← All terms

Insider Threat

An insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.

An insider threat is the risk posed by people who already have legitimate access to an organization's systems, data, or facilities — employees, contractors, vendors, and partners. Unlike an external attacker, an insider does not need to break in; the damage comes from how trusted access is used. Security frameworks group insiders into three types: malicious (deliberate theft, sabotage, or fraud), negligent (rule-bending, misdirected emails, unsafe shortcuts), and compromised (an outsider operating through a hijacked insider account).

How it works

Malicious insiders are the headline cases — a departing engineer exfiltrating source code, a finance employee running invoice fraud from the inside, a system administrator planting a logic bomb. Their advantage is context: they know where the valuable data lives, what monitoring exists, and how approvals work.

Negligent insiders are far more common. They upload confidential files to personal cloud storage to work over the weekend, reuse passwords that later surface in credential-stuffing lists, or approve a payment without verification. There is no intent to harm — which is exactly why traditional deterrents do little.

Compromised insiders sit in between: social engineering turns a well-meaning employee into an unwitting access vector. Once an attacker phishes a valid account, everything they do looks like insider activity, blurring the line between the two problems.

How to defend against it

Start with least privilege and timely deprovisioning: people should hold only the access their current role requires, confirmed through periodic user access reviews and revoked the day it is no longer needed — departing employees deserve special attention. Layer on monitoring that flags anomalous behavior (mass downloads, off-hours access, forwarding rules to external addresses) rather than trying to read intent, and data loss prevention controls that catch sensitive data leaving through unauthorized channels. Separate duties for sensitive actions such as payments and production changes so no single person can complete them alone.

Because the negligent majority responds to habits rather than warnings, continuous behavior-focused training and a blame-aware reporting culture do more than policy documents. Measuring which individuals and teams accumulate risky behaviors — the goal of a human risk score — lets security teams support the right people before a mistake, or a grievance, becomes an incident.

Full guide
Read the deep dive on this attack →

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.CEO FraudCEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.Credential StuffingCredential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.Shoulder SurfingShoulder surfing is observing someone's screen or keyboard to steal passwords, PINs, or confidential data — in person or via cameras in public spaces.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo