Insider Threat Awareness Month: Rethinking Risk in the Age of AI

During Insider Threat Awareness Month, it is important to recognize that insider risk extends well beyond the traditional image of a malicious employee stealing sensitive information. Today, legitimate access, human error, over-permissioned accounts and artificial intelligence systems can all create serious security risks.

As organizations adopt generative AI and agentic systems, the definition of an insider threat is changing. Sensitive data can be exposed through an employee’s use of an unapproved chatbot, a misconfigured privilege or an AI agent with permission to access multiple systems. Leaders such as Bertijn Eldering, Senior Sales Engineer at HackerOne, Clyde Williamson, Senior Product Security Architect at Protegrity, Shiv Agarwal, CEO and co-founder of Singulr AI, Jay Bavisi, founder and group president of EC-Council, Cyrus Robinson, SVP of Security Operations at C3, and Jon Guild, Senior Penetration Tester at Securin, highlight why visibility, access controls, continuous monitoring and clear boundaries for AI authority are essential to reducing insider risk.

Bertijn Eldering, Senior Sales Engineer, HackerOne

“The insider risk in enterprise AI is rarely about intent and more so about inherited access. An assistant does not simply decide to leak data, it answers the question it was asked using whatever it can access. One example of this is a case with Samsung where the organization reportedly restricted internal use of generative AI tools after employees were suspected of sharing sensitive material with a public chatbot. With a majority of employees now using these tools in their daily work, often outside formal governance processes, shadow AI has become a more relevant concern than traditional shadow IT.

Agentic systems change the form of the problem, not its underlying cause. Microsoft’s own AI research division exposed 38 terabytes of internal data through a single access token that was scoped to an entire storage account instead of the intended buc0 ket, and set to full control instead of read only. What came with it included workstation backups, service passwords, secret keys and more than 30,000 internal Teams messages. Agents are provisioned by the same people under the same delivery pressure, and they then act repeatedly and at machine speed. The more challenging issue is attribution. AI systems often arrive with their own logging, which can be less mature than the platforms around them. If you cannot separate an authorised automated workflow from a person misusing one, you have lost the signal that insider threat programmes depend on.

The answer to combating this challenge is practical. Give agents their own identities and scope them to a single task. Keep an audit trail you would be willing to defend in an investigation. Treat every change to a tool, model or integration as a change to your exposure, test that continuously rather than at review points, and keep a human in the loop for the judgement calls.”

Clyde Williamson, senior product security architect, Protegrity

“Insider threats are usually pictured as a malicious employee stealing data on the way out the door. That happens, but the bigger day-to-day risk is legitimate access, exposing more information than someone needs.

Once a user logs in, many systems still display sensitive data simply because that is how the application was built. AI makes that easier to get wrong. An employee can paste customer data into a chatbot in seconds, and an AI agent with broad permissions can move information across systems faster than any human ever could.

Organizations should focus on reducing unnecessary visibility after access is granted. Tokenization, encryption and masking can help keep sensitive values protected even when a person or AI system has legitimate access.

A perfect audit trail explaining how your data left the building is still an explanation of how your data left the building. The better outcome is making sure less sensitive data was exposed in the first place.”

Shiv Agarwal, CEO & co-founder, Singulr AI

“As AI becomes embedded in everyday workflows, insider risk is evolving faster than most organizations realize. Employees are adopting shadow AI tools at a pace that outstrips governance – often with good intentions, but with real exposure: sensitive data flowing into unvetted tools, and no visibility into what those tools can access or do.

The stakes rise sharply as organizations deploy AI agents with authority to access data, invoke tools, and act across systems. The question is no longer just whether your people are following policy; it’s whether your AI is. And as agents operate with greater autonomy, unchecked AI spend becomes its own category of insider risk. Token costs scale with agent activity, and without attribution down to the team or workload driving that spend, organizations discover the exposure after the fact.

