Insider Threat Categories, Expressions & Contexts
An insider is any person who has or had authorised access to, or knowledge of, an organisation’s people, facilities, information, equipment, networks or systems. The categories and expressions below are adapted from CISA’s Defining Insider Threats and Insider Threat Mitigation Guide.
Insider Threat Categories
Section titled “Insider Threat Categories”The categories describe differences in intent, awareness and the nature of the trusted relationship involved.
| Category | Description |
|---|---|
| Negligent Insider | An insider who exposes the organisation to risk by failing to follow known security responsibilities, policies or procedures through carelessness, poor judgement or convenience. |
| Accidental Insider | An insider who unintentionally creates risk through error, misunderstanding, misdelivery, inadvertent disclosure, unsafe interaction or improper handling of information, systems or assets. |
| Intentional Insider | An insider who deliberately misuses authorised access, organisational knowledge or a trusted position to cause harm, obtain personal benefit, act on a grievance or further another objective. |
| Collusive Insider | An insider who collaborates with an external threat actor to conduct or enable unauthorised or harmful activity. |
| Third-Party Insider | A person engaged through a contractor, supplier, consultancy, managed service provider, partner or other external organisation whose authorised access to, or knowledge of, the organisation creates insider risk, whether the resulting activity is intentional or unintentional. |
Expressions of Insider Threat
Section titled “Expressions of Insider Threat”The expressions describe the form of harm and may arise across different insider categories and contexts.
| Expression | Description |
|---|---|
| Violence | Threatened or actual physical harm, intimidation, harassment, bullying or other behaviour that creates a workplace safety risk, including violence directed at the organisation in pursuit of a political or social objective. |
| Espionage | Covert or unauthorised collection, acquisition or disclosure of sensitive, classified, strategic, commercial or proprietary information for advantage or on behalf of another party. |
| Sabotage | Deliberate action intended to damage, disrupt, degrade or interfere with facilities, systems, assets, processes or organisational capability, including through deliberate non-compliance with maintenance or operational procedures. |
| Theft | Unauthorised taking, copying, transfer, removal or misuse of money, property, data, intellectual property or other organisational assets. |
| Cyber Acts | Intentional or unintentional acts involving systems, accounts, networks, devices or data that cause or enable unauthorised access, operational disruption, alteration of information, malicious code execution or other cyber-related harm. |
Insider Contexts
Section titled “Insider Contexts”These contexts describe circumstances that can shape how insider risk develops and may apply across more than one category. Similar behaviour may arise under different conditions, and the surrounding context can influence how the organisation interprets and responds to it.
| Context | Description |
|---|---|
| Compromised Insider | An insider whose identity, credentials, account, device or access has been compromised and is used by an external threat actor without the insider’s authorisation. |
| Coerced Insider | An insider who is pressured, threatened, blackmailed, manipulated or otherwise compelled to undertake unsafe or unauthorised activity. |
| Former Insider | A former employee, contractor, consultant, supplier or partner representative, or other associate who retains organisational knowledge, relationships, influence or residual access after separation. |
| Opportunistic Behaviour | Deliberate activity in which an insider takes advantage of weak controls, excessive access, unclear ownership, poor oversight or process gaps for convenience, personal benefit or unauthorised advantage. |