Insider Threat: Definition, Types, Examples and Controls
An insider threat is not a kind of person you can pick out of a room. It is a piece of access doing something it was never meant to do, and most of the time nobody involved meant any harm at all.

The phrase sounds like it describes a kind of person, and that is where most of the trouble starts. The usual advice is a list of things to notice about colleagues: mood, hours, dissatisfaction with management. CISA's own mitigation guide says plainly that no such profile works. What an insider threat describes is access, granted deliberately, doing something it was not meant to do. Sometimes that is a person acting on a grievance. Far more often it is a spreadsheet pasted into the wrong tool, or a login that belongs to a real employee and is being used by somebody else.
What Is an Insider Threat?
Two definitions do most of the work here, and they agree with each other.
CISA defines an insider as any person who has or had authorized access to or knowledge of an organization's resources, including personnel, facilities, information, equipment, networks and systems, and an insider threat as the potential for that person to use their authorized access or their understanding of the organization to harm it. NIST's glossary puts the same idea in one sentence: the threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of organizational operations and assets, individuals, other organizations and the Nation. That wording is from NIST SP 800-53 Rev. 5.
Two words in the NIST version carry the whole topic. Wittingly or unwittingly means the category is not defined by intent. The person who sells a customer list and the person who emails it to the wrong address are both insider threats, because the definition is built on the access and the harm rather than the motive. Programs built entirely around catching bad actors miss most of what happens.
Both definitions also refuse to say employee. Organizations grant access to contractors, temporary staff, auditors, managed service providers and the developer who left in March whose account is somehow still enabled. CISA's mitigation guide adds the idea that ties them together: every insider threat has or had some level of a trust relationship with the organization it harms, and acts outside the expectations of that relationship.
What Is Considered an Insider Threat?
Two questions hide inside this one. Who counts as an insider, and which acts count as a threat.
Who counts is settled by where the access came from. If the organization granted it, the holder is an insider for as long as it works: current employees, former employees whose accounts are still live, contractors and temporary staff, vendors and managed service providers with a remote connection, partners with a shared drive, and anyone carrying detailed knowledge of how the place runs after the login itself is gone.
What counts is broader than data theft. CISA groups the ways an insider threat shows up into five expressions: violence, espionage, sabotage, theft and cyber acts. Violence includes threats and intimidation against the workplace; espionage is taking information for a competitor or a foreign government; sabotage is damaging systems, property or operations; theft covers money and intellectual property; and cyber acts are the same four carried out through technology.
What does not count matters just as much. An attacker who finds an unpatched server and breaks in has no granted access, so that is an external threat, even though the end result is a data breach either way. The distinction decides which controls are in scope: patching and perimeter filtering for one, access reviews and logging for the other. The moment that outsider is signed in with a real employee's credentials, though, the harm is being done through insider access, and the insider controls are the ones that catch it.
What Are the Types of Insider Threats?
Two schemes are in circulation and a searcher will meet both. Most vendors use three kinds sorted by what the person intended. CISA sorts by intentional against unintentional and then adds two categories describing who else is involved. They cover the same ground.
| Kind | What is happening | CISA's category |
|---|---|---|
| Malicious | Someone with access deliberately takes, damages or leaks something | Intentional |
| Negligent | Someone knows the rules and works around them, usually to get a job done faster | Unintentional, negligence |
| Accidental | Someone makes a mistake with no rule breaking involved at all | Unintentional, accidental |
| Compromised | The access is genuine, the person using it is not | No category of its own |
| Collusive | An insider works with an outside group, often for payment | Collusive |
| Third party | A contractor or vendor with granted access, deliberate or careless | Third-party |
CISA's guide is blunt about which end of that table carries the volume. Insider threats are intentional and unintentional, it says, and a significant portion of them involve negligent or accidental behaviors. It adds that not all intentional insider threats are malicious, which is the category covering the employee who copies files to a personal drive so they can finish something at the weekend.
The compromised insider
This is the kind that connects insider threat to every other attack, and the one worth following step by step. The account is real. The password arrived through a phishing message, through a password reused on a site that leaked and found by credential stuffing, or through a phone call to a help desk. Everything after that looks exactly like an employee doing their job.
