6 min read

Insider Threat Awareness Month: How Your Organization’s Insider Risk Program Compares

Author: STRIDER


Share

Insider Threat Awareness Month is an opportunity for organizations to look beyond whether they have an insider risk program and ask a more difficult question: How effective is it?

For many organizations, policies have been written, security tools deployed, and employees trained. But having the components of a program in place does not necessarily mean those components are working together—or that they are prepared to address the insider threats organizations face today.

That distinction matters as the threat continues to evolve.

An insider threat is a security risk posed by someone who already has some level of trusted access to an organization’s systems, data, intellectual property, or facilities. That individual might be an employee, contractor, or business partner. Unlike an external attacker, an insider already understands at least some of the organization’s systems and processes and may be able to operate within established security controls.

Not every insider threat is malicious. Employees can expose sensitive information through negligence or simple mistakes. Others may deliberately misuse their access for financial gain, revenge, or loyalty to another organization or nation-state.

Increasingly, however, organizations must also account for another dimension of insider risk: foreign actors actively identifying, targeting, and cultivating people with access to valuable technology, information, or expertise.

In January 2026, for example, a federal jury convicted a former Google software engineer on seven counts of economic espionage and seven counts of trade secret theft after he transferred proprietary AI chip technology to outside parties while secretly working with companies based in the People’s Republic of China (PRC). The case illustrates how trusted access to critical technology can become a target for economic espionage.

Traditional security controls remain essential, but insider risk presents a fundamentally different challenge. Organizations are not simply looking for an outsider trying to get in. They must also be able to identify when someone with legitimate access begins creating risk—or when that individual becomes the target of a foreign government or intelligence service.

How Mature Are Insider Threat Programs Today?

To better understand how organizations are addressing that challenge, Strider’s insider risk experts on the Client Services team conducted proprietary Program Maturity Assessments (PMAs) for 41 insider risk and economic security programs across a range of global organizations between 2025 and 2026.

Each assessment evaluated a program across 13 categories, including governance, policy, training, technical controls, employee management, and risk intelligence. Programs were benchmarked on a five-point maturity scale, ranging from ad hoc practices at Level 1 to optimized capabilities at Level 5. A score of 3 indicates a defined capability, while a 4 represents one that is managed and measurable.

Across all 41 assessments and all 13 categories, the average maturity score was 2.8 out of 5.

Most organizations are not starting from zero. They have established many of the foundations of an insider risk program. Processes exist, responsibilities have been assigned, and security capabilities are in place.

But many organizations have not yet reached the point where those processes are consistently monitored, measured, integrated across business functions, and adapted as threats change.

How Programs Compare Across 13 Categories

The assessments revealed both meaningful strengths and persistent gaps:

Program CategoryAverage Score
Access Controls3.6
Technical Controls3.3
Risk Intelligence3.2
Program Governance3.0
Policies and Procedures3.0
Risk Detection Capabilities3.0
Data Management2.9
Internal Threat Landscape2.8
External Threat Landscape2.8
Training and Communications2.7
Third-Party and Supply Chain Risk2.7
Risk Review and Response Process2.5
Employee Management2.1

The strongest category was Access Controls, at 3.6. Nearly every organization assessed scored between 2.0 and 5.0, suggesting that investments in physical and role-based access controls have become relatively mature across industries and organization sizes. The strongest programs consistently applied practices such as least-privilege access and badge-based controls.

At the other end of the spectrum was Employee Management, with an average score of just 2.1. It was not only the lowest-scoring category but also the category with the widest variation among organizations assessed.

One recurring weakness was offboarding. Strider’s assessments found organizations without formal departure communication protocols, delays between employee departures and access removal, and programs that depended heavily on self-reporting rather than insider-risk-specific indicators. More mature organizations demonstrated much tighter coordination between HR and security throughout the employee lifecycle.

Training and Communications, at 2.7, represented another common gap. Many programs still rely primarily on general cybersecurity awareness or onboarding rather than recurring, role-specific education focused on insider risk. The highest-performing organizations treated insider risk training as a distinct, ongoing discipline rather than another component of annual compliance training.

And Risk Intelligence, despite earning a relatively strong average score of 3.2, revealed perhaps the sharpest divide among the organizations assessed. At the mature end of the spectrum, organizations maintained dedicated intelligence capabilities that informed governance and prioritization and produced recurring strategic intelligence on relevant external threats. At the other end were organizations with no formal risk intelligence capability at all.

The divide matters because insider risk does not exist entirely within an organization’s network or workforce. Understanding which technologies, employees, research areas, and business relationships may be attractive to nation-state actors requires visibility into the external threat environment as well.

Developing a Program into a Mature Program

Taken together, Strider’s findings show an insider risk field that has made significant progress.

Most organizations recognize the threat. They have established governance structures, policies, technical security controls, and other foundational elements. The question is increasingly not whether organizations are addressing insider risk, but how mature those efforts have become.

The strongest programs share several characteristics. They combine executive sponsorship with active cross-functional governance. Their technical and detection capabilities are monitored, measured, and connected to specific risk indicators. And they incorporate dedicated risk intelligence that extends beyond conventional cybersecurity threat feeds.

Less mature programs tend to struggle at the points where different functions must work together: coordinating HR and security during employee lifecycle events, translating geopolitical threats into relevant information for employees, integrating multiple sources of risk information, and moving from incident response to proactive identification of potential exposure.

That is the next maturity challenge.

Turning Awareness Into Action

Insider Threat Awareness Month is an important reminder that insider risk deserves organizational attention. But awareness is only the starting point. Organizations should also use this month as an opportunity to examine where their programs stand.

Are policies consistently enforced across the enterprise? Is training tailored to the people and technologies most likely to be targeted? Do HR, security, legal, procurement, and leadership have a shared understanding of insider risk? Are detection capabilities designed specifically for insider threats? And does the organization understand the external actors that may be targeting its people and intellectual property?

For many organizations, the foundations are already there. Strider’s benchmark suggests the next step is turning those foundations into capabilities that are consistently monitored, measurable, integrated, and proactive.

Because the question is no longer simply whether your organization has an insider threat program. It is whether that program is ready for the threats it faces.

In Blog 2 of this series, we’ll examine what separates more mature insider threat programs from the rest—and the practical steps organizations can take to strengthen their people, processes, technology, and intelligence.