Back to Glossary

Threat source

Insider Threat

Risk arising from people or entities with legitimate access who may compromise security intentionally or unintentionally.

Related domain: CybersecurityConcept ID: concept-insider-threat

Definition

An Insider Threat is a Threat arising from the actions of people or entities with legitimate access to organisational Assets who may intentionally or unintentionally compromise security.

Human Explanation

The source may be an employee, contractor, partner or another authorised party whose access or knowledge enables an action to affect systems, information or operations.

Why it Matters

Legitimate access and organisational knowledge can allow an insider action to bypass controls intended primarily for external Threats and can increase its potential impact.

Conceptual Boundary

Insider Threat does not mean only deliberate malicious activity. It also includes error, negligence, compromised accounts and unintentional violations involving legitimate access.

Practical Perspective

Effective protection combines proportionate Access Control, Least Privilege, monitoring, usable processes and a Security Culture that enables early reporting without treating every insider as an attacker.

Related Concepts