- Credentials takenA fake login page, a reused password, or a call to the help desk
- Sign-in succeedsReal account, real password, sometimes a real approved MFA prompt
- Perimeter controls pass itFirewall, filtering and allow lists all see a member of staff
- Data accessed at ordinary scaleFiles this account is entitled to open, in volumes that look normal
- Behavior does not match the personA new country, odd hours, a forwarding rule, a bulk export
Which Is an Example of an Insider Threat?
One example for each of the three working kinds.
Malicious: the developer who left a kill switch. In August 2025 the Department of Justice announced that Davis Lu, a software developer at a company headquartered in Beachwood, Ohio, had been sentenced to four years in prison for causing intentional damage to protected computers. A 2018 realignment had cut his responsibilities and his system access. He responded with code that crashed servers using infinite loops, deleted coworker profile files, and a routine named IsDLEnabledinAD that would lock out every user if his own Active Directory account were ever disabled. It fired by itself on the day he was placed on leave and asked to hand back his laptop. Losses ran to hundreds of thousands of dollars. Nothing in that sequence needed an outside attacker or a vulnerability. It needed production access and a change in his standing at the company.
Negligent: data walking out through a tool nobody approved. The 2026 Verizon Data Breach Investigations Report found frequent use of AI tools by employees rising from 15 percent to 45 percent in a single year, with shadow AI, meaning staff using unapproved AI tools at work, now the third most common activity related to non-malicious data leakage. Nobody in that figure is stealing anything. They are pasting a customer list into a chatbot to have it summarized, which is the same act as emailing the list to a stranger and feels nothing like it.
Compromised: the login that belonged to a real employee. The pattern behind two of the breaches written up on this site this year is social engineering aimed at staff, usually by phone, followed by a session inside a legitimate account.
What Are the Warning Signs of an Insider Threat?
Insider threat is unusual among the threats a small company actually meets in that the warning signs are usually described as things to notice about people. That framing is the problem.
CISA's Insider Threat Mitigation Guide states that for the purposes of threat assessment there is no useful profile to identify and assess the potential risk of an individual committing an insider incident, and that prospective profiling carries considerable risk of false positives. Its position is that behaviors, informed by life circumstances, are what matter to an assessment, not a person's demographic details. A checklist asking managers to notice who seems dissatisfied pulls against that advice, and mostly generates reports about people who are tired.
What the research supports is narrower and more useful. The same guide records a study by CERT at Carnegie Mellon and the Secret Service National Threat Assessment Center of 23 insider incidents of computer system sabotage, in which 85 percent of the insiders held a grievance before the incident and in 92 percent of those cases the grievance was work related. It also separates making a threat from posing a threat, and notes that insider incidents are rarely sudden, impulsive acts. The practical reading: an unresolved workplace grievance is a management problem worth solving on its own merits, not a score recorded against a person.
The signals worth building an alert on are about data and access.

How to Detect Insider Threats
Detection runs on two channels and most organizations build only one of them.
The human channel is the one CISA emphasizes and the one that gets no budget. A study in the banking and finance sector cited in the mitigation guide found that in 85 percent of incidents, someone other than the insider had full or partial knowledge of that person's intentions, plans and activities, and the incidents were still not thwarted. The knowledge existed inside the organization and had nowhere useful to go. What fixes that is unglamorous: a reporting route with an anonymous option, a stated process for what happens after a report, and training that says outright that colleagues are usually the ones who notice first.
The technical channel is logs, plus the time to read them. The minimum useful set covers authentication, file access on the systems holding anything valuable, mailbox forwarding rules, privilege changes and data leaving the network. One place where the logs land is worth more than a better tool watching a single system, because insider activity shows up as a pattern across several rather than as an event in one.
User behavior analytics and data loss prevention are the products sold for this job, and both work when the baseline underneath them is real. A company that knows which data matters and where it lives gets alerts that mean something; a company that switches everything on everywhere gets a queue nobody reads. Access reviews outperform both and cost only time.
How to Prevent Insider Threats
Every control below either shrinks what one account can do or shortens the gap between an action and somebody noticing it. None of them depends on knowing in advance which person is the risk, which is the point.
The architectural version of the first item is zero trust, which treats every request as unverified regardless of where it came from or whose account made it. That is the right long term direction and a multi-year project. The access review is the version a small company can finish this month.
What Is an Insider Threat Program?
