National Insider Threat Awareness Month (NITAM) is a critical reminder that some of the most damaging security incidents originate from within. Human error, policy bypasses, and phishing-induced lapses account for most internal breaches, often costing millions to fix.
Organizations can protect their sensitive information by strengthening internal defenses, adopting stronger controls such as multifactor authentication and authorization, and fostering a culture of vigilance.
Eric Polet, Director of U.S. Operations, Arcitecta had this to say:
“At a time when cyberattacks are more frequent and data environments are larger and more complex, safeguarding critical assets requires continuous vigilance, intelligent monitoring, and a proactive defense against internal vulnerabilities.”
Max Gannon, Cyber Intelligence Team Manager at Cofense adds this:
“Insider threats are often associated with employees who intentionally misuse their access, but that definition misses a growing part of the risk. External attackers can create many of the same problems by stealing employee credentials, hijacking sessions or manipulating users through social engineering. Once they are operating through a legitimate account, malicious activity can be much harder to distinguish from normal business behavior.
Insider risk is no longer only a question of employee intent. It also includes how trusted access can be compromised. Employees are often the first to notice when a login request, MFA prompt or message feels out of place, making human context an important signal in identifying misuse of trusted access that may otherwise appear legitimate. Insider Threat Awareness Month is an opportunity to broaden the conversation around what insider risk actually looks like today.”
Piyush Sharrma, co-founder and CEO at Tuskira says this:
“Insider risk gets much more complicated once you stop looking at permissions as a flat list.
A user may only have access to a handful of systems. One of those systems may trust another identity. That identity may connect to a cloud role. An exposed vulnerability may open the next step. What looked like fairly limited access on paper can become a path to something far more sensitive.
Security teams already have plenty of data describing vulnerabilities and identities. The harder question is how those pieces connect.
AI-assisted attack-path analysis can trace that relationship across an environment. It can identify where legitimate access intersects with exploitable weaknesses. It can also show whether existing controls break the path before critical assets become reachable.
With insider threats, the first credential doesn’t have to be stolen. Sometimes it was legitimately issued. The security problem begins with everything that credential can reach next.”
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ adds this:
“An insider already has what an external attacker usually wants first: access.
That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.
Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.
This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account or malicious contractor tries them.
Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”
Ross Filipek, CISO at Corsica Technologies follows with this:
“The insider threat problem isn’t always dramatic. Sometimes nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company and their SaaS accounts aren’t shut down until days later.
Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have one team watching the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.
Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.
Insider threat programs don’t have to start with sophisticated surveillance. For a lot of businesses, simply making sure people only retain the access they actually need could eliminate a surprising amount of risk.”
Kevin Kirkwood, CISO at Exabeam had this to say:
“We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.
Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful once they were viewed together.
Now organizations have another insider entering the workforce: AI agents.
Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.
Insider Threat Awareness Month should push security teams beyond asking whether an identity successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.
The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.”
Kevin Mata, Director of Cloud Operations and Automation at Swimlane says this:
“One strange login probably isn’t enough to call something an insider threat. Neither is a large download or an unexpected privilege change. The challenge starts when several of those signals appear around the same person and nobody has the full picture.
That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.
AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.
That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”
Michael Centrella, Head of Public Policy at SecurityScorecard:
“National Insider Threat Awareness Month often brings to mind the traditional image of a malicious employee walking out with sensitive information. Today’s threats show that this is only one part of a much larger issue. Organizations also have to contend with outsiders who obtain legitimate access, contractors who can be recruited or compromised, stolen identities, and employees who intentionally or unintentionally put sensitive information at risk.
Recent incidents show both sides of that equation. A North Korean IT worker was hired by a U.S. government agency, giving a suspected foreign actor legitimate access through the front door rather than forcing them to break through the perimeter. In another case, a former TD Bank employee pleaded guilty after accepting bribes and using his legitimate access to obtain confidential customer information that was passed to outside co-conspirators. In one case, an outsider became a trusted insider. In the other, a trusted insider became an avenue for outside criminals.
Insider threat programs cannot rely only on pre-employment screening or assume that a valid account equals a trusted user. Security teams need to understand what access people and third parties actually require, limit privileges accordingly, and identify when behavior begins to deviate from the role behind the credentials. Trust cannot be treated as permanent. In a workforce increasingly made up of employees, contractors, remote workers, and external partners, authorized access needs the same ongoing scrutiny as any other part of the attack surface.”
