The Insider Threat Has Evolved. Most Corporate Security Functions Have Not.

The threat from within is no longer a story about a disgruntled employee and a USB stick. The actors have changed, the methods have changed, and the window for detection has narrowed. Understanding what a modern insider threat programme looks like is no longer optional for any organisation with something worth protecting.

Ask a chief security officer to describe their insider threat programme and the answer, more often than not, will involve some combination of background screening, DLP software, and periodic access reviews. It is a framework built for a specific era: one in which the primary risk was a financially pressured employee copying client data, or a disgruntled leaver walking out with intellectual property.

That framework is not wrong. It simply no longer covers the full picture. The actors, motivations, and tools have shifted considerably, and the gap between threat reality and organisational response has widened. What has changed is not the existence of insider risk. It is the sophistication, the patience, and in some cases, the institutional backing behind it.

Three Shifts that have Changed the Landscape

1. Ideologically motivated actors
Employees and contractors who hold political, environmental, or cause-driven grievances present a materially different risk profile from those motivated by financial gain. Their behaviour is harder to map in advance. They are less likely to exhibit the classic pre-incident indicators — financial stress, performance management issues, interpersonal conflict — and more likely to operate with deliberate calm over an extended period.

The 2023 case of Jack Teixeira, the US Air National Guard member who leaked classified intelligence documents to an online gaming community, is instructive. There was no financial motive. No evidence of coercion. The driver was ideological alignment and a desire for peer validation. By the time the leak was identified, thousands of documents had already circulated. His 2024 sentencing brought the case to a close, but the structural question it raised has not gone away: how do you profile a threat actor who looks, on paper, entirely normal?

2. State-sponsored placement
Intelligence services in a number of countries have demonstrated a sustained and documented interest in placing individuals within target organisations. The sectors most consistently in scope are critical national infrastructure, defence supply chains, advanced technology, and financial services.

One of the most operationally significant examples is the North Korean IT worker infiltration scheme, which the FBI, UK NCSC, and multiple allied agencies have issued repeated warnings about since 2022. North Korean nationals, using stolen or fabricated identities and AI-assisted interview techniques, have successfully obtained remote employment at technology companies across the US, UK, and Europe. Their objective is not disruption. It is persistent, low-profile access to codebases, financial systems, and internal communications. Several prosecutions followed in 2024, with further cases identified into 2025. The NPSA’s updated personnel security guidance, published in 2024, addresses this threat vector directly.

The target is rarely the organisation itself. It is the access the organisation provides.

3. AI-assisted exfiltration
This is the shift that legacy data loss prevention tools are least equipped to handle. Traditional DLP systems are calibrated to recognise patterns: file types, volume thresholds, known destination addresses. Newer exfiltration methods work around that logic entirely.

In early 2024, Microsoft disclosed that Midnight Blizzard — a Russian state-sponsored group — had used large language models to assist in analysing and processing exfiltrated data at scale, accelerating what would previously have been a slow and resource-intensive exploitation phase. The model was not the exfiltration tool. It was the analytical layer that made the exfiltrated data immediately actionable.

At the corporate level, the Samsung incident of 2023 — in which engineers inadvertently uploaded proprietary source code to a commercial AI platform — illustrated a related problem: that employees will use the tools available to them, and that those tools do not always sit within the security perimeter. The intent was not malicious. The exposure was real.

Detecting AI-assisted exfiltration requires a fundamentally different approach. Pattern recognition alone is insufficient. Behavioural context, access sequencing, and human analytical judgement all become more important, not less.

Where Legacy Programmes Fall Short

The weaknesses in most corporate insider threat functions tend to concentrate in four areas. It is worth being specific about each.

Screening treated as a one-time event
Background checks at the point of hire capture a moment in time. They say nothing about what has changed since. A person’s financial circumstances, personal affiliations, and exposure to third-party influence all evolve. Continuous personnel security — with defined re-screening intervals tied to role criticality and access level — is standard in high-security government environments. In the corporate sector, it remains the exception.

