| | |

Rethinking the Divide Between Insider Threat and Workplace Violence Prevention

A man in a suit stands before a blue cityscape background. Text reads, "Rethinking the Divide Between Insider Threat and Workplace Violence Prevention. Jameson Ritter. CPPS.

For years, many organizations have treated insider threat and workplace violence (WPV) programs as separate efforts. Insider threat initiatives became closely associated with cybersecurity, focusing on data theft, espionage, and misuse of digital systems. Workplace violence prevention, by contrast, was typically managed through HR, corporate security, or safety functions and focused primarily on physical incidents or employee conflicts.

As a result, organizations often developed two separate programs with different leadership structures, reporting chains, and assumptions about risk. Insider threat teams concentrated on digital harm, while workplace violence programs focused on physical harm. In practice, however, the behaviors associated with both types of incidents frequently overlap.

What the research says about shared behavioral pathways

Research over the past decade increasingly suggests that organizations may be evaluating related forms of risk through disconnected frameworks. One organization that has examined this issue extensively is the Carnegie Mellon University Software Engineering Institute (SEI) and its CERT National Insider Threat Center. In their 2022 report, Relating Insider Cyber Sabotage and Workplace Violence, researchers led by Dan Costa analyzed dozens of cases involving insider cyber sabotage and workplace violence and identified recurring similarities in the pathways that preceded harmful acts.

These shared indicators included grievance development, personal and work-related stressors, behavioral changes, increasing isolation, policy violations, and escalation over time before the incidents diverged into different forms of harm.

This distinction matters because organizations have historically separated these disciplines largely based on outcomes—one resulting in data theft or system sabotage, the other in threats or acts of violence. Yet the observable behaviors leading up to those outcomes often overlap significantly.

How the definition of insider threat has evolved

A notable shift followed in 2017 when the CERT National Insider Threat Center updated its official definition of insider threat to include “the potential for an individual who has or had authorized access to an organization’s critical assets to use their access, either maliciously or unintentionally, to act in a way that could negatively affect the organization.”

The update reflected years of case analysis showing that insider sabotage and workplace violence can emerge from similar behavioral pathways.

What federal guidance recommends

Federal guidance has reached a similar conclusion. In its 2019 publication, Violence in the Federal Workplace: A Guide for Prevention and Response, the Interagency Security Committee (ISC), working with the Cybersecurity and Infrastructure Security Agency (CISA), stated that an established insider threat program “can be an additional resource for reporting, monitoring, and tracking workplace violence” and recommended that insider threat and workplace violence programs be “complementary and mutually reinforcing.”

The guidance reflects changing views within organizations about how these risks should be assessed and managed. Rather than treating insider threat and workplace violence prevention as separate ownership areas, the guidance encourages coordination between programs that are often evaluating related behavioral concerns from different perspectives.

Where the gap between programs creates risk

Many organizations still struggle with this kind of integration. Cybersecurity teams may identify unusual system activity or policy violations but lack visibility into HR concerns, grievances, or troubling interpersonal behavior. At the same time, WPV or Behavioral Threat Assessment and Management (BTAM) teams may observe escalating conflicts or fixation without awareness of concerning digital activity occurring elsewhere in the organization.

In many cases, the relevant information already exists within the enterprise but remains fragmented across teams that do not routinely share context or assess concerns together.

How BTAM supports insider threat integration

This is where strong BTAM programs can play an important role. BTAM teams often include representatives from HR, legal, security, mental health, compliance, and operations who assess concerning behavior collectively and over time. That multidisciplinary approach aligns naturally with modern insider risk management.

Combining these perspectives allows organizations to assess concerning behavior more effectively. Data hoarding or unusual system activity identified by cybersecurity personnel, when considered alongside grievance narratives or leakage behaviors identified by a BTAM team, may provide a stronger indication of escalating risk than either set of indicators alone. Evaluated together, those signals can support earlier and more informed intervention decisions.

What integration does and doesn’t mean

Importantly, integration does not mean labeling frustrated employees as threats or expanding unnecessary surveillance. The goal is responsible prevention through improved context, communication, and coordinated response.

Effective prevention depends on responsible information sharing between teams already tasked with organizational safety, security, and employee well-being. That coordination requires clear reporting processes, privacy protections, legal oversight, and sound behavioral assessment practices, as well as a willingness to break down longstanding operational silos.

Why the convergence of these disciplines matters now

For decades, insider threat and workplace violence prevention developed as separate professional disciplines with distinct terminology and approaches. Those distinctions still matter. However, the people and behaviors behind these risks rarely fit neatly into “cyber” or “physical” categories.

Organizations that have invested in prevention efforts are increasingly recognizing the benefit of coordinating these disciplines while still maintaining the specialized expertise each provides. Insider risk is not solely a cybersecurity issue, just as workplace violence prevention is not limited to physical safety concerns. Both involve understanding how stressors, grievances, behavioral changes, and escalating risk can develop over time.

Prevention efforts are often stronger when those conversations occur collaboratively rather than in isolation.

This article was originally published in Workplace Violence Today magazine.

Similar Posts