John Bruggeman, vCISO at CBTS adds this:
“National Insider Threat Awareness Month is a reminder that insider risk extends well beyond the traditional image of a disgruntled employee. A legitimate account can create serious exposure when it is compromised, misused, or retains access that no longer reflects the user’s responsibilities. Most of the time I see organizations have good on-boarding processes but weak off-boarding processes.
With Agentic AI, AI is now an insider threat, AI could now be your weakest link. You need to make sure your AI agents can be trusted, just like your employees. What you want to consider is whether you can recognize when trusted access begins to deviate from its intended purpose. Ask yourself, can you recognize when trusted access, human or AI, starts to drift from its intended purpose?
Answering that question requires disciplined identity governance and consistent oversight. Access should be reviewed as roles change, employment ends, or business needs evolve. Security teams also need enough visibility to recognize meaningful changes in how an account is being used without relying on a single signal. A login from an unexpected location or access to information outside a normal work pattern may warrant scrutiny, particularly when it involves sensitive systems.
Organizations should always know who can reach critical data and why that access is still necessary. Align identity controls with monitoring, and misuse gets caught earlier, before it has room to spread.”
You can read more about this here: https://securityawareness.dcsa.mil/cdse/nitam/index.html
UPDATE: Additonal commentary has come in starting with Amit Shuster, VP, Product and Engineering, Vetric:
“Executive impersonation is a growing insider threat method, as attackers can now combine publicly available video with knowledge of an organization’s leadership, processes and culture to create highly convincing requests. A familiar face and voice can make an urgent instruction from a CEO, for example, to transfer funds, disclose sensitive information or bypass a control feel legitimate, particularly when it appears through the video platforms employees already use and trust. Falsified videos floating online could also cause unfounded internal AND external reputational concern, depending on the content.
This Insider Threat Awareness Month, organizations should focus on understanding how legitimate insiders can be manipulated or even tricked into believing fraudulent information. They need verification processes that do not depend on a video’s apparent authenticity. Investigators, meanwhile, need visibility into how impersonation content is created, distributed and coordinated across difficult-to-monitor platforms.
Video intelligence tools can help investigators close those coverage gaps and identify patterns of harmful activity, enabling organizations to respond before a convincing impersonation causes widespread damage.”
Mike Wade, VP, Customer Success, Gravwell
“Insider threat activity often originates from people and systems that are already trusted. The warning signs rarely live in a single alert or data source, making them particularly challenging to detect. They emerge when security teams can connect activity across identity, network, endpoint, cloud and other telemetry over time. That makes broad, full-fidelity visibility especially important. If critical data was filtered out, discarded or never collected because of cost or architectural limitations, teams may discover during an investigation that the context they need is simply gone.
Insider Threat Awareness Month highlights the need for organizations to think beyond collecting alerts and focus on whether investigators can actually access and interrogate the data when it matters.
Security teams need the freedom to retain diverse telemetry, look back historically, and ask new questions of that data as an investigation evolves. You can’t predict which piece of information will prove decisive in advance, so building a security data strategy around preserving visibility gives defenders a much stronger foundation for detecting, investigating and responding to insider activity.”
Arvind Parthasarathi, CEO and founder, CYGNVS
“September is Insider Threat Awareness month, and this year, there’s a new insider threat to watch…and many companies don’t even realize it. Organizations are giving AI agents broad access to corporate systems and data, and unlike human insiders, they move at machine speed. On top of that, they don’t even need malicious intent to cause serious damage. An agent pursuing the wrong objective (or the right objective without proper guardrails) can create a security, legal or regulatory crisis before the human response team even understands what happened. That gives Insider Threat Awareness Month a new twist.
Different human insider situations require different response playbooks, and AI now makes that challenge far more complex. Organizations are deploying agents faster than they’re developing playbooks for when those agents cause harm, if they’re building them at all.
Response teams need answers before an incident occurs: Who has the authority to stop an agent? How do we contain it? What evidence do we preserve? What legal or regulatory obligations are triggered?
And they need a trusted place to run that response. If the systems and communications you normally rely on are implicated in an AI incident, you don’t want to collaborate on your response inside them. An out-of-band command center gives security, IT, legal, communications and executives a separate environment to take control, contain the incident and make decisions when speed and trusted coordination matter most.”
Catalyst by Zoho Solves The Shortfalls of Moving from Coding to Production With an Agent-Ready, Full-Stack Cloud and Built-In Governance
Posted in Commentary with tags Zoho on September 2, 2026 by itnerdZoho Corporation, a global technology company, today announced major enhancements to Catalyst by Zoho, its Platform-as-a-Service (PaaS), now weaving agentic development capabilities directly into the coding environments developers already use. Additions include Agent Skills, a non-interactive command-line interface (CLI), and Model Context Protocol (MCP) support to Catalyst’s platform, along with new integrations for agentic AI coding assistants including Anthropic’s Claude Code and OpenAI’s Codex. To enhance accessibility and empower future developers, the platform is also offering a free student program that includes full-stack hosting, functions, database, and AI tooling.
