GlossarySecurity awareness

Insider threat

Short answer

An insider threat is a security risk that comes from people inside the organisation, or with trusted access to it, such as employees, former employees, contractors or partners. It can be malicious, negligent or the result of an account being compromised.

Three types

Malicious insiders deliberately steal data, sabotage systems or commit fraud, often around a resignation or a dispute. Negligent insiders cause incidents by mistake: sending a file to the wrong person, falling for phishing or using unapproved tools. Compromised insiders are legitimate accounts taken over by an attacker, who then acts with that person's access.

Why it is hard to detect

Insiders already have legitimate access, so their activity looks normal to most controls. The warning signs are usually unusual behaviour: downloading large volumes of data, accessing systems unrelated to the role, activity at odd hours or copying files to personal storage shortly before leaving.

How to reduce the risk

Most measures are about limiting what any single person can do: least privilege and regular access reviews through IAM, removing access on the day someone leaves, segregation of duties for payments and critical changes, DLP on sensitive data, logging and monitoring, and awareness training. Background checks and confidentiality agreements cover the hiring side.

Where it shows up in compliance

ISO 27001 includes screening, terms of employment, disciplinary process, responsibilities after termination and segregation of duties (Annex A 6.1 to 6.6 and 5.3). Monitoring employees must respect the GDPR and, in Spain, workers' digital rights.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub