The person may be a current or former employee, contractor, partner, or another trusted participant. Harm can be deliberate, negligent, or unintentional and may affect information, systems, finances, facilities, safety, people, or reputation.
Insider-threat management should protect the organization without treating every worker as an adversary. Effective programs combine clear policy, proportionate access, workforce support, secure reporting, technical monitoring, privacy and employment safeguards, and multidisciplinary assessment of concerning situations.
Key points
Malicious activityTheft, fraud, sabotage, espionage, unauthorized disclosure, or deliberate policy evasion.
Unintentional activityMistakes, unsafe workarounds, misdirected information, weak credential handling, or actions taken without understanding the risk.
Risk reductionLeast privilege, separation of duties, access reviews, monitored privileged activity, secure offboarding, training, and supportive reporting channels.
Important limitationA technical anomaly does not establish intent or wrongdoing. Assessment must be lawful, proportionate, evidence-based, protected from bias, and coordinated with the appropriate privacy, legal, human-resources, and security functions.