"What I like about CISA’s framing is that it gets away from the outdated idea that insider threat means a disgruntled employee stealing files on the way out." — Aviv Nahum, Co‑founder and CEO at Above Security
CISA’s Insider Threat Mitigation Guide: key updates
The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Insider Threat Mitigation Guide to reflect a changing workplace and threat environment. The agency added updated case studies and statistics, new insights that account for evolving workplace trends — including artificial intelligence and remote/hybrid work — and resources intended to support organizational preparedness.
Aviv Nahum: move beyond post‑incident reconstruction
Aviv Nahum told Security Magazine that CISA's framing moves away from a narrow, outdated view of insiders. "An insider can be malicious, careless, compromised, coerced or completely unaware that they are helping an attacker," he said, arguing the common denominator is trusted access used in a way that creates risk. Nahum warned most organizations still treat insider risk as an incident‑response problem: "Something happens, HR or Legal raises a concern, and security starts reconstructing the story after the fact. That model does not scale."
Nahum called for continuous, contextual understanding of behavior — "who is acting, what changed, what data and systems are involved, and whether multiple weak signals form a meaningful pattern" — and stressed that insider risk "sits at the intersection of security, HR, legal and the business." He emphasized proportionate intervention ranging from coaching to restricting access rather than blanket surveillance.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildRex Booth: broaden the identity perimeter — including non‑human actors
Rex Booth, CISO at SailPoint, reinforced the guide’s wider conception of insiders: "An insider is no longer limited to a company’s full‑time employees. It can be anyone with legitimate access or trusted proximity ... including contractors, vendors, and partners." He added that insiders may be "non‑human: machine accounts or AI agents operating within the enterprise."
Booth described the central operational challenge: legitimate credential use can be indistinguishable from malicious activity. To meet it, he urged unified visibility that "continuously monitors how identities behave across your entire ecosystem," paired with an identity strategy designed to stop mistakes from becoming enterprise crises.
Morey Haber: technical controls, governance, and non‑human identities
Morey Haber, Chief Security Advisor at BeyondTrust, grouped insider incidents into three classes: malicious insiders, negligent insiders, and compromised insiders. He stressed that many modern ransomware campaigns begin by compromising a user’s identity rather than breaching a perimeter directly, and that most successful attacks "eventually leverage a trusted identity."
Haber outlined concrete prevention measures the guide encourages:
- Embrace least privilege and just‑in‑time access so users and AI agents receive only necessary permissions for limited durations.
- Invest in identity security analytics that continuously evaluate behavior, entitlements, privilege accumulation, toxic combinations of access, and anomalous activity.
- Strengthen governance around non‑human identities, service accounts, API keys, AI agents, and Agentic AI workflows.
- Pair behavioral monitoring with adaptive controls and extra verification for high‑risk actions such as mass downloads, unusual data transfers, or privileged changes.
- Evolve security awareness into continuous education that reinforces accountability and reporting.
"The future of insider threat prevention is not surveillance. It is intelligent identity governance," Haber wrote.
Mika Aalto and Carl Windsor: culture, micro‑training, and monitoring everyday tools
Mika Aalto, Co‑Founder and CEO at Hoxhunt, predicted negligence will remain the dominant form of insider risk: "I don’t anticipate the balance of insider threats to ever shift from negligence to malicious activity." She advocated behavioral science, positive reinforcement, and targeted, in‑the‑moment training — "instantly deliver a positive, in‑the‑moment ‘nudge’ or micro‑training without disrupting their workflow" — to turn employees into "an active, intelligent human sensor network."
Carl Windsor, CISO at Fortinet, urged operational investments that combine "visibility, analytics, and automation to identify risk before data leaves the environment." Windsor highlighted common egress channels — email, collaboration apps, personal cloud accounts — and recommended data leak prevention, deception technology, and behavioral analytics to detect unusual access patterns or misuse of sensitive data.
What this means for security teams, HR, and business leaders
Security teams: prioritize identity security analytics, least‑privilege and just‑in‑time access, and stronger governance for non‑human identities. Several experts argued these steps reduce the opportunities for misuse before incidents occur.
HR and legal leaders: accept insider risk is a cross‑functional problem that requires shared processes for contextual investigation and proportionate interventions — from coaching to access restrictions — rather than relegating response to a single department.
Business leaders: treat employees as partners in defense by funding continuous, signal‑driven training and lightweight controls that preserve productivity while offering real‑time nudges and protections for everyday tools.
Across voices in the conversation, the message is consistent: CISA’s update shifts attention from a narrow, post‑hoc model to a broader, proactive approach that treats trusted access — human and machine — as the central control point. The practical test for organizations is operationalizing least privilege, continuous identity validation, and cross‑functional response long before a single incident prompts reconstruction.




