It’s time to rethink what we mean by insider risk

Anna Borgström

CEO | NetClean

Cybersecurity has become increasingly sophisticated at detecting malware, suspicious network activity and compromised credentials. Yet some of the most serious risks an organization faces can originate much closer to home – with the people who already have legitimate access to its systems, information and infrastructure. Insider risk is not a new concept. But I believe our understanding of it has become too narrow.

Insider risk is more than malicious intent

The traditional view of insider risk often centers on employees deliberately stealing data, committing fraud or sabotaging their employer. These are serious threats, but they represent only part of the picture.

An individual does not need to intend to harm their organization to create a security risk. Personal behaviors and vulnerabilities can expose both the individual and their employer to coercion, compromise or exploitation – particularly when that person has access to sensitive information, systems or critical infrastructure.

At NetClean, more than 20 years of detecting child sexual abuse material on corporate devices has given us a unique perspective on this type of risk. It has shown us that serious human-risk signals can exist inside organizations while remaining largely invisible to conventional cybersecurity tools.

The landscape is expanding

Today, we see that challenge extending into new areas. Terrorist and violent extremist content is one example.

Radicalization increasingly takes place in digital environments, and extremist material can appear on the same devices and infrastructure people use in their professional lives. When this involves someone with access to sensitive systems, information or critical infrastructure, it can become more than a societal or law-enforcement concern. It can also represent an organizational security risk.

Recognizing these risks does not mean organizations should monitor everything employees do. Effective human-risk detection should be precise and proportionate, focused on clearly defined high-risk indicators based on verified intelligence rather than attempting to interpret or profile ordinary human behavior.

Security teams already have more alerts than they can manage. Human insider risk cannot become another source of noise. What organizations need are high-confidence signals that identify serious risk and provide enough context to act.

The insider risk landscape is expanding. Our definition of cybersecurity needs to expand with it.

A blind spot cybersecurity can no longer ignore

Most cybersecurity technologies are designed to recognize technical threats: malicious code, unusual network activity, compromised credentials. They were not built to identify many of the human-risk signals that may exist within an organization.

As technical defenses become stronger, this blind spot becomes harder to ignore. For NetClean, this is why our mission is evolving. We are expanding our detection capabilities to include terrorist and violent extremist content alongside child sexual abuse material. It is an important step for us, but it also reflects something bigger.

The next generation of cybersecurity must help organizations understand not only the threats targeting their systems, but also serious human vulnerabilities that can create risk from within – while maintaining accuracy, proportionality and respect for privacy.

The insider risk landscape is expanding. Our definition of cybersecurity needs to expand with it.

Our mission just got bigger

NetClean is expanding ProActive to detect terrorist and violent extremist content (TVEC), adding a new category of human insider risk detection alongside CSAM. Read the launch announcement →

Want to understand what emerging human-risk signals could mean for your organization? Talk to our team →