Updated: October 2026
The person with the easiest path to your data already has a login. Firewalls, EDR and email filters are built to stop strangers, and they wave an employee straight through. Insider threats are the risks that come from people you already trust, and this guide covers the types, the warning signs worth watching and the controls a small IT team can run without turning into the workplace police.
TL;DR: An insider threat is anyone with authorized access who harms the organization, on purpose or by accident. Careless mistakes cause more incidents than malice. Departing employees and shared accounts are where small companies get hurt most. The controls that work are boring: least privilege, fast offboarding, access reviews, logging you can search, and a plan agreed with HR and legal before anything happens.
What Is an Insider Threat?
CISA defines an insider as "any person who has or had authorized access to or knowledge of an organization's resources." That covers employees, contractors, vendors, interns and people who left last month but still have a working password.
An insider threat, in CISA's words, is "the potential for an insider to use their authorized access or understanding of an organization to harm that organization." The key word is potential. The threat is the access itself, sitting there for anyone who makes a mistake, gets phished or holds a grudge.
That makes it different from an outside attack. An attacker has to break in. An insider starts inside, with valid credentials, on a device you manage, doing things that look like normal work. Nothing trips an alarm because nothing looks broken.
Insider Threat vs Insider Risk
You'll see both terms, often in the same vendor brochure. They describe the same problem from two ends.
Insider risk is the exposure: how much sensitive data sits behind how many accounts, how long access lingers after people leave, how many shared logins exist. It's always there, and you manage it like any other risk, by shrinking it.
An insider threat is the moment that exposure meets a person who misuses it, by accident or on purpose. You can't predict which person that will be. You can make sure the blast radius is small when it happens, which is where the controls later in this guide come in.
Types of Insider Threats
CISA's insider threat definitions split insiders by intent. For IT work, it helps to add two practical categories CISA's list folds into others: the compromised account and the departing employee.
| Type | What it looks like | Intent |
|---|---|---|
| Negligent | Sends the payroll file to the wrong "Sarah", leaves a share open to everyone | None, carelessness |
| Accidental | Clicks a phishing link, deletes the wrong folder | None, a mistake |
| Malicious | Copies client lists, sabotages a system, sells access | Personal gain or a grudge |
| Collusive | Works with an outside group, often for money | Deliberate, with a partner |
| Compromised account | An attacker logs in as a real employee | The employee has none |
| Third party | A contractor or vendor with standing access | Any of the above |
| Departing employee | Takes files "they worked on" on the way out | Often feels justified |
Carelessness is the big one. In the Ponemon Institute and DTEX 2026 Cost of Insider Risks study of 354 organizations, 53 percent of insider incidents were due to employee negligence. Malice makes the headlines, but mistakes make the tickets.
The compromised account deserves its own row because it behaves like an insider. Once an attacker has a valid session, every control that trusts the user trusts the attacker too. That's why MFA and session controls belong in an insider threat plan, not only in a phishing plan.
Red Hat's Security Detail episode walks through the same split between careless and malicious insiders, with examples.
Why Insider Threats Are Hard to Spot
An insider uses the access they were given. A sales rep exporting the CRM looks exactly like a sales rep doing their job. A developer cloning every repo looks like a developer. The difference between normal and harmful is often context: the timing, the volume, and the fact that they resigned yesterday.
Third parties widen the gap. Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30%. A vendor's technician with a standing VPN account is an insider in every way that matters, except you didn't hire them and you can't see their HR file.
Small teams have one more problem: shared accounts. When five people log in as "admin" or "reception", no log can tell you who did what. Every insider investigation starts with the question "which person was this?", and a shared account has no answer.
Warning Signs Worth Watching
Warning signs come in two kinds. Technical signals show up in logs. Behavioral signals show up in people. Neither proves anything on its own. They're reasons to look closer before anyone draws a conclusion.
Technical signals worth alerting on:
- Large downloads or syncs from SharePoint, OneDrive or a file server, especially in the weeks after a resignation.
- New forwarding rules that send mail to a personal address.
- Access to systems or folders outside someone's role, or a sudden spike in failed access attempts.
- USB mass storage use on machines where it's normally blocked or rare.
- Logins at odd hours or from new countries, which often point to a compromised account rather than a person.
- New admin accounts, disabled logging or deleted audit trails.
Behavioral signals are the ones HR and managers see first: open conflict with a manager, a missed promotion, money trouble mentioned out loud, a notice period, or someone suddenly asking about systems they never needed. IT's part is making sure the people who notice them know who to call.
Mind the legal line. Monitoring employees has rules. New York, for example, requires employers to give written notice at hiring, get an acknowledgement and post a notice before monitoring phone, email or internet use. Other states and the GDPR add their own limits. Agree what you log, who can look at it and why, with HR and legal, before you need it. Watching everyone "just in case" creates more legal risk than it removes.
The Departing Employee Problem
The riskiest day for your data is often an employee's last one. People take client lists, templates and code because they feel it's their work, and some of it ends up at a competitor.
This r/sysadmin post is the version small companies know best. A fired employee downloaded every file from SharePoint before anyone disabled the account.
The replies agree the fix is timing. For an involuntary exit, IT disables the account and revokes sessions while the person is in the meeting with HR, not after. For a resignation, the notice period is when to review what they can reach and pull anything they don't need for handover.
Order matters:
- Place a retention or litigation hold on the mailbox and files if there's any chance of a dispute.
- Disable sign-in and revoke active sessions and tokens.
- Reset or remove MFA methods, app passwords and registered devices.
