CISA has revised its Insider Threat Mitigation Guide with updated case studies, statistics, and resources to help security, HR, and organizational leaders build or assess insider-risk programs at any maturity level. The guidance addresses risks created by hybrid and remote work, adverse employee separations, and AI-enabled manipulation and deception, while broadening its scope from data protection to physical security, violence prevention, access control, and visitor screening.
The agency urges organizations to identify behavioral warning signs and improve preparedness and early-risk detection because trusted users, contractors, vendors, machine identities, and AI agents can misuse, compromise, or unintentionally expose organizational assets through otherwise legitimate credentials and workflows. Recommended measures include least-privilege and just-in-time access, identity and behavioral analytics, governance for non-human identities, adaptive controls for high-risk actions, data-loss prevention, and continuous security education.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
CISA published an updated Insider Threat Mitigation Guide with refreshed case studies and statistics and guidance addressing AI, hybrid and remote work, access control, visitor screening, and adverse employee separations. The revision expands the guide's scope to physical security and violence prevention alongside data protection and provides preparedness and early-risk-detection resources.
September 2026 is designated National Insider Threat Awareness Month, themed “Protect Our Potential,” promoting insider-risk awareness and mitigation programs across government and industry.
CISA first issued its Insider Threat Mitigation Guide.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcesecuritymagazine.com
Open sourceinfosecurity-magazine.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.