Skip to content

Setting the foundations: Five principles for a shared approach to Insider Risk

  • Knowledge Level: Introductory
  • Protection Stage: All Stages
  • Time to read:

This webpage outlines five key principles underpinning NPSA advice and guidance

Last Updated: 11 March 2026
Share this article:

Setting the foundations: Five principles for a shared approach to Insider Risk - This document is available to download as a PDF

Introduction

With 25 years’ experience in personnel and people security, the National Protective Security Authority (NPSA) has developed insider risk advice and guidance, leveraging unique insights and partnerships from government, industry and academia in the UK and internationally.

Whether new to the field or experienced security practitioners, audiences need a clear and consistent understanding of key concepts related to insider risk.

This paper outlines five key principles underpinning NPSA advice and guidance, including:

Principle 1: Adopting a shared language

NPSA provide definitions to encourage consistency and highlight that both unintentional and intentional insider events can cause harm to organisations. 

Principle 2: Broadening our understanding of potential insider threats 

Categories of the most common insider events are included. They widen the frames of reference when considering the breadth of assets that need protecting and the range of potentially relevant insider events.

Principle 3: Considering the ‘spectrum of intent’: unintentional to intentional insider activity

Our message, ‘If you have people, you have insider risk’ challenges assumptions that insider risk solely relates to those who intentionally set out to cause harm. The spectrum of intent demonstrates holistic, organisation-wide systems aiming to reduce both intentional and unintentional insider events. These should target both unintentional and intentional insider risk, support staff resilience and build engagement in security.

Principle 4: Detecting signs of and de-escalating insider risk

Reviews of known cases demonstrate that signs, across the critical pathway to insider risk, are visible to the organisation. There are opportunities to intervene early to help mitigate and reduce insider risk before it manifests or escalates.

Principle 5 The foundations for effective interventions

In this section we provide frameworks focusing on what drives insider risk and implications for mitigations. Key considerations are effective security culture and measures that shape the environment to limit the opportunities for insider events to take place, whether intentionally or unintentionally.

Principle 1: Adopting a shared language

The definitions provided are designed to help bring about understanding of complex concepts relating to insider risk, insider events and learning from known cases. These should be viewed as technical definitions for practitioners. How these are used to inform organisational communications about insiders and insider risk will vary and be tailored according to specific audiences and organisational objectives.

Everyone with and those who have had access – even those in your supply chain – can pose a risk to the organisation: ‘If you have people, you have insider risk’.

  • Insider - Any person who has, or previously had, authorised access to or knowledge of the organisation’s resources, including people, processes, information, technology, and facilities.
  • Insider Risk - The likelihood of harm or loss to an organisation, and its subsequent impact, because of the action or inaction of an insider.
  • Insider Threat - An insider, or group of insiders, that either intends to or is likely to cause harm or loss to the organisation.
  • Insider Event - The activity, conducted by an insider (whether intentional or unintentional) that could result in, or has resulted in, harm or loss to the organisation.

Definitions set the ground rules for shared understanding. Without them, the same terms can be interpreted differently, leading to confusion. Organisations are therefore encouraged to use the NPSA definitions outlined above when assessing and managing insider risk.

Principle 2: Broadening our understanding of potential insider threats

Organisations adopt a narrow perspective when considering the range of potential insider events and sometime fail to consider all the ways in which insiders can cause harm.

NPSA has grouped common insider events into five categories (as seen in Figure 1) noting that these are not exhaustive.

Furthermore, inside events can feature multiple acts; for instance, facilitation of unauthorised access can lead to sabotage or violence.

Types of insider events: Unauthorised disclose or Theft or Information, Process corruption, Violence, Facilitation of unauthorised access, sabotage

