Research by the Ponemon Institute found that insider incidents involving credential theft cost organisations an average of $842,462 each, while those caused by negligence and malicious insiders cost an average of $747,107 and $742,125 respectively.
These costs can accumulate through investigations, incident response, system recovery, business interruption, lost productivity, legal action, regulatory penalties, and reputational damage.
In contrast to the threat posed by external attackers, insider threat involves actors who already possess some degree of legitimate access to the victim’s physical premises or computer networks. They may know where valuable information is stored, which critical systems to target, and how to bypass security controls.
In some cases, the individual does not even need to act maliciously: a simple mistake or stolen set of credentials can produce similar consequences. The first step in reducing insider risk is therefore understanding what an insider threat is, the different forms it can take, and how organisations can reduce their exposure.
What is an Insider?
An insider is someone who has or previously had legitimate access, knowledge, or privileges within an organisation. This includes current and former employees, contractors, suppliers, and other trusted third parties.
The threat posed by insiders to an organisation typically falls under one of the following categories:
Malicious intent
Negligence
Credential theft
An event in which an insider has caused harm to an organisation (regardless of intent) is known as an insider incident.
Malicious Intent
Malicious insiders are individuals who deliberately abuse their access privileges to harm an organisation. This may include stealing sensitive information, conducting corporate or state espionage, sabotaging systems or equipment, deleting or manipulating data, selling information or credentials, or helping an external actor gain access to the organisations networks or physical property.
The threat posed by malicious insiders does not end when they leave the organisation - former employees may retain valuable technical knowledge, understand security vulnerabilities, and understand how critical systems operate. If accounts, key cards, credentials, and devices are not promptly secured when that individual leaves the organisation, they may also retain access into the organisation’s systems and physical property.
EnerVest Attack: In June 2012, EnerVest network engineer Ricky Joe Mitchell learned that he was going to be dismissed from the company. Before his employment ended, he reset the company’s servers, disabled its backup process, disconnected network equipment, and turned off its cooling system. Operations were disrupted for approximately 30 days, some data was permanently lost, and the US Department of Justice estimated the company’s losses at more than $1 million.
The incident could have been prevented by limiting knowledge of the planned dismissal and removing Mitchell’s physical and remote access before, or during, the termination meeting. Independent checks of EnerVest’s backup arrangements could also have exposed that one employee could disable data replication and helped ensure critical information remained recoverable. Read more.
Negligence
Negligent insiders are employees or other trusted individuals whose mistakes, carelessness, or failure to follow security procedures unintentionally exposes the organisation to harm.
Negligent behaviour may include sending information to the wrong recipient(s), misconfiguring databases or cloud storage, losing devices, using weak or reused passwords, or bypassing security controls for the sake of convenience. Employees can also negligently facilitate credential theft by falling victim to phishing attacks, failing to handle sensitive information properly, and failing to regularly update and secure their devices.
Negligence is by far the most common cause of insider incidents. Research by the Ponemon Institute recorded an average of 13.8 insider incidents caused by negligence per organisation, compared to 6.3 resulting from malicious intent and 5.3 from credential theft.
Insider-risk management should therefore focus just as heavily on implementing clear operating procedures, regular training, and a workplace culture in which employees are encouraged to report mistakes promptly as it does on technical safeguards.
Boeing Data Breach: In November 2016, a Boeing employee accidentally emailed a spreadsheet containing the personal information of approximately 36,000 colleagues to his wife while seeking help with formatting. Hidden columns contained names, addresses, birth details, employee IDs, and Social Security numbers.

Boeing’s headquarters in Crystal City, Virginia.
Reproduced with permission of the photographer under CC 2.0
Boeing was forced to investigate the breach, conduct forensic examinations, remove copies of the file, notify affected employees and regulators, and provide two years of identity-protection services, incurring significant costs despite no actual harm being done.
Controls blocking sensitive data from external emails, clearer handling procedures, staff training, and removing personal information from working documents could have prevented it from occurring. Read more.
Credential Theft
Credential theft occurs when an external attacker obtains the legitimate credentials of an employee or other trusted individual, giving them access to either an organisation’s systems or physical property - effectively becoming a malicious insider.
Credentials can be obtained through phishing, credential-stealing malware, password reuse, social engineering, or the compromise of a personal device. In some cases, they can also be obtained through coercion such as blackmail or threats of violence.
Credential theft can take place even when the victim has done nothing either deliberately or accidentally wrong, and they are often unaware their credentials have been stolen.
Organisations can reduce the risk of credential theft by implementing phishing-resistant multi-factor authentication (MFA), password managers, and controls that detect unusual behaviour. Similar vigilance should apply on company premises: employees should be encouraged to challenge or promptly report unfamiliar individuals, suspicious conduct and attempts to enter restricted areas, even when the person appears to possess valid identification or access credentials.
These measures should form part of a zero-trust approach in which every request is assessed according to factors such as the user, device, location, and behaviour, regardless of whether valid credentials have been supplied.
North Korean Remote Workers: North Korean IT workers used stolen American identities to secure remote jobs at hundreds of companies, with US facilitators hosting company laptops so overseas connections appeared domestic. One network compromised 68 identities, defrauded 311 businesses, and generated more than $17 million. Other operatives stole credentials, source code, and export-controlled defence information.
The scheme could have been disrupted through in-person identity checks, comparisons between interviewees and workers, and verification that company equipment reached the employee’s registered address. Employers should also restrict remote-access software, monitor unusual login locations, limit access to role requirements, and repeat identity checks when accounts, devices, or permissions change. Read more.

A laptop farm in Litchfield Park, Arizona, US, photographed by the FBI in 2023
Summary
Insider threat is not limited to employees deliberately attacking their employer. It can result from malicious activity, negligence, and credential theft (or any combination of the three), meaning the person responsible for creating the vulnerability may be hostile, careless, or entirely unaware that their access is being abused.
The EnerVest and Boeing cases and North Korean remote-worker scheme show that despite the different these incidents can be, but they all demonstrate how trusted access creates risk when it is not adequately controlled.
Organisations cannot eliminate that risk entirely, but they can substantially reduce it through compartmentalisation, least-privilege access, strong authentication, employee training, monitoring, effective recruitment procedures, and immediate removal of access when employees leave.






