficult security risks to manage because insiders already have something attackers work hard to obtain: trusted access. A witting insider deliberately abuses that access to steal data, commit fraud, or damage an organization. An unwitting insider may cause similar harm by falling for phishing or social engineering, mishandling sensitive information, or simply making a mistake. In either case, legitimate credentials and normal access can make the activity difficult to distinguish from everyday business operations.
A recent case (https://www.justice.gov/usao-dc/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade) illustrates the potential cost. Former U.S. defense contractor executive Peter Williams used his access to a secure network to steal eight sensitive cyber-exploit components and sell them to a Russian cyber-tools broker. Williams received $1.3 million for the stolen technology, but admitted that his actions caused his employer an estimated $35 million in losses. In March 2026, he was sentenced to 87 months in federal prison. The case is a stark example of how quickly trusted access can become a serious financial, intellectual property, and national security risk.
Reducing insider risk starts with limiting both opportunity and impact. Organizations should enforce least privilege and regularly review access rights, monitor for unusual behavior such as large downloads or unexpected access to sensitive systems, and use DLP controls to detect unauthorized movement of data. Regular security awareness training can reduce the risk posed by unwitting insiders, while clear reporting channels give employees a way to flag suspicious activity or mistakes quickly. The goal is not to distrust employees, but to make sure that trusted access does not become uncontrolled access.
++
Nick Lantuh, President – Interpres Group of CyberProof
While National Insider Threat Awareness Month has always centered on human behavior, security leaders must recognize that the modern “insider” is increasingly non-human. As enterprises deploy autonomous AI agents to run complex workflows, these systems are handed valid, privileged credentials to access production networks, cloud databases, and SaaS applications. Agents function as literal-minded task executors; they are built to accomplish goals by any means possible, regardless of whether a path crosses compliance lines or operational guardrails. When driven by vague instructions or misaligned goals, an agent can rapidly pull untrusted external data, or trigger damaging actions, creating severe insider risk at machine velocity.
Addressing this shift matters because standard security playbooks and human monitoring simply cannot keep up with real-time, multi-step, machine speed agent actions. Treating agents as static background services creates invisible, over-privileged blind spots that legacy access management tools miss entirely. Protecting the enterprise requires pivoting to strict execution governance and non-human identity lifecycle controls designed specifically for automated workloads.
Organizations can limit this exposure by establishing clear boundaries around agent deployments and:
Enforce Non-Human Identity Governance: Treat every autonomous agent as an independent identity registered to a specific human owner, swapping out permanent API keys for short-lived, ephemeral credentials granted only when an action is executed, limiting databse permissions, combined with strict role-based access policies.
Implement Dynamic Intent Checks: Monitor runtime tool calls to confirm an agent’s queries stay aligned with its stated business purpose, requiring explicit human sign-off for critical operations like privilege changes or bulk data transfers.
Isolate Environments, Audit and Monitor Telemetry: Restrict agent execution to tightly scoped sandboxes with strict outbound filtering, and deploy real-time behavioral logging to spot anomalous API surges, unapproved data hoarding, or rogue inter-agent calls before damage occurs. Collect all outputs, tool calls, data collections and prompts.
++
Karim Hossen, CISO, EfficientIP
Insider threats aren’t limited to malicious employees. They can involve compromised credentials, negligent users, contractors or legitimate accounts behaving in unexpected ways. AI adds another dimension, as employees can inadvertently expose sensitive information or bypass established security processes. The larger lesson for CISOs is that authentication alone doesn’t establish trust: an account can be completely legitimate and still behave in a way that puts the organization at risk.
That makes behavioral visibility increasingly important. Security teams need to understand what authenticated users and devices are actually doing and recognize activity that deviates from normal patterns. Network and DNS activity can provide useful early signals, including unusual communications with newly observed domains or infrastructure associated with command-and-control or data exfiltration.
Ultimately, organizations need to move beyond simply verifying identity and toward continuously evaluating behavior. The earlier security teams can recognize when a trusted account begins behaving unexpectedly, the better chance they have of intervening before that activity becomes a larger security incident.
