From negligent clicks to rogue admins, insiders continue to fuel breaches – and IAM is fast becoming the best defence
Insider threats have always been a thorn in the side of security leaders, but in today’s hyperconnected workplace, they’re becoming harder to spot and even harder to stop. The numbers tell the story: according to Verizon’s 2025 Data Breach Investigations Report, almost a third of breaches involved insiders, whether through malice, negligence or human error.
That’s worth repeating: one in three data breaches are caused by the people you employ.
For a CISO, this means the challenge isn’t just about protecting against shadowy external attackers. You must also manage the risk lurking within your organisation’s own walls.
Understanding the insider threat spectrum
It’s tempting to view insider threats purely through the lens of malicious actors: the disgruntled employee downloading customer lists before resigning, or the rogue admin selling access on the dark web. But research shows that most insider incidents stemming from negligence and human error account for the majority of cases.
That doesn’t make them any less damaging. Many of the most disruptive incidents in recent years have stemmed from identity and access weaknesses; the same gaps insiders are best placed to exploit.
This is where Identity and Access Management (IAM) steps in.
IAM as the first line of defence
The insider threat problem and IAM are inseparable. If you can’t verify who has access to what and enforce it in real0time, you’re flying blind. Modern IAM frameworks, grounded in zero trust principles, provide a practical way forward.
That begins with least privilege access. Employees and contractors should only be able to reach the systems and data they genuinely need for their role, and nothing more. Well-implemented role-based and attribute-based access controls can dramatically limit the damage of a compromised or malicious account.
Authentication, too, needs to evolve. The days of logging in once and having free rein are long gone. Adaptive methods that factor in behaviour, context and risk ensure identities are continuously validated, particularly when a user attempts to access sensitive resources.
Privileged access management (PAM) is another critical piece of the puzzle. Administrator accounts remain one of the most attractive targets for both insiders and outsiders. Strong PAM controls, combined with session recording and just-in-time provisioning, make it much harder for the “keys to the kingdom” to be misused.
Watching what insiders do without breaking trust
Surveillance is a loaded word, and CISOs must tread carefully. Employees don’t want to feel like they’re constantly under suspicion, yet without visibility into behaviour, spotting insider threats is impossible. The solution lies in context-rich monitoring that focuses on anomalies rather than blanket oversight.
Security teams are increasingly using user and entity behaviour analytics (UEBA) to detect deviations from regular activity. An employee suddenly transferring gigabytes of data at 2am? That should raise an eyebrow. A contractor logging in from an unexpected location? Worth investigating.
The key is transparency. Communicating why monitoring exists helps maintain trust, and when paired with clear policies and HR support, this approach can catch red flags early without creating a culture of paranoia.
The human element
Technology alone won’t solve insider threats. Training, culture and process play just as critical a role. Employees need regular, engaging education on security best practices, not just box-ticking compliance modules. More importantly, they need to feel safe reporting mistakes without fear of punishment.
“Our research indicates that 60% of successful cyber attacks have human factors, but that does not mean humans are innately vulnerable,” said AJ Thompson, CCO at UK-based IT consultancy firm Northdoor. “It means our security paradigms need to shift. Good Identity and Access Management is not about restricting access, but designing systems that work with human psychology rather than against it.”
CISOs also need strong links with HR and legal teams to manage insider risk holistically. Exit processes, background checks and well-defined escalation paths for suspicious behaviour all reduce blind spots.
AI agents don’t fit traditional IAM models, they access sensitive data, call APIs, and act autonomously, creating new identity and security risks that legacy systems weren’t designed to manage. The Ultimate Guide to Identity for AI explains how to secure AI agents with authenticated delegation, scoped access, human oversight, and governance frameworks that scale as AI adoption grows.
Download the guide to build an identity strategy that protects your organization while enabling AI innovation.
Third parties: the forgotten insiders
It’s not just employees. Contractors, suppliers and partners often have privileged access to core systems. The Okta breach in 2023, which traced back to a third-party contractor’s laptop, remains a case study in how external insiders can create serious damage.
IAM provides the guardrails here too. Automating joiner-mover-leaver processes ensures that third-party access is provisioned quickly when needed – and just as quickly revoked when it’s not. Continuous attestation of access rights, especially in highly regulated industries, should be standard practice.
AI: the new wildcard
AI brings both new risks and new opportunities. Generative AI tools are already being misused by insiders to smuggle data out of corporate environments, while AI-driven phishing and impersonation attacks increase the likelihood of employees being duped into handing over credentials.
On the flip side, AI is supercharging detection. Machine learning models can sift through terabytes of log data to spot subtle insider anomalies that humans would miss. Early adopters are already embedding AI-driven UEBA into their SOC workflows, giving them a fighting chance of staying ahead.
“We’re starting to see a rise in hyper-personalized phishing attempts, as well as a growing threat of AI-powered social engineering attacks that can mimic human communication patterns with remarkable accuracy,” said Kiran Chinnagangannagari, Co-Founder of Securin.
“This isn’t just about better spam filters anymore – cybersecurity professionals must fundamentally rethink how we approach user education and authentication in a world where machines can convincingly impersonate trusted contacts.”
A layered defence
Ultimately, there is no silver bullet for insider threats. But by weaving monitoring, culture and collaboration together, organisations can significantly reduce the risk.
With a modern IAM strategy at the core, organisations can even shift the balance, turning what has long been an intractable problem into one that can be managed, measured and mitigated.
Related articles