9 min read

How to Build a More Mature Insider Threat Program

Author: STRIDER


Share

In the first blog of this series, we examined how insider threat programs compare across organizations and found that, while many have established the foundations of an effective program, most have significant room to mature.

Across the 41 Program Maturity Assessments (PMAs) conducted by Strider’s insider risk experts between 2025 and 2026, organizations earned an average maturity score of 2.8 out of 5. Most have the policies, processes, and security capabilities in place. The larger challenge is moving from those defined processes to programs that are consistently monitored, measured, integrated across the organization, and designed to identify risks before an incident occurs.

Strider’s findings also demonstrate that no single tool or policy makes an insider threat program mature. The strongest programs are those that bring together people, processes, technology, and intelligence. They build collaboration across functions, continually educate employees, evaluate whether their controls are effective, and understand not only what is happening inside the organization, but also who may be targeting their people and technology from the outside.

Based on the patterns Strider observed across its assessments, five areas are particularly important for organizations seeking to move from awareness to action: people and trust; education and awareness; technology and tools; evaluation and feedback; and proactive processes.

1. Build the Program Around People and Trust

At its core, insider risk is a human challenge.

Employees, contractors, and other trusted individuals need access to sensitive systems and information to do their jobs. An effective insider threat program cannot eliminate that access or operate on the assumption that every employee represents a potential threat.

Instead, mature programs create a culture in which protecting the organization is a shared responsibility.

That begins with trust. Employees need to understand why security practices exist, feel comfortable raising concerns, and know that reporting potentially suspicious interactions will be taken seriously rather than treated as an accusation.

Leadership engagement matters, as well. Insider risk should not sit solely with a cybersecurity team. Cross-functional participation from security, HR, legal, procurement, executive leadership, and other relevant teams allows organizations to understand risk in context and act on it consistently.

Strider’s assessments showed the importance of that coordination. Employee Management was the lowest-scoring category across all 41 PMAs, averaging just 2.1 out of 5. A recurring weakness was coordination between HR and security, particularly during offboarding. Some organizations lacked formal departure communication protocols, while others experienced delays between an employee’s departure and removal of access. The strongest programs, by comparison, demonstrated tight HR-security integration throughout the employee lifecycle.

Mature programs should also consider which employees may be particularly attractive targets for foreign actors. Individuals with access to sensitive research, proprietary technology, strategic business information, or specialized expertise may face risks that differ significantly from those facing the broader workforce.

Creating an ongoing awareness loop for these employees—including regular briefings on the tactics, techniques, and procedures used by nation-state actors—can help them identify concerning interactions early and give them a clear path for reporting them.

2. Move Beyond Annual Security Training

Insider threat education should not be treated as a once-a-year compliance exercise.

Strider’s assessments found that Training and Communications averaged 2.7 out of 5. Many organizations provide security education during onboarding or through general cybersecurity awareness programs but lack recurring, role-specific insider threat training.

More mature programs take a different approach.

Training should be continuous, relevant, and tailored to the employee. A researcher working on sensitive technology, for example, may need to recognize very different risks than an employee with privileged administrative access or a procurement professional evaluating overseas suppliers.

Scenario-based training can make those risks tangible. Real-world examples can help employees recognize behaviors such as unusual professional outreach, persistent requests for information, foreign talent recruitment approaches, coercion, or efforts to develop relationships that could eventually be leveraged for access.

Training should also help employees understand what to do when something feels unusual. That is particularly important when dealing with state-sponsored threats. The initial interaction may not look suspicious. A foreign actor may begin by offering professional opportunities, research collaboration, conference invitations, consulting arrangements, or other seemingly legitimate forms of engagement.

Employees who understand these tactics are better positioned to recognize when a professional relationship may be creating risk and to engage security teams before that relationship escalates.

As Strider’s Insider Threat Benchmarking E-book notes, the goal should be to give employees ownership of the outcome rather than another checklist to complete.

3. Tune Technology to Insider Risk

Most organizations already have significant cybersecurity capabilities. But technology designed to detect malware, network intrusions, or external attackers does not automatically translate into an effective insider threat capability.

That distinction showed up clearly in Strider’s findings.

Technical Controls averaged 3.3 out of 5, one of the stronger categories assessed by Strider’s experts. Yet many organizations relied on a capable general cybersecurity stack without tuning those tools to identify insider-specific behaviors.

Mature programs go further.

User activity monitoring, behavioral analytics, anomaly detection, data loss prevention, and other technical capabilities should be connected to specific insider risk indicators and deployed transparently in ways that respect employee privacy.