++
Jonathan Kreiner, Co-Founder and CTO, ORION Security
Strip away the insider-threat label and most incidents start with something ordinary: sensitive data moving in a way nobody can properly explain. An employee downloads a file, sends it to a personal account, or pastes it into an AI tool, or an agent accesses or shares more than its user intended. It could be an honest mistake, malicious human intent, or unsafe AI behavior, and each can look legitimate in isolation.
The problem is the lack of context to understand the data, behavior, and intent behind its movement. AI raises the stakes because agents can access and move data across systems faster than security teams can manually investigate. CISOs need tools that can keep pace by connecting activity across people and AI, following the full movement of data, and explaining risk with confidence. Otherwise, security will continue reacting too late to genuine threats while creating unnecessary friction for legitimate work.
++
Chad Cragle, CISO, Deepwatch
Insider Threat Awareness Month is a good time to say this plainly – a valid login does not always mean a safe login. We have seen threat actors change a password and the extra sign in check on an account, then use it as if they were the employee. What gives them away is what happens next. The account may start downloading customer files late at night, open folders that have nothing to do with the employee’s job, or appear to log in from two locations minutes apart. We do not call someone a threat because of one odd event. We look for a pattern, then we check.
AI gives people one more way to make a mistake. Someone can paste a customer list, financial report or piece of code into an AI tool while trying to get work done faster. That information is no longer only inside the company. Threat actors are also using AI to write messages that sound more believable. On our side, AI can quickly put a password reset, a late night download and a strange sign in into the same case. It helps us see what deserves attention. A person still has to decide what it means.
++
John Harbaugh, CIO & CISO, BlueVoyant
The insider threat landscape continues to change rapidly, and AI is removing one of the oldest barriers to malicious activity: technical skill. With AI guiding their actions, the technical capability that once limited what an individual could do is becoming far less relevant. We are entering an era of the “autonomous adversary,” where access, not expertise, is the most important ingredient.
Cybersecurity teams can no longer dismiss a vulnerability or a workflow because it looks too complex for an average employee to exploit unassisted. Static risk registries and compliance checklists were built for a threat that moved at human speed; they are not enough in an environment where access can be turned into action in minutes or seconds, adapted in real time, and covered along the way. In an environment that may now be threatened by an autonomous insider threat, it needs to introduce an autonomous defender to prevent and defeat it.
For this year’s National Insider Threat Awareness Month, the priority needs to shift from what employees can access to how that access is being used and the increase in risk exposure when introducing agentic threats. Organizations should focus on identifying deviations from normal behavior and intervening before suspicious activity becomes a security incident, because the gap between having access and doing damage is closing faster,in a world with this new threat, than current programs are built to catch.
++
Gil Geron, CEO & Co-Founder, Orca Security
This National Insider Threat Awareness Month, the biggest shift we’re seeing in insider risk is that everyone has become a builder. It’s no longer just developers and engineers deploying software and connecting services to company data. You now have analysts, product managers, marketers and other employees building with AI. That’s great for innovation, but it also means a much larger group of people can introduce risk, often without going through the traditional development or security process. That naturally expands the insider threat surface in ways security teams may not immediately see.
The answer isn’t to tell people to stop building. That’s not realistic, and companies don’t want to give up the speed and opportunity AI creates. You have to assume people are going to use these tools, so the question becomes: can you see what they’re building, what it can access, and what permissions it has? If everyone is going to be a builder, security has to make it easier for them to build safely.
++
Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER
The Insider Threat Did Not Disappear. AI Changed Its Shape.
The insider threat conversation has centered on intent for two decades. The disgruntled employee with unchecked network access or the departing salesperson with a customer list are examples every required training course still covers. That framing no longer matches the emerging problem. Verizon’s 2026 Data Breach Investigations Report (VDBIR) found that 45% of employees are now regular users of AI on corporate devices, authorized or not, up from 15% the previous year, and that 67% reach those services through non-corporate accounts on company hardware. Shadow AI is the third most common non-malicious insider action in Verizon’s data loss prevention dataset, a fourfold increase from the year before. At iCOUNTER, we see AI shifting the insider threat into the 3rd Wave of Cybersecurity: it both enables the authenticated employee and creates a vulnerability inside that identity.
