Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Insider Threat Data Shows Identity Gaps, Not MaliceRisk Analysis and Quantification
4 min readFor CISOs

Insider Threat Data Shows Identity Gaps, Not Malice

Security leaders are noticing a shift in insider threat patterns: the issue isn't mainly malicious actors, but rather unchecked access rights and unnoticed behavioral anomalies. Data from practitioners reveals three critical findings that should reshape how your team approaches insider risk.

What the Data Shows

Organizations often measure insider threat readiness by whether they receive alerts for suspicious downloads or abnormal logins. That's the wrong metric. Andrew Costis, who leads adversarial research at AttackIQ, suggests a more revealing question: how much damage could a trusted account cause if abused? In many environments, the answer is "substantial," especially when permissions have accumulated over time or controls haven't been tested against real attacker behavior.

The gap between detection and prevention has widened. Teams know when something suspicious happens, but they don't know if their environment could withstand it.

Key Findings

Finding 1: Process failures create more risk than malicious intent

Ross Filipek, CISO at Corsica Technologies, describes the actual pattern: old accounts that nobody disabled, employees who moved departments but kept their original permissions, contractors who finished projects but retained remote access, and former employees whose SaaS accounts remained active for days after departure. These gaps persist because access management spans IT, HR, and departmental managers without unified oversight.

Smaller organizations face this acutely. Responsibilities get distributed, and access quietly accumulates across systems that don't communicate.

Finding 2: Behavioral anomalies matter more than authentication success

Kevin Kirkwood, CISO at Exabeam, encountered an insider threat case involving a foreign operative aligned with North Korean interests who passed through the hiring process as a seemingly legitimate employee. The access looked legitimate. Small behavioral anomalies, viewed together, told a different story.

The case illustrates a broader principle: authentication proves identity, not intent. Your controls need to understand whether behavior still makes sense after someone successfully logs in.

Finding 3: AI agents are entering your insider threat surface

Organizations now face a new category of insider: AI agents that hold credentials, interact with internal systems, and take actions without step-by-step human approval. None of that makes an agent malicious, but it makes blind trust dangerous. Your insider threat program must extend beyond human identities to any entity acting with employee-like authority.

Kevin Mata, Director of Cloud Operations and Automation at Swimlane, adds operational context: one anomalous login isn't enough to call something a threat. Neither is a large download or unexpected privilege change. The challenge appears when several signals cluster around the same identity and nobody has the full picture because identity data, endpoint activity, and cloud access live in separate systems.

What This Means for Your Team

Your insider threat program probably focuses on the wrong scenarios. If you're building detection rules for disgruntled employees stealing files, you're addressing a minority of actual incidents. The majority stem from access that should have been removed, permissions that should have been reviewed, and behavioral patterns that should have triggered correlation.

You also can't judge readiness by alert volume. The relevant question is whether a trusted account with legitimate access could reach privileged systems, escalate permissions, or move laterally toward sensitive data before your controls would detect and stop those actions. Most teams don't know the answer because they haven't tested it.

Finally, if your identity and access management program doesn't account for non-human identities with credentials and system access, you have a coverage gap. AI agents, service accounts, and automated processes represent trusted identities that can exhibit behavioral anomalies.

Action Items by Priority

Immediate (this quarter):

  • Map employee lifecycle touchpoints across IT, HR, and department managers. Document who removes access at each transition: role change, department transfer, contractor completion, and termination. Identify gaps where no single team owns the step.

  • Run a sample validation: select five recently departed employees and verify their access was removed from all systems within 24 hours. If you find active accounts, you've confirmed the process failure described above.

Near-term (next two quarters):

  • Build insider scenarios into your adversarial validation program. Test whether a trusted account with legitimate access could reach sensitive systems, escalate privileges, or exfiltrate data before detection. Continuous exposure management should include insider techniques, not just external threat patterns.

  • Implement quarterly access reviews that require managers to certify which permissions their team members actually need. Don't ask managers to review a list and approve it. Ask them to justify each elevated permission. The difference matters.

Ongoing:

  • Establish behavioral baselines for both human and non-human identities. Correlate identity data, endpoint activity, and cloud access in a single view so analysts can see clustered anomalies instead of isolated signals.

  • Define escalation paths that include HR and legal for insider investigations. Security isn't always the only team involved, and the best response isn't necessarily the fastest one. Build the coordination framework before you need it.

NIST Insider Threat Program

Promotional banner for the Pentest Readiness checklist download

You Might Also Like