The 2025 Insider Risk Report, produced by Cybersecurity Insiders in collaboration with Cogility, reveals that a vast majority of organizations find insider threats as difficult or even more challenging to detect than external cyberattacks. According to the report, 93% of surveyed security leaders acknowledge the complexity of identifying insider risks, yet only 23% express strong confidence in their ability to prevent such threats before significant damage occurs. The findings highlight a critical gap in proactive defense, with most organizations remaining reactive despite the growing risks posed by AI-driven threats and decentralized workforces.
The report, based on a survey of 635 CISOs and cybersecurity professionals, underscores that only 21% of organizations integrate non-technical signals—such as HR data, financial stress, or psycho-social indicators—into their insider risk detection programs. Furthermore, just 12% have implemented mature predictive risk models, leaving the majority vulnerable to sophisticated insider attacks. Experts warn that without adopting behavioral intelligence and predictive analytics, organizations risk being blindsided by trusted insiders exploiting new technologies, potentially leading to severe data breaches and reputational harm.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
A 2025 Insider Risk Report was published, finding that most organizations struggle to detect and predict insider risks. The two references appear to report the same publication rather than separate events.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.