AI enables the authenticated employee by putting ungoverned and invisible capability inside a valid session. Non-corporate AI accounts on corporate hardware sit outside enterprise control. The work still looks like the job while corporate data leaves into systems the organization does not govern. Source code is the most common content submitted to external generative AI in Verizon’s DLP data, by a large margin, followed by images and structured data. Research and technical documentation appear in 3.2% of those policy violations. On average, more than 15% of users have unauthorized AI browser extensions that retain browsing context, including internal sites. AI gives that identity exploring speed, more reach and more cover while the session remains legitimate.
That enablement changes what a stolen or misused session is worth. The identity now carries source code, retained browser context, and a personal AI account the enterprise cannot see or revoke. In the same VDBIR, credential abuse fell to 13% as an initial access vector while vulnerability exploitation climbed to 31%. Stolen credentials still hold at 36% across breach action varieties, and credential abuse appears in 39% of breaches across the full attack chain.
Exploitation often gets attackers in. Credentials are how they operate once inside, and escalate privilege quietly through session tokens, OAuth integrations, and SaaS access paths. Social engineering is 16% of breaches, with financial motive in 86% of those cases. Internal actors fell to 12% from 18%, and in Privilege Misuse breaches convenience is the leading motive at 60%. Intent is still the wrong measure. Breaches with third-party involvement reached 48%, up 60% year over year, the highest that figure has run in the VDBIR. The session looks like someone doing the job. The threat is what that authenticated identity moves without real authority: money, credentials, and proprietary material. Third-party compromise and the authenticated employee are now one operating problem.
Whether the insider is willing participant or unaware employee, AI tools have amplified their ability to expose the organization with speed and accuracy.
++
Michem Boles, Field Chief Information Security Officer at Intezer
September is National Insider Threat Awareness Month, and organizations should be paying closer attention to a form of insider risk that is easy to overlook. When employees turn to unsanctioned tools simply to get their jobs done, they can unknowingly become a threat.
Our recent research into NinjaMare shows how quickly that behavior can become a security problem. In the case we investigated, an employee looking for a basic productivity tool such as a PDF merger or compressor mistyped a URL and clicked a search ad. That single action led to an infection that gave an attacker remote control of the machine and remained undetected by security tools for two years.
The warning for organizations is clear. Insider threats do not always come from malicious employees. They can begin with well-intentioned staff improvising when approved tools are unavailable. Security teams should treat that behavior as a real risk and make legitimate, sanctioned alternatives easy to access.
++
Bojan Simic, CEO and co-founder, HYPR
GenAI, deepfakes and synthetic identities have fundamentally changed the hiring threat model. Bad actors can now pass an interview, get hired and receive legitimate credentials, without having to break in. We’ve seen this playbook associated with North Korean IT worker schemes, but as HYPR experienced firsthand, the threat extends well beyond any single country or campaign. The security failure happens when we authenticate a credential without first establishing that it belongs to the right human.
Organizations need to extend zero trust to Day Zero. Human intuition, a convincing video interview or a background check cannot be the final security control determining who receives access to corporate systems. Identity verification should be tied directly to credential provisioning, with phishing-resistant authentication and independent verification used to establish that the person being granted access is actually the person the organization intended to hire. As AI makes impersonation cheaper and more convincing, insider threat programs need to start as early as the interview stage and continue through to offboarding.
++
Guillaume Valadon, Head of Cybersecurity Research, GitGuardian
Hard-coded secrets in git commits are not a new problem. Most organizations underestimated them for years, and some still do. The fix sounds trivial: never hard-code a secret. The reality is harder, and the volume of hard-coded secrets keeps climbing. In most teams, nobody knows the secret is there. If they do, nobody knows who owns it, how to rotate it, or what breaks when it is. So nobody rotates it. The secret is still valid months or years after the commit that leaked it.
Pentesters and red teamers have known this for years. A hard-coded secret is the cheapest way into an engagement. Since spring 2025, attackers have industrialized it, with specifically crafted secret-stealing malware, and stopped waiting for the mistake. GitHub Actions first, then npm, PyPI and crates.io. They go where secrets legitimately live: in CI pipelines and on developer laptops. An environment variable used exactly as intended is readable by every package in the build.