- Remove forwarding rules, delegates and shared-mailbox access.
- Transfer file ownership, then remove access to shares, SaaS apps and the VPN.
- Collect the laptop and badge, and rotate any shared secrets the person knew.
The hold goes first for a reason. In Microsoft 365, a deleted user's mailbox data is kept for 30 days and then permanently removed. With a hold applied before the account is deleted, the mailbox becomes an inactive mailbox and stays searchable, per Microsoft's guidance on inactive mailboxes. Delete first and hold later, and the evidence may already be gone.
For the full list, our client offboarding checklist covers the same ground at the company level.
Controls That Work for a Small Team
You don't need a dedicated insider threat program to cut the risk down. You need a handful of controls, run on a schedule, owned by someone.
Least privilege. People get access to what their role needs and nothing more. Group access by role instead of granting it person by person, which is what role-based access control is for. When someone moves teams, their old access goes with the old role.
Access reviews. Once a quarter, managers confirm who can reach the finance share, the CRM export and the admin portals. Access creeps. Reviews are how it gets pulled back.
Separation of duties. The person who approves a vendor payment shouldn't also be able to change the vendor's bank details. The same idea applies to IT: the admin who can delete logs shouldn't be the only one who can read them.
Named admin accounts and privileged access. No shared admin logins. Admin rights live on separate accounts, used only when needed, ideally checked out through privileged access management so every use has a name and a timestamp.
Data controls. Sensitivity labels, blocked downloads for unmanaged devices and alerts on bulk exports stop a lot of quiet copying. Data loss prevention software adds content inspection when you need it.
Logging you can search. Keep sign-in logs, file access audit logs and admin activity long enough to answer "who did what" months later. Free tiers often keep only days, so check retention before you rely on it. OpenFrame can run a script across a client's devices to list local admin accounts and USB storage settings, then collect the output in one place.
MFA and session controls. They stop the compromised-account insider, the one that walks past every control built on trust.
A Worked Example: The Two-Week Notice
Here's how the pieces fit together in a 40-person company. The names and numbers are illustrative.
On Monday, an account manager hands in two weeks' notice. HR logs it in the HR system and messages IT the same morning, because the offboarding runbook says to. IT checks what the account can reach: the CRM with an export button, a shared "Clients" folder and a personal OneDrive syncing to a home laptop.
Nothing is accused and nothing is locked. IT removes the CRM export permission, since handover work doesn't need it. The manager confirms which files the handover needs. The alert on bulk downloads from the "Clients" folder is already running, so nobody has to watch anything by hand.
On Wednesday the alert fires: 1,900 files synced from the "Clients" folder in 11 minutes. IT doesn't message the employee. IT calls HR, exports the audit log, and places a hold on the mailbox and OneDrive. HR and legal decide the next step. It turns out to be a sync setting the employee never meant to turn on, and the files are removed with a signed confirmation.
On Friday afternoon, while the exit meeting runs, IT disables sign-in, revokes sessions, removes the phone from MFA and transfers file ownership. The laptop comes back. The account is deleted 30 days later, after the hold is confirmed.
Nothing in that week needed a special tool. It needed a runbook, one alert and an agreement with HR about who calls whom.
Handling a Suspected Insider
When a signal turns into a real suspicion, the first call is to HR and legal, not the employee. Insider cases touch employment law, privacy and sometimes criminal law. An IT team acting alone can ruin an investigation or create a lawsuit.
A small-team sequence looks like this. Preserve evidence quietly with holds and log exports. Limit access if the risk is live, with HR's agreement. Document every step with times and names. Don't confront, don't browse the person's mailbox out of curiosity, and don't tell colleagues. If data left the building, your incident response plan takes over, including any notification duties.
Speed still matters. The same Ponemon and DTEX study found the average time to contain an insider incident fell to 67 days in 2025, from 81 days in 2024. That's more than two months of exposure per incident, which is why a written plan beats improvising.
This r/cybersecurity thread asks what email controls to apply once someone is identified as an insider threat. The strongest reply is about order, not settings: hold first, before anyone touches the account.
An Insider Threat Checklist for Small Teams
Most of this fits in a spreadsheet and a calendar reminder. Use it as a starting point and assign an owner to every row.
| Control | Cadence | Owner |
|---|---|---|
| Role-based access groups for every shared resource | Set up once, fix as roles change | IT |
| Access review of finance, HR, CRM and admin portals | Quarterly | Managers + IT |
| No shared admin accounts; admin rights on separate accounts | Always | IT |
| MFA on every account, including service desk and vendors | Always | IT |
| Offboarding runbook with hold, disable, revoke order | Every exit | HR + IT |
| Alerts on bulk downloads, forwarding rules and new admins | Continuous | IT |
| Audit log retention checked against your needs | Yearly | IT |
| Vendor accounts reviewed and time-limited | Quarterly | IT + vendor owner |
| Monitoring policy agreed and communicated to staff | Yearly | HR + legal |
| Insider scenario in your incident response plan | Yearly | IT + HR + legal |
Awareness training belongs on the list too. Over half of insider incidents are negligence, and people who know what a misdirected email or an overshared folder costs make fewer of them.
The Short Version
Insider threats come from people with legitimate access, and carelessness causes more incidents than malice. Protect the moments that matter most, like resignations and terminations, with a fast offboarding order. Run least privilege, access reviews and searchable logs as routine. Agree the rules with HR and legal before you need them. If you're tightening access next, start with role-based access control, then look at how privileged accounts are handled.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
