Skip to main content
CybersecurityIncident Response

CISA Revamps Insider Threat Guide with Expanded Mitigation Advice

Security professional reviews laptop in office setting with thoughtful expression.

"Insider threats continue to evolve as technology becomes more advanced," said Scott Breor, CISA's acting executive assistant director for infrastructure security.

CISA publishes a revised Insider Threat Mitigation Guide

The Cybersecurity and Infrastructure Security Agency (CISA) published a revision to its Insider Threat Mitigation Guide on September 9. First issued in 2020, the guide is framed as a practical playbook for security and human resources professionals who run insider threat programs, as well as leaders at any level. CISA said the guide can be used by any organization "regardless of the maturity of its security," and that industry and government partner feedback informed the update.

New content on hybrid and remote work, artificial intelligence, and adverse separations

The revision adds case studies, statistics and expanded guidance addressing several workplace trends. CISA consolidated sections for a more streamlined format and expanded material on the rise of hybrid work and remote work, explaining how those models change an organization's control over both physical and digital access. The update also adds content explicitly on artificial intelligence — limited, in the agency's words, to AI "used to manipulate or deceive" — and on mitigating the risk of adverse employee separations. CISA characterized these additions as responses to a "dynamic and evolving operational landscape" and as acknowledgements of the growing impact of insider threats on critical infrastructure.

Physical security measures: access control and visitor screening

Beyond data loss, the guide situates insider risk inside the agency's physical security portfolio. The update places new material on access control and visitor screening alongside other guidance, reflecting CISA's broader framing of insider threats: protecting key assets, preventing violence, reducing losses, safeguarding sensitive data and saving lives. The agency said the guide is intended to give employees an understanding of behavioral indicators that may signal risk, not only to spot potential data exfiltration but also to inform physical security and safety responses.

Preparedness and early risk detection: resources for organizations without programs

CISA linked the guide to newly released resources that support preparedness and early risk detection. The agency described those resources as the "practical route into the material" for organizations that do not yet have an established insider threat program. That framing suggests the revision aims both to raise baseline awareness among employees and to offer structured steps for organizations seeking to stand up or mature a program.

What this means for security teams, human resources, and organizational leaders

  • Security teams: Expect guidance that ties digital controls to changing physical-access patterns under hybrid and remote work models, and that highlights AI used to manipulate or deceive as an explicit insider-threat vector to monitor.
  • Human resources: The guide expands content on adverse separations and behavioral indicators, positioning HR as a central partner in detection and mitigation activities and in shaping workplace processes tied to access and screening.
  • Organizational leaders: CISA encouraged organizations to review the guide and assess their programs against it; the agency made clear the guide is intended for organizations at any maturity level and provided additional resources for those without an existing program.

Scott Breor urged organizations to build programs that "protect key assets, prevent violence, reduce losses, safeguard sensitive data, and save lives." CISA gave no timetable for further revisions, leaving the cadence of future updates unspecified even as the revision arrives amid what the agency described as rising concern about employees and AI tools. Notably, the new AI material focuses on manipulation and deception rather than offering a broader assessment of AI's role in insider incidents.

The practical, immediate step CISA set out is straightforward: review the revised guide, compare current practices to the consolidated sections on hybrid work, remote access, AI deception, access control and visitor screening, and use the agency's preparedness and early-detection resources if a formal program does not yet exist. What remains unanswered in the revision is when CISA will publish further updates — a question organizations will likely watch as workplace models and AI capabilities continue to change the risk landscape.

Original story: https://www.infosecurity-magazine.com/news/cisa-updates-insider-threat-guide/