AI widened the surface and shortened the clock. Agents, LLM tooling, and platforms use credentials because they cannot work without them. Each new agent is another entity holding another key, in another place nobody inventoried. During the OpenAI and Hugging Face incidents of July 2026, agents took the initiative to go hunting for credentials on their own. No attacker directed them. One chain went from a leaked credential to Kubernetes cluster admin in under thirteen hours.
Thirteen hours is the number that matters. A response that starts with “whose key is this, and what breaks if we revoke it?” has already lost. And the credential that gets taken is not necessarily one anybody hard-coded. It can be an environment variable, injected correctly, into a build that reads it exactly as designed.
The problem is not just hard-coding. It is not knowing what a leaked credential opens. What these attacks taught us is that secrets observability is the prerequisite, not the follow-up. An inventory of credentials by machine and severity turns a leak into a revocation list instead of an investigation.
++
Owen Parry, CISO, CyberFOX
Insider risk rarely starts with intent. It starts with an account that has more access than the role requires, and nobody ever takes the extra access back. From there the damage looks the same whether it comes from a careless employee or an attacker holding that person’s credentials. The account could do it either way, and the control that should have caught it was never really operating.
That last part is the problem most organizations don’t want to talk about. We buy a tool for a risk we haven’t staffed for, get it partly deployed, and never tune it. It sits on the budget and gets checked off on the insurance questionnaire, yet it isn’t enforcing anything. And the reason usually isn’t a skills problem. The teams I talk to know what to do. They just don’t have the time. The same one or two people are covering security, the help desk, and every onboarding and offboarding, and they aren’t also going to tune a platform that assumes a dedicated administrator on the other end. So price the labor before you price the license. If running the tool properly costs more in your people’s time than the license costs in dollars, you’ve bought a project, not a control.
The fix is to pick controls your team can run in an ordinary week: standard rights by default, elevation for the specific task, automatic revocation, and a log of all of it. Most teams can say who has admin. Fewer can show when they had it, for what, and who took it back.
++
Dr. Garfield Jones, EVP Strategy and Research, QuSecure
The cybersecurity risk posed by quantum computing is largely due to Harvest Now, Decrypt Later (HNDL) and Harvest Now, Forge Later (HNFL) attacks. Adversaries are already intercepting and storing encrypted traffic and data today, positioning themselves to exploit it once a cryptographically relevant quantum computer (CRQC) capable of running Shor’s algorithm becomes available — a capability some in the industry expect as early as 2029.
That CRQC would be capable of breaking the classical algorithms (RSA and ECC) currently used to protect data in transit and digital signatures. For any organization holding data with a long confidentiality shelf life — government records, health data, intellectual property, infrastructure control systems — the breach effectively happens now, even though decryption may not occur for years. This is why urgent transition to quantum-resistant algorithms needs to happen today.
Crypto-agility matters because PQC migration is a multi-year process spanning legacy system remediation, vendor and supply-chain dependencies, and hybrid deployment models that layer classical and post-quantum algorithms together during the transition. It’s also what allows an organization to keep pace with a still-evolving standards landscape — including future guidance under CNSA 2.0 and evolving federal directives (Executive Orders, OMB memos, and DoW guidance).
Certificate management is a critical operational focus for this transition, since digital certificates are the mechanism through which quantum-vulnerable algorithms are actually embedded across an enterprise — TLS certificates, code-signing certificates, device identity certificates, and the broader PKI underpinning them. Every certificate signed with RSA or ECC today is an HNFL exposure point, and PQ-safe certificates (particularly those using SLH-DSA) tend to be significantly larger than their classical counterparts, which can break systems not designed to handle bigger key and signature sizes — making automated, crypto-agile certificate lifecycle management essential rather than optional.
That operational reality is compounded by an interoperability constraint worth understanding: PQC and classical algorithms can’t communicate directly in transit, so an organization still running classical algorithms won’t be able to establish PQC-secured connections with one that has fully transitioned. The clearest near-term deadline illustrating this urgency is TLS 1.3, the earliest mandated federal transition, with a compliance date of January 2, 2030 — alongside a cryptographic bill of materials (CBOM) to inventory where vulnerable algorithms live across systems, applications, certificates, and third-party dependencies, prioritizing migration in OT/IT converged environments and AI infrastructure where both HNDL and HNFL exposure are highest.