A program is the standing arrangement for doing all of the above deliberately rather than after an incident. CISA describes such a program as combining physical security, personnel awareness, and information-centric principles, and sets out four steps: define what an insider threat means for this particular organization, detect and identify people who come to attention through observable concerning behavior, assess whether there is genuine intent and capability, and manage the case to a resolution.
In a company of thirty people that is a one page document and two named people, plus an agreement to call a lawyer before anyone opens an employee's mailbox. In a large organization it is a standing team drawn from security, HR, legal and management, because an assessment made by security alone tends to end in a dismissal that creates the grievance it was meant to defuse.
The legal weight is easy to miss. CISA's guide states that all insider threat programs touch multiple complex legal considerations including privacy and civil liberties, whistleblower protection, employment law, health and educational privacy, liability, and individual due process rights. Monitoring an employee's communications is a decision to take with legal counsel in advance, not a setting to switch on quietly. And if an incident happens anyway, what to do after a data breach is the same work whether the access was borrowed or granted.
Key takeaways
- An insider threat is harm done through access the organization granted, wittingly or unwittingly. Intent is not part of the definition.
- Insiders include contractors, vendors, partners and former staff whose accounts still work, not only employees.
- The working kinds are malicious, negligent and compromised. CISA adds collusive and third-party, and splits the unintentional side into negligence and accident.
- Negligence is the volume, the compromised account is the hardest to see, and the deliberate saboteur is the rarest of the three.
- There is no useful profile of a person who will do this. CISA says so in its own guide, and behavior around data and access is what a program should be built on.
- Detection needs both channels: a reporting route people trust, and logs on the systems holding anything valuable, read by somebody.
- The cheapest effective controls are an access review, offboarding on the day, separation of duties and phishing-resistant sign-in.
Common questions
What are the four types of insider threats?
Most lists give malicious, negligent, accidental and compromised. CISA organizes it as unintentional, split into negligence and accident, against intentional, then adds collusive insiders working with an outside group and third-party insiders such as contractors. The compromised account, where the access is genuine and the user is not, has no category of its own, and CISA files the phishing that produces it under the cyber expression.
What is not considered an insider threat?
An attacker who was never given anything. Breaking in through an unpatched server or an exposed service is an external threat, because the boundary is the grant rather than the damage. Borrowed credentials are the exception, and they put the incident back inside.
Are most insider threats malicious or accidental?
Accidental and negligent. CISA's mitigation guide puts a significant portion of insider threats in that category, and the everyday version is a file sent to the wrong address or pasted into a tool nobody approved. Deliberate sabotage is the rarest kind, which is why it is the version most people picture.
What is the difference between insider risk and an insider threat?
Insider risk is a permanent condition: people hold access, and that access could be misused. An insider threat is a specific case where there is reason to believe misuse is happening or about to. Risk is managed by design, through least privilege and offboarding. A threat is managed by named people following an agreed process.
Can a contractor or a vendor be an insider threat?
Yes, and CISA gives them their own category. Anyone granted access to facilities, systems, networks or people is an insider for as long as that access works, including a managed service provider with a remote connection. Third-party access deserves the same reviews, logging and offboarding as an employee's.
Is a former employee still an insider threat?
Until every account, key, token and shared password they knew has been dealt with, yes. CISA's definition covers any person who has or had authorized access or knowledge of an organization's resources. The knowledge outlasts the login, which is why the accounts should not.
Who should manage insider threats in a small company?
Two named people, usually whoever runs operations and whoever runs IT, with a lawyer to call before anyone reads an employee's messages. Naming them in advance matters because the first insider case is a bad moment to decide who decides. Larger organizations pull the same group from security, HR, legal and management.
Do remote workers create more insider threat risk?
They change its shape more than its size. Personal devices make careless data handling easier and physical oversight impossible, and voice phishing works better when a phone call is a normal way to meet a colleague. The answers are the same: least privilege, phishing-resistant sign-in, and logging on the systems holding the data.
What advantage does an insider have over an outside attacker?
They start inside. No perimeter to cross, no vulnerability to find, no alarm for a login that was supposed to happen. They also know where the valuable data lives and which activity looks normal, which is knowledge an outsider spends weeks acquiring. That is why detection rests on behavior over time rather than on one blocked event.

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.