Skip to content

Insider Threat Categories, Expressions & Contexts

An insider is any person who has or had authorised access to, or knowledge of, an organisation’s people, facilities, information, equipment, networks or systems. The categories and expressions below are adapted from CISA’s Defining Insider Threats and Insider Threat Mitigation Guide.

The categories describe differences in intent, awareness and the nature of the trusted relationship involved.

CategoryDescription
Negligent InsiderAn insider who exposes the organisation to risk by failing to follow known security responsibilities, policies or procedures through carelessness, poor judgement or convenience.
Accidental InsiderAn insider who unintentionally creates risk through error, misunderstanding, misdelivery, inadvertent disclosure, unsafe interaction or improper handling of information, systems or assets.
Intentional InsiderAn insider who deliberately misuses authorised access, organisational knowledge or a trusted position to cause harm, obtain personal benefit, act on a grievance or further another objective.
Collusive InsiderAn insider who collaborates with an external threat actor to conduct or enable unauthorised or harmful activity.
Third-Party InsiderA person engaged through a contractor, supplier, consultancy, managed service provider, partner or other external organisation whose authorised access to, or knowledge of, the organisation creates insider risk, whether the resulting activity is intentional or unintentional.

The expressions describe the form of harm and may arise across different insider categories and contexts.

ExpressionDescription
ViolenceThreatened or actual physical harm, intimidation, harassment, bullying or other behaviour that creates a workplace safety risk, including violence directed at the organisation in pursuit of a political or social objective.
EspionageCovert or unauthorised collection, acquisition or disclosure of sensitive, classified, strategic, commercial or proprietary information for advantage or on behalf of another party.
SabotageDeliberate action intended to damage, disrupt, degrade or interfere with facilities, systems, assets, processes or organisational capability, including through deliberate non-compliance with maintenance or operational procedures.
TheftUnauthorised taking, copying, transfer, removal or misuse of money, property, data, intellectual property or other organisational assets.
Cyber ActsIntentional or unintentional acts involving systems, accounts, networks, devices or data that cause or enable unauthorised access, operational disruption, alteration of information, malicious code execution or other cyber-related harm.

These contexts describe circumstances that can shape how insider risk develops and may apply across more than one category. Similar behaviour may arise under different conditions, and the surrounding context can influence how the organisation interprets and responds to it.

ContextDescription
Compromised InsiderAn insider whose identity, credentials, account, device or access has been compromised and is used by an external threat actor without the insider’s authorisation.
Coerced InsiderAn insider who is pressured, threatened, blackmailed, manipulated or otherwise compelled to undertake unsafe or unauthorised activity.
Former InsiderA former employee, contractor, consultant, supplier or partner representative, or other associate who retains organisational knowledge, relationships, influence or residual access after separation.
Opportunistic BehaviourDeliberate activity in which an insider takes advantage of weak controls, excessive access, unclear ownership, poor oversight or process gaps for convenience, personal benefit or unauthorised advantage.