Access that accumulates rather than expires
The principle of least-privilege access is broadly understood and inconsistently applied. In practice, permissions accumulate. Individuals move roles, take on new responsibilities, or inherit access from predecessors. Without active governance, the result is a sprawling access landscape that nobody has mapped and that creates significant unmonitored exposure. Most organisations would be surprised by what a thorough access audit reveals.

Detection tools without investigative depth
DLP systems identify anomalies against known patterns. An actor who takes the time to understand what the system is looking for — and the North Korean IT worker cases suggest some do — can operate below the detection threshold indefinitely. Technology surfaces indicators. It cannot investigate them. Behavioural analytics and trained human oversight remain essential components of any credible function.

No clear investigative pathway
When a concern is flagged, most companies route it through HR or legal channels designed for employment matters, not intelligence investigations. The distinction matters. Evidence handling, interview strategy, and legal authority in an insider investigation are materially different from a disciplinary process. Using one framework for the other produces poor outcomes in both directions: either the investigation is compromised, or an innocent employee is handled badly.

What a Modern Programme Looks Like

A proportionate, intelligence-led insider threat function operates across four interconnected workstreams. None of them work in isolation.

Continuous personnel security. Vetting is a programme, not a process. This means defined re-screening intervals based on role criticality, a structured framework for reporting and assessing changes in personal circumstances, and escalation pathways that sit outside normal line management. For companies in sensitive sectors, the NPSA’s updated personnel security framework is the appropriate benchmark – it was revised specifically to account for the state-sponsored placement threat.

Behavioural analytics with human oversight. Automated monitoring of access patterns, data movement, and communication metadata can surface anomalies. It cannot contextualise them. A significant proportion of insider threat investigations begin with a human observation – a colleague, a manager, a security officer noticing something that does not fit. Technology and human judgement are complementary. Neither replaces the other.

Access governance as a live discipline. Access reviews need to be event-driven as well as periodic. Role changes, project completions, contractor offboarding: all are access events requiring an active response. Mapping who holds what access, and testing whether that access remains genuinely necessary, is one of the highest-return investments available in insider risk reduction. It is also, in most organisations, overdue.

A defined investigative pathway. When a concern is raised, there should be a legally sound route from initial referral through to investigation and, where warranted, action. This requires trained investigators, an evidence handling protocol that will withstand external scrutiny, and senior leadership sponsorship. The function needs authority to operate. Without it, referrals either stall or escalate inappropriately.

The Culture Question

Programmes built exclusively on monitoring tend to generate a surveillance atmosphere that erodes the trust most organisations are simultaneously trying to build. This tension is real, and it is worth naming honestly.

The most effective insider threat functions operate with a degree of transparency: employees understand what is monitored, why it exists, and under what circumstances action will be taken. When the purpose is clearly about protecting the organisation from genuine bad actors — rather than managing performance or policing individual behaviour — staff are considerably more likely to engage constructively. That includes reporting concerns about colleagues.

Where to Start?

For most companies, the practical question is not whether to build a comprehensive insider threat function from scratch. It is where the highest-value interventions are. Three areas consistently offer the most immediate return.

  • Conduct an honest audit of your access landscape. Understand who holds what permissions, whether they remain necessary, and where your highest-value data sits relative to the individuals who can reach it.
  • Review your personnel security framework against current NPSA guidance. Assess whether continuous screening is proportionate to your risk profile, sector, and the nature of your third-party relationships.
  • Establish a clear referral pathway for insider concerns that sits outside standard HR processes and is supported by appropriate investigative capability, whether built internally or through a specialist partner.

None of this is a short-term project. The organisations that handle insider risk most effectively treat it as an ongoing discipline rather than a compliance exercise. The question worth asking is whether the programme in place today reflects the threat environment as it actually exists in 2026 — or the one that was in view when the framework was first built.

Informed. Proportionate. Prepared.
Priavo Security provides bespoke intelligence-led security programmes for corporations, private clients, and high-risk environments worldwide. To discuss your organisation’s insider risk exposure, contact our advisory team at enquiries@priavosecurity.com

Sign up to our security newsletter

* indicates required
   
By entering your details into our website, you consent to our processing of your personal data in accordance with our Privacy Notice, including for HR & marketing purposes.