Similarly, technology alone rarely provides enough context. For example, a technical alert might show that an employee downloaded an unusual volume of data. But understanding whether that activity represents risk could also require knowing about changes in the individual’s behavior, policy violations, foreign travel, external relationships, or other relevant information.

The strongest programs therefore combine technical signals with human review rather than relying on automated alerts in isolation.

A formal risk review process can help bring these inputs together. Strider’s experts recommend establishing a consistent process through which an Insider Threat Working Group or similar cross-functional body can evaluate signals, add relevant context, determine whether escalation is appropriate, and document how decisions are made.

The goal is not simply more monitoring. It is better-informed monitoring.

4. Continually Evaluate Whether the Program Works

An insider threat program cannot be built left unchanged.

Organizations evolve. Employees change roles. New technologies are developed. Partnerships and suppliers change. And foreign actors continually adapt the methods they use to gain access to sensitive information.

A mature program therefore needs a regular feedback loop.

Red teaming, structured risk assessments, after-action reviews, and program maturity assessments can help organizations identify where controls are effective and where gaps remain. Anonymous reporting mechanisms, employee feedback, and post-incident debriefs can also reveal weaknesses that security teams might otherwise miss.

Strider’s findings point to the importance of formalizing that process. Annual PMAs and written after-action reporting can give leaders a structured way to measure progress, capture lessons, and prioritize improvements over time.

This is particularly important because program maturity can move in both directions. New offices, leadership transitions, changing vendors, acquisitions, or new business requirements can introduce vulnerabilities into processes that previously worked well.

Organizations should regularly ask: Is the control working? Is it being applied consistently? And does it address the threats we face today?

5. Understand the Threat Before It Reaches Your Organization

Perhaps the biggest difference between a reactive insider threat program and a proactive one is when the organization begins looking for risk.

Reactive programs wait for an alert, policy violation, or incident.

Proactive programs seek to understand who and what an adversary is likely to target before that happens. That requires understanding both the internal and external threat environments.

Internally, organizations should know which technologies, intellectual property, research programs, data, and expertise are most strategically important.

Externally, they need visibility into the nation-state actors, intelligence services, talent programs, research institutions, companies, and other entities that may be seeking access to those assets.

Strider’s PMA findings demonstrated a significant divide in this area. Risk Intelligence averaged 3.2 out of 5, but organizations tended to fall toward opposite ends of the spectrum. More mature organizations embedded dedicated intelligence capabilities into governance and prioritization and produced recurring intelligence on relevant external threats. Less mature organizations sometimes had no formal risk intelligence capability at all.

Connecting this external intelligence with internal knowledge can allow security teams to identify employees, teams, technologies, and business relationships that deserve additional attention.

Instead of asking only, “Has someone done something suspicious?” organizations can begin asking, “Who is most likely to be targeted, by whom, and why?”

That shift creates opportunities for earlier engagement before an external relationship develops into an insider threat.

How Does Your Program Compare?

Mature insider threat programs are not defined by a single technology or policy. They are built through consistent execution across the organization. As a starting point, security leaders can ask whether their programs:

  • Have an established, cross-functional governance structure with regular interdepartmental engagement.
  • Maintain a dedicated and active insider risk policy framework.
  • Extend internal threat awareness beyond leadership to operational employees.
  • Maintain structured awareness of external threats, including relevant government or intelligence-community briefings.
  • Deliver recurring insider threat training that is distinct from general cybersecurity awareness.
  • Demonstrate close coordination between HR and security throughout the employee lifecycle.
  • Maintain a formal system for continuous, proactive risk review.
  • Align technology investments to specific insider risk indicators.
  • Combine multiple detection streams with human review.
  • Consistently apply least-privilege and physical access controls.
  • Apply data classification and labeling consistently.
  • Coordinate procurement and security around third-party and supply-chain risk.
  • Produce recurring intelligence on insider risk and the external threat environment.

Few organizations will be equally mature across every category. A program maturity assessment can help leaders identify where the organization already has strong capabilities, where gaps remain, and where limited resources can have the greatest impact.

The strongest programs do more than respond when something goes wrong. They create trusted environments where employees understand the threat, connect intelligence with technical and human signals, continuously evaluate their defenses, and identify areas of exposure before adversaries can exploit them.

That is the transition from an insider threat program that exists to one that is built to perform.

In Blog 3 of this series, we’ll look at what that transition can mean in practice and how an organization used a Program Maturity Assessment as the starting point for identifying targeted employees, strengthening security controls, and addressing previously unseen risks across its workforce and supply chain.