Skip to main content
CybersecuritySocial Engineering

Security Leaders Warn of Evolving Insider Threats

Empty office corridor with cubicles and private offices, laptop screen blurred in foreground.
“An insider already has what an external attacker usually wants first: access,” Andrew Costis said, underscoring why traditional alert-focused defenses can miss the real risk when trusted accounts are abused.

Andrew Costis on adversarial validation and continuous exposure management

Andrew Costis, engineering manager of the Adversary Research Team at AttackIQ, framed the problem in operational terms: an insider begins with access, and organizations cannot judge their readiness by counting alerts for downloads or abnormal logins alone. Costis argued that defenders must ask whether a trusted account could reach privileged systems, escalate access, or move laterally toward sensitive data — and whether existing defenses would detect and stop those actions before access becomes compromise.

He recommended folding insider scenarios into the same adversarial validation exercises used for external threats. In Costis’s terms, continuous exposure management (CEM) and adversarial evaluation (AEV) can test realistic techniques against live defenses “before a real employee, compromised account or malicious contractor tries them.” His closing line distilled the prescription: “Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.”

Ross Filipek on discipline in access lifecycle management

Ross Filipek, CISO at Corsica Technologies, emphasized the mundane — but ubiquitous — sources of insider risk: orphaned accounts, role changes that leave excess permissions, contractors whose remote access is not revoked, and delays in closing SaaS accounts after departures. Filipek noted that access “quietly accumulates” because responsibilities are split across IT, HR, and management processes, and that smaller organizations may lack a single team to watch the entire employee lifecycle.

His remedy is procedural and low-tech: define what access employees should have at hire, review permissions when roles change, and remove access immediately when someone leaves. Periodic access reviews, he said, can catch the gaps that daily operations miss. Filipek’s point is explicit: insider threat programs don’t need sophisticated surveillance to start; a lot of risk can be eliminated by ensuring people only retain the access they actually need.

Kevin Kirkwood on behavioral baselines and the emergence of AI agents

Kevin Kirkwood, CISO at Exabeam, urged a wider definition of “insider.” He said organizations must retire the idea that insiders are always disgruntled employees stealing files. Exabeam encountered “a foreign operative aligned with North Korean interests” who passed hiring and looked legitimate until small behavioral anomalies — weak signals viewed together — revealed a different story.

Kirkwood added a new category to the insiders list: AI agents. “Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step,” he said, noting that such agents are not inherently malicious but that “blind trust” becomes dangerous. His prescription: move beyond authentication checks and focus on whether an identity’s behavior still makes sense — for employees, contractors, and increasingly, machines acting with employee-like authority.

Kevin Mata on signal correlation, automation, and cross-team response

Kevin Mata, director of cloud operations and automation at Swimlane, described the analyst’s practical problem: identity data, endpoint activity, and cloud access often live in separate systems, and assembling a complete picture can eat the time analysts need to decide. He warned that single-event noise — one strange login, one large download, or one unexpected privilege change — rarely proves an insider threat by itself; the danger arises when several signals cluster around the same person and “nobody has the full picture.”

Mata advocated using AI to connect signals while an investigation is developing, and automation to enrich events with context and route higher-risk cases to the right people. He stressed coordination: security teams may need HR or legal involved, and “the best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.”

What this means for security operations, HR, and smaller organizations

  • Security operations: Treat insider scenarios as part of adversarial validation, build behavioral baselines that include non-human identities, and invest in cross-system signal correlation so analysts can act on developing patterns rather than isolated alerts.
  • HR and legal: Bake access lifecycle checkpoints into onboarding, role changes, and offboarding processes, and establish agreed evidence and escalation paths when investigations implicate personnel matters.
  • Smaller organizations: Start with basic process discipline — defined initial permissions, timely removal of access, and periodic access reviews — before pursuing sophisticated monitoring or validation programs.

Across these perspectives the through-line is both simple and exacting: reduce accumulated privileges, connect signals across identity and activity systems, and validate defenses against realistic insider techniques. As Costis put it, awareness alone is not enough — validation tells you whether the environment can withstand it. That dual approach is the practical next step security leaders in the piece recommend for Insider Threat Awareness Day (or Month, in Kirkwood’s phrasing): move from recognizing risk to proving defenses against it.

Original story