Growing fears surrounding internal breaches are prompting a shift in corporate security strategies. 🔗The National Cyber Security Centre (NCSC) has long warned of the dangers of internal actors, and the release of the highly anticipated 🔗Cybersecurity and Infrastructure Security Agency (CISA) Insider Threat Mitigation Guide (September 2026) reinforces this critical focus.
Designed for critical infrastructure owners, operators, and commercial organisations, this publication redefines how businesses need to safeguard against risks originating from within. Below is our executive breakdown of the key advice, strategic updates, and practical takeaways to help your organisation navigate this evolving threat landscape.
1. The Evolving Threat Landscape and Financial Realities
Insider threats represent a complex and evolving challenge that no modern enterprise can afford to ignore. Trusted insiders possess authorised access and institutional knowledge that can cause significant damage if misused, whether intentionally or inadvertently. These insiders range from full-time employees to contractors, vendors, and trusted partners.
The data highlights a severe and growing financial and operational burden:
The average annualised cost of insider incidents (2024/2026) is $17.4 million. |
It takes an average of 81 days to contain an insider threat incident. |
57% of medium to large firms experience 21 or more incidents per year. |
The financial implications extend far beyond immediate incident response. Credential theft costs organisations an average of $4.8 million annualised. Insider negligence accounts for $8.8 million annually. What’s more, workplace violence carries an estimated $130 billion annual impact in the United States, alongside a profound human toll, with over 25,000 nonfatal workplace violence incidents annually and 1 in 7 workers feeling unsafe at work.
2. Key Categorisation of Threat Vectors
CISA emphasises that insider threats span both physical and digital domains and fall into distinct categories:
Unintentional Threats (Accidental vs. Negligent) |
This category accounts for the vast majority of insider disruptions. Accidental acts stem from simple mistakes, such as mistyping an email recipient or clicking a phishing link. Negligent acts stem from ignoring established policies, such as piggybacking through secure doors or bypassing patch updates. |
Intentional/Malicious Threats |
These are motivated by grievances, financial strain, ideological goals, or external recruitment. Manifestations include intellectual property (IP) theft, financial fraud, sabotage, government/economic espionage, and targeted workplace violence. |
Collusive & Third-Party Threats |
This is a growing area of concern where cybercriminals recruit insiders to enable fraud or access networks. Third-party risks involve contractors, suppliers, and external vendors with elevated access privileges. |
3. Artificial Intelligence Considerations
A major addition to the 2026 Guide is CISA’s explicit focus on Artificial Intelligence and Adversarial AI (AAI). As a firm championing best-in-class AI tools, like CrowdStrike Falcon Guardian (🔗see more on CrowdStrike Falcon Guardian here), Mondas aims to raise awareness of the dual-edged nature of these technologies.
Data Poisoning & Model Tampering |
Insiders with privileged access can corrupt AI training datasets or alter operational parameters. This can lead to misclassifications or fraudulent transaction approvals. |
Unaccredited AI Use |
Employees inadvertently inputting proprietary data into unapproved or commercial AI tools creates unauthorised exposure risks. |
AI-Enhanced Manipulation |
Threat actors are using deepfakes (audio, video, images) and hyper-personalised AI phishing to manipulate internal staff into breaching controls. |
4. The 6-Stage Progression Toward a Malicious Incident
The 2026 Guide highlights that intentional insider acts are rarely spontaneous. They follow a predictable, observable 6-stage progression path:
| 1. Grievance & Ideation: Distress, resentment, or personal/professional triggers translate into a desire for revenge or financial gain. |
| 2. Preparation: Conceptualising plans, gathering tools, obtaining unauthorised privileges, or acquiring weapons/malware. |
| 3. Exploration: Reaching a tipping point, probing network/facility weaknesses, or seeking co-conspirators. |
| 4. Experimentation: Testing boundaries, conducting reconnaissance, or attempting unauthorised system access. |
| 5. Execution: Exploiting access to execute data exfiltration, sabotage, fraud, or physical harm. |
| 6. Escape: Covering tracks, evading detection, publicising stolen IP, or exfiltrating data. |
5. Building and Managing a Mitigation Programme
CISA details a structured operational methodology across four key mission areas: Plan, Organise & Equip, Train & Execute, and Evaluate & Improve.
Shift to a Protective & Supportive Culture. The guide strongly advises against purely punitive or enforcement-oriented models. Effective programmes focus on prevention, empathy, and positive incentives. Zero-tolerance policies often backfire by suppressing reporting due to fear of severe retribution or causing peers to lose their jobs. Fostering a supportive culture encourages early reporting when employees observe distress or anomalous behaviour.
Multidisciplinary Threat Management Team (TMT). No single department can manage insider risk alone. Organisations must establish a multidisciplinary TMT led by a designated Senior Official, such as a CSO or CISO. Core stakeholders should include HR, Legal Counsel, IT/InfoSec, Physical Security, Privacy Officers, and Behavioural Health Professionals.
Case Study Insight
In a highlighted case involving a petroleum plant automation technician exhibiting severe workplace misconduct and sabotage attempts, an abrupt termination carried high risk of violent reprisal. By engaging an external behavioural health expert, placing the individual on paid leave with Employee Assistance Program (EAP) therapy, and maintaining continuous third-party monitoring, the company safely neutralised the threat without incident.
Hybrid & Remote Work Adaptations. To mitigate remote work risks, organisations should enforce encrypted VPNs and strict data storage standards. Periodic endpoint security audits and regular managerial check-ins are also required to counter social isolation and maintain early risk detection capabilities.
Handling Involuntary Separations Offboarding represents a period of acute insider threat risk. Key recommendations include:
- Ensuring at least two non-immediate group representatives conduct termination meetings in private, safe areas with quick exit access.
- Synchronising with IT/Security to revoke logical and physical access simultaneously during the meeting.
- Preserving employee dignity by arranging secure packing and mailing of personal belongings rather than public escorting.
Executive Key Takeaways & Recommendations
To align with CISA’s updated guidance, Mondas recommends the following foundational steps:
Know Your High-Value Assets |
Maintain a dynamic inventory of critical physical and digital assets, mapped to access permissions. |
Combine Human Vigilance & Technological Tools |
Deploy User Activity Monitoring (UAM), Data Loss Prevention (DLP), and Privileged Access Management (PAM) alongside peer awareness training. |
Incorporate AI Security Controls |
Establish clear policies regarding approved AI usage, update user agreements, and protect training data from tampering. |
Build Law Enforcement Partnerships |
Establish liaison relationships with local police and threat assessment units prior to incidents occurring. |
Document & Measure |
Conduct tabletop exercises and routine internal audits to ensure compliance with privacy laws and continuous programme improvement. |
If you’re struggling with the complex insider threat issues outlined in this article, or if you need assistance implementing the latest CISA recommendations with best-in-class tools, Mondas specialises in this topic. Contact us now to get in touch with our expert team.
Article brought to you by Lance Nevill, Cyber Security Director, Mondas 🔗Connect with Lance on LinkedIn
Article First Published: 18 September 2026


