An insider threat is a risk to your organisation that comes from someone who already has legitimate access to your systems or data: an employee, a contractor, a supplier, or anyone else on the inside. NIST’s official glossary defines it as the threat that an insider will use their authorised access, wittingly or unwittingly, to cause harm. That “wittingly or unwittingly” distinction matters more than most businesses realise, because it means the person who costs you the most might never intend to do you any damage at all.

Table of Contents
What counts as an insider, exactly?
An insider is anyone with legitimate access to your organisation’s assets who could exploit that position, whether they mean to or not. That is a wider group than most people picture. NCSC’s guidance on reducing data exfiltration by malicious insiders names employees, contractors, partners, suppliers, privileged IT staff, part-time workers with more than one employer, and even senior staff and non-executive directors as people who fall within scope. Anyone with a badge, a login, or a set of keys is, technically, an insider.
What are the different types of insider threat?
Sources tend to group insider threats into three broad categories. This split is a widely used industry convention rather than a formal government classification, but it’s a useful way to think about the different risks involved:
| Type | What it looks like |
|---|---|
| Malicious insider | Deliberately misuses access for personal gain, revenge, ideology, or to help an outside party |
| Negligent insider | Causes harm through carelessness: a misdirected email, a lost laptop, a policy shortcut taken to get the job done faster |
| Compromised insider | An outsider who has obtained a legitimate insider’s credentials and is now operating with their level of access |
NCSC’s own guidance focuses mainly on the malicious case, and lists the motivations it sees most often: personal financial gain, revenge, ideological or political allegiance, ego or a sense of ownership over work they created, data hoarding, and coercion through blackmail or extortion. But the same guidance is careful to flag negligent behaviour too, pointing out that staff who build insecure workarounds around clunky security controls create a real, if unintentional, version of the same exposure.
Why insider threat is different from an external attack
A pen tester or an external attacker usually has to get through your perimeter first: a firewall, an email filter, a login screen. An insider skips that step entirely. They already have a badge, a password, and in many cases a genuine business reason to be looking at the data they end up misusing. That is precisely why MITRE ATT&CK lists Valid Accounts as a distinct technique in its own right: an attacker using real, working credentials looks like normal activity right up until it doesn’t.
The same technique note flags that former employees’ accounts, left active after they leave, are a common way for both outsiders and disgruntled ex-staff to keep access nobody intended them to still have. It’s also why testing scoped from inside your network, as covered in our guide on internal vs external penetration testing, catches a different set of risks than a test run purely from the outside.
How do you spot a potential insider threat?
NCSC’s guidance frames the useful warning signs less as a personality checklist and more as a set of channels worth watching: unusual use of personal or webmail accounts, external storage devices such as USB drives, encrypted messaging apps, screen-sharing during video calls, and behaviours aimed at covering tracks, like partial copy-paste instead of full file transfers, screenshotting instead of downloading, or renaming files to disguise their contents. None of these alone proves anything. Together, and especially around access to your most sensitive systems, they are worth a closer look.
How do you reduce insider threat risk?
NCSC’s guidance structures the response around three activities, and each does a different job:
- Prevent. Apply least-privilege access control so people only reach what their role requires. Restrict removable media and personal storage where you can. Build policies with staff input so they don’t invite workarounds.
- Monitor. Log and review access in something close to real time, with extra scrutiny on privileged accounts and your most critical systems.
- Audit. Keep tamper-proof activity logs, so you can reconstruct what happened if something does go wrong.
NCSC’s wider 10 Steps to Cyber Security guidance adds a practical detail worth acting on directly: a proper joiners, movers and leavers process, so that access is granted when someone starts, adjusted when they change role, and revoked the moment they leave. That single control closes off one of the most common ways former staff retain access they should never have kept.
Where personnel security and vetting fit in
Technical controls only cover part of the picture. NCSC’s cloud security principles point to BS 7858:2019 as a recognised standard for pre-employment screening, covering identity checks, right-to-work verification, and unspent criminal convictions. That kind of vetting, paired with role-appropriate ongoing training rather than a single annual session, is what NCSC’s guidance on engagement and training recommends: security that people are equipped to follow, not a policy they resent and route around.
Where penetration testing fits in
NCSC’s own guidance on penetration testing describes it as gaining assurance in a system’s security by attempting to breach it the way an adversary might. Some of the scenarios it names are directly relevant here: a lost laptop, an unauthorised device connected to the internal network, a compromised host already sitting inside your perimeter. These scenarios test the same assumption an insider threat represents: what can someone already inside your defences reach? NCSC also runs a dedicated tabletop exercise through Exercise in a Box on responding to an insider threat resulting in a data breach. Run it alongside any technical testing, not instead of it.
If you want to know what someone with legitimate access, or someone who has taken it over, could reach inside your organisation, that is exactly the kind of question a scoped penetration test is built to answer. Get in touch if you would like to talk through where your own exposure is likely to sit.
Frequently asked questions
Is an insider threat always someone acting maliciously?
No. NIST’s own definition explicitly covers harm done “wittingly or unwittingly.” A well-meaning employee who emails a sensitive file to their personal account to keep working over the weekend is just as much an insider threat as someone deliberately stealing data, even though the intent is completely different.
Can a contractor or supplier be an insider threat?
Yes. NCSC’s guidance explicitly includes contractors, partners and suppliers alongside employees, since anyone with legitimate access to your systems or premises falls within the same risk category, regardless of whose payroll they’re on.
How is this different from a compromised account used by an external attacker?
The access looks the same from the outside, which is exactly the problem. MITRE ATT&CK groups both cases under the same technique, Valid Accounts, because an attacker using real credentials and an insider misusing their own can be very difficult to tell apart from activity logs alone.
What’s the single most effective control against insider threat?
There isn’t one silver bullet. But a properly enforced joiners, movers and leavers process, so access is added, changed and removed as people’s roles change, closes off one of the most consistently exploited gaps.
Does penetration testing cover insider threat specifically?
A scoped test can be designed around exactly this scenario, testing what a legitimate but low-privileged account, a lost device, or a compromised internal host could reach. Agree that scope explicitly with whoever is running the test, since a generic external test won’t answer this question.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.