++
Justin Dolly, Chief Customer and Security Officer, Ory
Organizations must treat agents with the same discipline they apply to human insiders: constrain what an agent can actually do, enforce those limits where actions execute, and be able to stop it the moment it moves beyond what its job requires. Insider threat programs were built around people. Onboarding, offboarding, access reviews and least privilege all assume that the thing with access to your systems is a human whose permissions someone deliberately scoped. AI agents break that assumption. They hold credentials, touch production systems, customer data, billing and deployment pipelines, often with the reach of a senior engineer. And in many organizations they are given that access all at once because scoping it down is slower than shipping.
That’s the insider threat problem repeating itself just with a new kind of insider. The lesson that mature insider threat programs have already learned is that access must be earned incrementally and narrowed constantly, not granted broadly and trusted by default. Agents are increasingly running with standing permission to do far more than any individual workflow requires, creating the same overprovisioning problem we’ve seen with human insiders. The difference is that an agent can act on that excess capability thousands of times a day without a human in the loop to notice it drifting.
Treat agents the way a mature insider threat program treats people: assume that access will eventually be used for something for which it wasn’t intended, and build the ability to constrain what an agent can actually do, rather than just logging what it did retrospectively. That means controlling capabilities at the point where actions execute, so a given agent can be limited to exactly what its job requires and stopped cold the moment it goes beyond those limits. It’s the same discipline we’ve spent two decades building for human insiders, just applied to a workforce that never sleeps.
++
Jonathan Halstuch, Co-Founder and CTO, RackTop Systems
People still picture a cyberattack as a hacker finding one software flaw and breaking in. But in reality, attackers use stolen credentials, trick employees or exploit trusted access. They combine a weak process, stolen credentials, excessive permissions and ordinary-looking actions until they can reach the data. Once a valid account is in play, an outsider can look like an insider. Login and perimeter controls still matter, but the decisive signal may come later, when sensitive data is accessed, copied, altered or removed.
Insider is not a payroll category. It includes contractors, along with the employees and contractors of suppliers or partners that hold your information. When you share data with another company, their insider risk becomes part of yours. Motives differ. Nation-states may steal information for military, intelligence or competitive advantage. Some state-backed cyber operations steal funds to finance government programs. Criminal groups turn stolen data and access into money to finance the next operation. Whatever the motive, the target is often the data.
Air gapping a system doesn’t prevent an authorized user from moving data through removable media. Isolation creates another problem, potentially preventing the system from sending events to central monitoring. That environment needs protection where the data lives: least privilege, a local record of user activity, behavior-based detection, and the ability to stop suspicious access in real time or large-scale data movement without a network connection to a central service.
++
Adam Dimopoulos, Chief Information Security Officer at Entrust
For years, insider threat strategies have focused largely on people: employees or contractors who misuse legitimate access, intentionally or otherwise. With the rise of agentic AI, strategies must shift in order to remain effective. An AI agent can be created by the organization, given legitimate credentials and perform an authorized business function, yet still introduce significant risk if it’s granted excessive authority, operates outside its intended boundaries, or retains access longer than necessary.
That’s why organizations need to treat AI agents as identities in their own right and apply theappropriate trust models to those agents. Giving an agent authority to act on someone’s behalf shouldn’t mean duplicating all of that person’s permissions. To control what agents are authorized to access and execute, organizations need to apply least privilege access, clearly defined decision boundaries, lifecycle management, and human oversight, especially for high-stakes actions.
National Insider Threat Awareness Month is a timely reminder that insider risk extends beyond people. The future of insider threat is increasingly about governing delegated authority. As AI systems become more autonomous, organizations need to continually ask: who or what an agent is acting for, what authority has been delegated, and whether that authority remains appropriate over time.
++
James Cassata, senior cloud security architect at Myriad360
Insider threat management programs are more important than ever. Between an increasingly mobile workforce, the normalization of remote and hybrid work, and the explosive growth of SaaS applications and AI platforms, organizations have more ways for sensitive data to leave their control than at any point in the past. And while malicious insiders, particularly disgruntled or departing employees who intentionally take company data with them, remain a serious concern, insider risk isn’t always malicious. A well-intentioned employee uploading sensitive information to a personal cloud account or an unsanctioned AI tool can create just as significant an exposure.