Insider Threat Awareness Month is a timely reminder that AI governance isn’t a deployment checklist – it’s an ongoing discipline. Organizations need to know which AI systems are operating in their environment, what they can access, what actions they can take, and what they are spending. Guardrails must be in place before deployment, and continuously verified as AI workflows evolve. Visibility, control, and accountability across every AI system aren’t optional; they’re the foundation.”

Jay Bavisi, founder and group president, EC-Council

“We are moving from AI 2.0 to AI 3.0, and I think the most important change is being underestimated. AI 2.0 gave us tools. Generative AI could create, summarize, analyze and assist.

AI 3.0 is giving us actors. Reasoning and agentic systems can pursue objectives, use tools, navigate workflows and act with increasing autonomy.

That distinction matters enormously for insider threat.

A tool waits for you. An agent acts for you. Once AI can operate inside enterprise systems, interact with applications, access data and make decisions across a workflow, the security question changes from what AI knows to what authority AI has.

That is an important part of the thinking behind EC-Council’s Adopt. Defend. Govern. framework. In the agentic era, adopting AI is no longer simply choosing a technology. You are deciding what agency enters the enterprise. Defending it means challenging what that agency can be made to do. Governing it means deciding where its authority begins, where it ends and when it should be taken away.

Insider Threat Awareness Month becomes particularly interesting in the transition to AI 3.0. Insider risk is beginning to include something organizations have never had to manage at this scale: autonomous digital actors operating legitimately inside enterprise trust boundaries.

The real question is no longer whether AI belongs inside enterprise workflows. That decision is already being made. The question is whether organizations are defining the boundaries of machine authority as deliberately as they once defined human access.

In AI 3.0, insider risk will not only be shaped by who is trusted, but by what is trusted to act.”

Cyrus Robinson, SVP, security operations, C3

“A common mistake is treating insider risk as either a malicious employee problem or an annual awareness exercise. Many incidents begin with routine actions by people using legitimate access. That may be a misdirected email, an overly broad file share, a personal cloud account or an unapproved AI tool. A malicious insider may use many of those same paths. Intent matters during the investigation, but access and data protections need to contain the impact in either case. For defense contractors, a routine mistake involving sensitive information can create risk beyond one company and into the wider supply chain.

Technology can correlate identity, endpoint, email, cloud and data activity and surface behavior that deserves attention. An unusual login or a large download is a signal, not a verdict. There may be a legitimate business explanation, so security operations teams need thresholds that reflect the environment, clear escalation paths and analysts who can validate what happened. Automation can accelerate triage, but the SOC’s role is to establish context and escalate what matters. Intent and response should be assessed through the organization’s broader insider threat process, with the appropriate security, legal, HR and operational leaders involved.

Strong insider threat programs come back to disciplined fundamentals. Keep access aligned to job need, review it when roles change and remove it quickly when someone leaves. Protect privileged accounts and monitor the movement of sensitive data. Training should be recurring and tied to the employee’s responsibilities. Employees also need a simple way to report mistakes or concerns without feeling as though they are automatically being treated as suspects. The goal is to identify issues early and keep mistakes or misuse from becoming larger incidents.”

Jon Guild, senior penetration tester, Securin

“When organizations hear ‘insider threat,’ they often focus too narrowly on a malicious employee. That framing is increasingly wrong at both ends. A stolen credential, an over-permissioned contractor, a misconfigured privilege and an honest mistake all arrive at the same place. A valid identity reaching something the business never intended it to reach.

The difference between them is intent, and intent is invisible to your stack. Credentials leak. Contractors retain access. Privileges get misconfigured. Sometimes nobody gets breached at all. The access you intended can be more useful to an attacker than any exploit.

Awareness training is a layer, and layers are good, but the layer people skip is figuring out how far an ordinary account gets once someone is already inside. Blast radius is the question, and blast radius comes from combinations. A stale delegation nobody remembers configuring. A group whose membership made sense in 2019. A forgotten asset. Individually, low. Together, a path to critical systems.

Most organizations can state their policy on least privilege. Very few can tell you what a contractor account or a standard employee account actually reaches when someone tries. Only one of those is evidence.”

Join our LinkedIn group Information Security Community!

No posts to display