By Cyber Defense Technologies June 16, 2026 4 min read
Security programs often focus on keeping outsiders out. Insider threats come from people who are already in: employees, contractors and partners with legitimate access. Several of the most damaging disclosures of classified information in U.S. history came from insiders, including widely reported recent cases involving military personnel who shared classified material online.
Insiders are not always malicious. Some are careless, some are manipulated by others, and some have their credentials stolen. But whatever the motive, they start with access an outside attacker would have to work hard to obtain.
Types of insider threats
- Malicious insiders intentionally steal, leak or sabotage, whether for money, ideology, grievance or coercion.
- Negligent insiders cause harm through mistakes: mishandling classified or controlled information, falling for phishing, or bypassing controls for convenience.
- Compromised insiders are people whose accounts or devices have been taken over by outside attackers.
- Recruited insiders are approached and cultivated by foreign intelligence services or criminals.
Requirements for cleared organizations
Cleared contractors participating in the National Industrial Security Program must establish and maintain an insider threat program, with a designated senior official, employee training, and procedures to gather, integrate and report relevant information, under 32 CFR Part 117 (the NISPOM rule). Government agencies have similar requirements under national insider threat policy, supported by the National Insider Threat Task Force.
Indicators
Insider threat indicators
Behavioral
What colleagues may notice
- Unexplained financial difficulty or sudden wealth
- Disgruntlement or conflict with the organization
- Unusual interest in information outside their role
- Unreported foreign contacts or travel
Technical
What monitoring may detect
- Access to data outside normal patterns
- Large downloads, printing or removable media use
- Attempts to bypass security controls
- Activity at unusual times or from unusual places
No single indicator means someone is a threat. Programs look for combinations and changes over time, and they must handle information fairly:
Behavioral indicators
- unexplained financial difficulty or sudden affluence
- significant disgruntlement or conflict with the organization
- attempts to access information outside a person's role or need-to-know
- unreported foreign contacts or travel
- violations of security rules or attempts to circumvent them
Technical indicators
- access to large volumes of data outside normal patterns
- unusual downloads, printing or use of removable media
- attempts to disable or bypass security controls
- activity at unusual times or from unusual locations
- use of unauthorized cloud storage or communication tools
Technical controls that support the program
- Least privilege and need-to-know: access limited to what each role requires, reviewed regularly.
- User activity monitoring: required on classified systems in many environments, with clear notice to users.
- Data loss prevention: detection of sensitive information leaving through email, web, printing or removable media.
- Removable media control: restrict and log use, especially on classified systems.
- Privileged user oversight: additional monitoring and separation of duties for administrators, who have the broadest access.
- Rapid access removal: coordinated processes to remove access when people leave or change roles.
The human side
Technology cannot replace a healthy security culture. Effective programs:
- train employees to recognize and report concerns, and to understand foreign intelligence approaches
- make reporting safe and confidential
- involve HR, security, legal and IT together
- treat people fairly and respect privacy and due process
- offer support, such as employee assistance programs, since many insider incidents begin with personal crises
Frequently asked questions
Doesn't monitoring employees damage trust? Monitoring should be transparent, lawful, proportionate and focused on protecting sensitive information. In cleared environments, users are notified that systems are monitored. Clear policies and fair handling build trust rather than undermining it.
Are administrators a special risk? Administrators have broad access and the ability to bypass controls, so programs apply additional oversight, such as separation of duties, logging of administrative actions and review by others.
What should employees do if they are approached by someone seeking information? Report it to their security officer. Cleared personnel have specific reporting obligations for suspicious contacts.
What to do this week
- Confirm your insider threat program's senior official, and that their contact details are known to employees.
- Review who holds privileged access to classified and CUI systems, and remove what is no longer needed.
- Check that departures trigger same-day account removal, and test it with a recent example.
- Verify that removable media is restricted and logged on sensitive systems.
- Remind staff how to report concerns and suspicious contacts, and that reporting is confidential.
How CDT can help
CDT helps cleared organizations protect classified and controlled information through classified network engineering, monitoring and detection through cyber hunt and managed security, and security control assessments of the technical controls that support insider threat programs.