Catalyst by Zoho bridges the gap between code generation and reliable deployment by giving agentic AI coding assistants a structured, deterministic way to build and deploy applications. Developers can use the AI coding assistants of their choice while Catalyst provides the underlying full-stack serverless infrastructure and controls, eliminating the need to stitch together multiple cloud services and vendors. This approach simplifies development and future iterations while reducing operational complexity,positioning Catalyst as a reliable partner as technical capabilities and customer needs evolve.
Turning AI-Generated Code Into Production-Ready Applications
AI coding assistants can generate code quickly, but getting it to production requires deep platform knowledge, cloud services, and deployment workflows. Catalyst brings these together on a single serverless full-stack cloud, offering AI coding assistants what they need to build, test, and deploy applications. These capabilities make this possible:
Catalyst Agent Skills gives coding assistants the context they need to understand Catalyst services, architecture, and recommended development patterns. Rather than relying on the model to determine how Catalyst should be used, the Skill guides the assistant toward the appropriate capabilities and workflows. By surfacing only the capabilities relevant to the task, they help assistants make the right application and service choices, optimize token use, and generate accurate, verified output even with lighter models.
The non-interactive CLI allows AI coding assistants to execute multi-step workflows in Catalyst from start to finish without requiring human input at every step. This reduces manual intervention and helps developers move faster from coding to deployment.
The Catalyst MCP server provides AI coding assistants direct access to Catalyst capabilities from the developer’s existing environment. Actions such as creating a database table or adding a column can be performed directly from VS Code, Claude Code, Cursor, or any AI IDE without switching to the Catalyst console, keeping development in one workflow and accelerating delivery.
Orchestration, built into the Skill, ties the three capabilities together. When an AI coding assistant faces a decision about how to execute a request, the Skill routes it deterministically down the CLI or MCP path rather than leaving that choice to the model. This approach lowers the developer’s cognitive load, reduces the risk of incorrect tool selection, and helps produce more reliable, production-ready applications.
Built on Zoho’s Platform with Humans in Mind
While each service may work well independently, managing a fragmented stack can add operational complexity and make security, privacy, and governance harder to maintain. Applications built on Catalyst run inside Zoho’s own data centers and inherit Zoho’s robust security infrastructure, including DDoS protection, SOC compliance, regular vulnerability assessment and penetration testing (VAPT), a web application firewall, and more.
Human oversight is built into the deployment process rather than added afterward, giving organizations greater control as AI becomes part of application development:
Decoupled environments keep development and production separate. Code moves to production by manual promotion only—ensuring the AI agent never touches production, eliminating the risk for error.
Scoped collaborator controls define who—or what—can participate in development and what actions they can perform.
Full audit trails provide records to assist with oversight, including application logs, platform logs and MCP tool-call logs. From this data, developers can track precisely what actions the AI agent took, and when. Every change after launch is versioned, attributable, and reversible.
What’s Next
Catalyst is advancing towards a new era of agentic software development, where developers can collaborate with increasingly capable AI agents to execute sophisticated workflows across the software development lifecycle—all on a governed, full-stack cloud foundation. Forthcoming changes include multi-agent hosting, AI tool connectors, agentic SDLC, and more.
Disclaimer: All trademarks, product names, and company names cited herein are the property of their respective owners.
Pricing and Availability
Catalyst by Zoho offers a monthly free tier for developers to explore the platform, plus $250 in free credits for users who want to go deeper over a six-month period. Catalyst is available for immediate use.
Catalyst continues to offer a straightforward pay-as-you-go pricing model, with every feature bearing a per-unit cost rather than a license fee layered on top of usage. Developers get full visibility into usage from the Catalyst console and can set budget alerts and ceilings to prevent unexpected bills. A structured subscription option is also available for teams that prefer predictable costs.
Catalyst remains completely free for students, no subscription or credit card required to deploy non-commercial applications.
Zoho’s Privacy Pledge
Zoho respects user privacy and does not run on an ad-revenue model in any part of its business, including its free products. The company owns and operates its own data centers, giving it full oversight of customer data privacy and security. More than 150 million users worldwide, across more than 1 million paying organizations, rely on Zoho to run their businesses, including Zoho itself. For more information, visit zoho.com/privacy-commitment.html.
Leave a comment »