What Is an Insider Threat? What NITAM Gets Right and What It Misses. 

A picture of a hooded person inside a building meant to signify an insider threat.

September is National Insider Threat Awareness Month

Poisoned water. Pathway to violence. Insider threat. What do these things have in common? They all start with a grievance. 

At a utility company, an insider with authorized access to the water system began threatening to poison it. The act wasn’t random. It was the end point of a journey that included a grievance, escalating behavior, and a decision to cause harm. The warning signs existed. What didn’t exist was a single team with visibility across all of them. 

That is the central risk: insider threat and behavioral threat management are converging, but many organizations still leave the warning signs split across teams that do not routinely share context. 

What is National Insider Threat Awareness Month? 

Every September, the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of the Director of National Intelligence (ODNI) co-sponsor National Insider Threat Awareness Month, known as NITAM. It’s an annual campaign designed to help organizations recognize the warning signs of insider risk and build programs to address them. 

This September, CISA released the 2026 edition of its Insider Threat Mitigation Guide, updated from the original 2020 version. The guide highlights updated case studies and statistics, and expands guidance on hybrid and remote work, AI, access control, visitor screening, and adverse employee separations. Its framing is worth noting: insider risk sits at the intersection of security, HR, legal, IT, privacy, and the business, not solely in the security operations center. 

That framing matches what practitioners in behavioral threat management have been arguing for years. 

What is an insider threat? 

An insider threat is the potential for someone with authorized access to an organization’s people, facilities, systems, or information to use that access to cause harm, whether intentionally or through negligence. That definition comes from CISA and has broadened significantly over time. 

It’s not limited to government contractors stealing classified data. It includes employees, contractors, vendors, and anyone else with knowledge of or access to an organization’s operations. The harm doesn’t have to be digital. It can be physical, operational, or reputational. 

Insider threat is behavioral before it’s operational. That distinction matters, because behaviors are observable. Organizations that treat insider threat purely as a technology problem will always be responding after the fact. 

What is the pathway to violence, and how does it connect to insider threat? 

The pathway to violence is a framework used in behavioral threat assessment and management (BTAM) to describe how individuals move from grievance to harmful action. It isn’t a sudden break. It’s a progression, and it’s observable at multiple points along the way. 

According to Jameson Ritter, CTM and CPPS Director of Threat Management, Carnegie Mellon University’s CERT National Insider Threat Center research shows that insider risk has a distinct behavioral progression; in practice, Ritter notes that the early escalation pattern often mirrors the pathway to violence before it diverges toward sabotage, theft, espionage, or physical harm. A grievance forms. Behavior escalates. Boundaries get tested. The terminology differs between BTAM and insider risk programs, but the underlying behavior is often the same. 

The divergence happens at a decision point. One path leads toward data theft, sabotage, or espionage. The other leads toward threats or violence. By the time that split occurs, the window for early intervention has already been open for a long time. 

What does insider threat look like in practice? 

Insider threats can take many forms. Sometimes theft of intellectual property, but sometimes direct physical threats to people, property, or resources. 

A manufacturing company employs workers who operate high-end, precision equipment. Someone develops a grievance. Before anything visible happens, there’s leakage: behavioral changes, complaints, boundary testing. Then three machines go offline, ruined by intentionally wrong code and incorrect dimensions entered by someone who knew exactly what they were doing. Multi-million-dollar equipment. Weeks of lost production. A small or mid-sized company running a half-dozen machines can’t absorb that kind of loss quietly. 

In a separate client case, a stalking and domestic violence situation surfaced threat signals that lived entirely in internal instant messaging channels. If the team hadn’t looked there, and if the right people hadn’t had access to look, the signal would have been invisible. The threat was real. The information existed inside the organization. It just wasn’t in anyone’s line of sight because the teams weren’t talking. 

That’s the cost of a wall that shouldn’t exist. 

Who should be on an insider threat team? 

The most common answer organizations give is security. Sometimes HR. Occasionally legal. 

That’s not enough. 

Security sees boundary probing and access anomalies. HR sees disciplinary patterns and behavioral reports from colleagues. Cyber sees unusual system activity, data hoarding, and access to restricted files. None of those teams, working alone, sees the full picture. The threat signal is almost always distributed across functions that don’t routinely share context. 

A multidisciplinary insider threat team brings all of those perspectives to one table. That means security, HR, legal, IT and cyber, and in some cases communications and operations, depending on the organization. The goal isn’t to expand surveillance. It’s to make sure that when the pieces of a concerning pattern exist inside an organization, someone is in a position to connect them. 

BTAM programs are built for exactly this kind of multidisciplinary assessment. The infrastructure already exists in organizations that have invested in threat management. Extending it to include insider risk isn’t a rebuild. It’s a conversation that should already be happening. 

Where do organizations start? 

Jameson Ritter’s read on where this is heading: over the next five years, insider risk and behavioral threat management will merge into one program rather than two sides of the house. The organizations getting ahead of it now are the ones expanding their threat management teams to include cyber and IT representation, building information-sharing protocols across functions, and treating behavioral signals as relevant regardless of whether they appear in an HR file, a disciplinary record, or a system log. 

The first step is simpler than most organizations expect: convene security, HR, legal, IT and cyber, and operations to review one recent concern through a shared insider-risk lens, then decide what information should have been visible earlier and who needed to be at the table. 

One house. A wider table. 

A resource worth reading this September 

CISA’s 2026 Insider Threat Mitigation Guide is the most current federal guidance available on building and sustaining an insider threat program. Released September 9, 2026, it addresses the realities of hybrid work, AI, and adverse separations, and it reinforces the multidisciplinary framing that effective programs require. It’s a practical starting point for any organization that wants to move from awareness to action. 

Interested in this type of training? See all our available training–in-person, virtual, and eLearning–in our training catalog.

Similar Posts