Many organizations have already addressed some of the traditional paths for data exfiltration, such as locking down USB ports and removable media. But those controls were designed for a different era. Today, an employee doesn’t need a thumb drive to walk out the door with sensitive information. Personal SaaS accounts, cloud storage services, web applications, generative AI platforms, and even simple copy-and-paste actions can provide alternative paths for corporate data to move into environments the organization neither controls nor monitors.
Like most cybersecurity challenges, there is no single control that solves the insider threat problem. Defense in depth is critical. Organizations should combine strong identity and access controls with data loss prevention, SaaS and cloud visibility, appropriate monitoring of user activity, and clear policies governing how sensitive information can be handled and where it can be stored. Just as importantly, those controls need to focus on the data itself and the context surrounding its movement, not simply the device or network it happens to traverse. The goal shouldn’t be to treat every employee as a potential threat, but to understand where sensitive data resides, recognize when behavior creates meaningful risk, and have the visibility and processes necessary to respond before that risk becomes an incident.
++
++
Andrew Hartnett, Chief Technology Officer at Bitwarden
Insider risk can stem from the deliberate misuse of legitimate access or from an honest mistake, and the potential damage grows when accounts retain broader access than a person needs. Stolen credentials present a different threat, but excessive permissions can magnify the impact in much the same way. Credential management is foundational, but organizations also need to govern what happens after access is granted, particularly for privileged access to critical systems and sensitive data. That means enforcing least privilege, reviewing access as roles change, and maintaining visibility and auditability into who accessed what and when.
The same access governance principles become even more important as organizations exponentially add machine identities, automation, and AI agents. Non-human identities require credentials and permissions, but broad, permanent access should not be the default. Each non-human identity should have a clear owner, with access scoped to a specific task, limited in duration where possible, and logged so teams can understand what was accessed and what actions were taken. Organizations also need the ability to revoke access quickly. These controls limit the impact when legitimate access is misused, credentials are compromised, or automated systems take unintended actions.
++
Corey Nachreiner, Chief Security Officer, WatchGuard
Here is my contrarian advice. Stop building your insider program around the angry employee and stop buying keystroke surveillance. It creates enormous noise and it teaches your staff that security is something done to them. Put the money in your hiring pipeline instead and treat it as a security control. Have a security practitioner sit in on remote technical interviews. Verify candidates on live video in ways that break deepfakes, like asking for unscripted movement, a physical ID held up to the camera, or a question about what is outside their window. Watch for the operational tells, like an address change right before the laptop ships. Attackers are working your job postings from both directions. Run a synthetic candidate through your own hiring process and see if anyone catches it. Almost no company has ever tried this, and it is the cheapest assessment you will run this year.
Then assume you will miss something and remember that most insider risk is not malice. It is your well-meaning majority. Our 2026 Cybersecurity Hygiene Report found 76 percent of employees reusing passwords and 64 percent putting work data into Shadow AI tools nobody approved. Those numbers did not improve with seniority or education, which means your highest privileged people are in them. We have run this play before and called it Shadow IT. Everyone tried bans first and everyone failed. What worked was discovery, then governance. Visibility first, policy second. In practice, that means no standing privilege, because there is nothing to abuse at 2 a.m. if nothing was granted at 2 a.m. It means two people are required for the actions you cannot undo. It means rate limits and required reason codes on customer record lookups, because those support agents should never have been able to browse all the accounts in the first place. And it means applying every one of those controls to your AI agents too. Nearly every incident I described started with someone making a perfectly reasonable decision. Nobody was reckless. They just were not visible. We spent a decade learning how to watch people, and the next insider incident at most companies will involve an identity that never had a pulse.
++
Gene Moody, Field CTO, Action1
Insider threats are uniquely difficult to detect because malicious activity often looks almost identical to legitimate work. Such as an admin accessing a production database, an engineer moving files, or an employee exporting information can all be routine. The actions are legitimate normal work processes, the difference is all intent, and whether anyone has the context to recognize when legitimate access is being abused.
