National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.
Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.
Eric Polet, Director of U.S. Operations, Arcitecta had this to say:
“At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.”
Max Gannon, Cyber Intelligence Team Manager at Cofense adds this:
“Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.
Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.”
Piyush Sharrma, co-founder and CEO at Tuskira says this:
“Insider risk gets much more complicated once you stop looking at permissions as a flat list.
A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.
Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.
AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.
With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.”
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ adds this:
“An insider already has what an external attacker usually wants first: access.
That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.
Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.
This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.
Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”
Ross Filipek, CISO at Corsica Technologies follows with this:
“The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.
Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.
Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.
Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”
Kevin Kirkwood, CISO at Exabeam had this to say:
“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.
Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.
Now organizations have another insider entering the workforce: AI agents.
Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.
Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.
The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”
Kevin Mata, Director of Cloud Operations and Automation at Swimlane says this:
“One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.
That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.
AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.
That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”
Michael Centrella, Head of Public Policy at SecurityScorecard:
“National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.
Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.
Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.”
John Bruggeman, vCISO at CBTS adds this:
“National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.
With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?
Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.
Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.”
You can read more about this here: https://securityawareness.dcsa.mil/cdse/nitam/index.html
Related
This entry was posted on September 1, 2026 at 8:30 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Today Starts National Insider Threat Awareness Month
National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.
Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.
Eric Polet, Director of U.S. Operations, Arcitecta had this to say:
“At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.”
Max Gannon, Cyber Intelligence Team Manager at Cofense adds this:
“Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.
Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.”
Piyush Sharrma, co-founder and CEO at Tuskira says this:
“Insider risk gets much more complicated once you stop looking at permissions as a flat list.
A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.
Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.
AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.
With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.”
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ adds this:
“An insider already has what an external attacker usually wants first: access.
That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.
Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.
This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.
Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”
Ross Filipek, CISO at Corsica Technologies follows with this:
“The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.
Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.
Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.
Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”
Kevin Kirkwood, CISO at Exabeam had this to say:
“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.
Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.
Now organizations have another insider entering the workforce: AI agents.
Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.
Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.
The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”
Kevin Mata, Director of Cloud Operations and Automation at Swimlane says this:
“One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.
That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.
AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.
That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”
Michael Centrella, Head of Public Policy at SecurityScorecard:
“National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.
Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.
Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.”
John Bruggeman, vCISO at CBTS adds this:
“National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.
With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?
Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.
Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.”
You can read more about this here: https://securityawareness.dcsa.mil/cdse/nitam/index.html
Share this:
Like this:
Related
This entry was posted on September 1, 2026 at 8:30 am and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.