It is a bigger problem than most would guess. Verizon’s 2025 Data Breach Investigations Report recorded 825 incidents involving privilege misuse, including 757 with confirmed data disclosure. Ninety percent of the actors were internal, with financial gain the primary motive.
The overarching lesson? The people best positioned to exploit a system are often those who understand it best and use it frequently.
There is also a very human factor that is often overlooked as it is all to easy to paint the villain vs understand the motivation. Burnout, staffing pressure, and disengagement don’t automatically create malicious employees, instead they produce shortcuts, undocumented workarounds, and less scrutiny of anomalous activity. Resentment can also lead someone to rationalize wrongdoing with a “They owe me this”, or “They deserve this” mentality. The feelings may be justified, however the crime never is. The first sign is often “Quiet Quitting” where employees neglect all but the minimum required to stay employed. Pay attention to employee wellbeing, where financial gain may be the primary motive, employee. Studies reflect that the tipping point where most crossed from employee to criminal was not the just money itself, but the justification of the crime in the personal position of how the employee felt wronged.
Insider-threat prevention isn’t about distrust, it is about ensuring trust doesn’t mean unrestricted access, and legitimate access doesn’t mean invisible access.
The questions aren’t simply “Who can access this?” but “Why do they need it, what did they do with it, and would we notice if that access suddenly changed?”
And equally important: “Are my employees productive, or simply surviving?”
++
Brian Hussey, VP, Howler Cell Threat Services, Cyderes
Most insider threat programs are built to catch a policy violation. Insiders rarely commit one. The account is valid, the access was granted on purpose, and the activity falls inside that person’s job. Your controls approved it in advance.
We see this in several ways in the field. One example that has been frequently hitting the news recently are North Korean IT workers. They apply, interview, get hired, and receive a laptop and credentials through the front door. Bad leavers give notice and can spend their last three weeks pulling the customer list and the pricing model, and nothing they touch was off limits to them the day before. The one I worry about most is the bought insider. Scattered Spider and ShinyHunters have money to spend, and paying an employee for a credential, an MFA approval, or one command run on an internal host is cheaper and faster than burning an exploit.
Organizations cannot alert their way out of this. Authorized activity does not trip rules. What works is knowing what is normal and hunting for what falls outside it. Baseline the account, not the network. What does this person open, from where, at what hours, in what volume. Then go looking for the drift. A sales engineer exporting the full CRM instead of pulling five records. A repository nobody on that team has touched in eight months. A login from a residential IP at three in the morning on an account that has never worked off hours. Accessing and downloading sensitive data spiking two weeks after somebody resigns.
Those are hypotheses, not alerts, and a threat hunt team has to go find them in data the SOC has no reason to escalate. The same work turns up risk you did not know you had. Service accounts with far more privilege than their function needs. Contractors still holding access after the project closed. Live credentials for people who left last year. Fix those and you have removed the insider’s easiest path before anyone uses it.
++
Mandy Andress, CISO, Elastic
As we recognize National Insider Threat Awareness Month, we need to expand our definition of what an “insider” actually is.
With generative AI now embedded in daily enterprise workflows, autonomous AI agents have become key actors in our digital environments. When these agents take unintended actions to meet their programmed objectives, they effectively represent a new class of insider threat. The security impact mirrors that of a traditional human insider, but the speed, scale, and capability of AI mean the potential magnitude is far greater.
The core danger lies in how AI agents solve problems. Because they are non-deterministic, we cannot always anticipate how they will pursue their objectives. If an agent encounters a security barrier, it won’t simply stop. It may attempt to bypass established controls, escalate its own permissions, or manipulate other agents in the environment to achieve its goal. Security teams frequently underestimate this risk, and organizations compound it by defaulting to open access permissions to avoid operational friction.
Mitigating this requires treating identity as the primary control plane for AI. The same zero trust and least privilege principles we apply to humans must apply to machines. Every AI agent needs its own distinct identity, scoped strictly to the minimum data and permissions required to do its job. Pair that with layered programmatic guardrails and logic transparency, and organizations can adopt AI safely. Without it, autonomous agents become the most dangerous insiders we’ve ever introduced.
##