Figure 1: Types of insider events

  • State espionage – e.g. passing information that may provide an advantage to another government, state, or foreign intelligence service;
  • Corporate espionage – e.g. unauthorised disclosure of Intellectual Property (IP) to another company or competitor;
  • Personal theft of IP – e.g. taking IP for personal use, such as future employment or to sell for personal gain;
  • Media disclosure – e.g. giving information to a media organisation.
  • Fraud – e.g. deception to secure unfair or unlawful gain;
  • Criminal facilitation – e.g. using an organisation’s data to facilitate organised crime;
  • Abuse of power – e.g. using official authority gained through the organisation for personal gain;
  • Malign influence – e.g. use of subversive, deceptive, or coercive methods to manipulate attitudes, perceptions or behaviours to advance their interests or objectives.
  • Sexual or violent crime– e.g. using privileged access to facilitate an attack against another person.
  • Terrorism – e.g. using inside access to facilitate or carry out terrorism;
  • To a physical building or asset – e.g. enabling unauthorised access to physical assets;
  • To IT systems – e.g. enabling unauthorised access to corporate or restricted networks or systems;
  • To people – e.g. enabling privileged access to people for the purpose of gaining unauthorised, inappropriate or potentially harmful influence.
  • Physical sabotage – e.g. physically damaging assets;
  • Electronic sabotage – e.g. reducing the availability, integrity or confidentiality of data on IT systems, deleting data on a server;
  • Reputation sabotage – e.g. intentionally undermine reputation of an organisation by spreading false information

Principle 3: Considering the ‘spectrum of intent’: unintentional to intentional insider activity

NPSA research has shown that only a small minority of people are intentionally seeking to cause harm to their organisation. However, the risk of harmful action (or inaction) by those lacking any intent can also have long-lasting and widespread impact. NPSA describes a ‘spectrum of intent’ (see Figure 2) which includes the harming potential of unintentional insiders. The spectrum highlights the need for interventions to extend beyond measures, such as pre-screening and detection of intentional insiders, to include systems that support well intentioned staff to be resilient and engage in effective security.

The spectrum of intent to cause harm, running from unintentional to intentional

Figure 2: The spectrum of intent to cause harm

 

Organisations should use the spectrum of intent to broaden their approach to reducing insider risk, moving beyond a focus on only intentional threats.

Principle 4: Detecting signs of and de-escalating insider risk

Learning from reviews of known insider events highlights that the risk evolves over time and there are often visible signs and (potentially multiple) chances to detect and disrupt potential insider threats.

Here, we introduce the critical pathway to insider risk framework1 (summarised in Figure 3) as a means of highlighting opportunities to identify issues and intervene early to de-escalate them before they evolve into insider events. This helps explain why and how someone who legitimately joins an organisation, without any intention of committing an insider act (a self-initiated insider), ends up causing harm to the organisation.

The pathway outlines four aspects that can increase insider risk in these individuals and/or how these may show out in the workplace.

1 E. Shaw and L. Sellars, Application of the Critical Path Method to Evaluate Insider Risk, Studies in Intelligence, vol.59, no.2, June 2015 & Shaw, E.D. (2023). The psychology of insider risk. CRC Press.

  1. Personal predispositions - These are intrinsic traits or past experiences, such as personality disorders, a history of rule violations, or social network risks, that make an individual more susceptible to risk. They represent the underlying vulnerabilities an employee brings into the organisation.
  2. Stressors - These are significant life events that trigger or “squeeze” an individual’s predispositions. Such pressures can push an employee further down the pathway toward potential malicious intent.
  3. Concerning behaviours - These are observable indicators in the workplace that signal an escalation of risk. Most insiders exhibit these smaller warning signs long before committing a serious act.
  4. Problematic organisational responses - When an organisation either ignores warning signs or responds in a maladaptive way, such as through inconsistent or heavy-handed discipline. Such failures to intervene effectively can further alienate the employee and solidify their trajectory toward a harmful act.

Critical Pathway to Insider Risk, adapted from Shaw

Figure 3: Critical Pathway to Insider Risk, adapted from Shaw1

Taken as a whole, the pathway describes a ‘perfect storm’ whereby individuals with vulnerable personal predispositions go on to experience stressors in their lives. These stressors may be associated with personal predispositions (e.g. poor social skills contributing to workplace conflict).

Personal predispositions, such as a lack of resilience can also exacerbate stress. When an individual is not coping with stressors this can become evident through visible concerning behaviours. If these are not identified/or managed effectively (problematic organisational responses) then this can lead to a cycle of increased stress and progression along the pathway, ultimately an increased risk that the individual may become an insider threat.

The majority of people who appear on the pathway will not go on to become insider threats. Indeed, they may become disengaged, display other counter-productive workplace behaviours and disgruntlement or simply leave the organisation. However, insider threats do not emerge without warning (as illustrated in Figure 3).

Organisational responses can either exacerbate and accelerate individuals along the pathway to insider risk, or interventions can divert people off the pathway before an insider threat emerges or escalates.

Strong organisational influence helps individuals move off the critical pathway to becoming an insider threat. Organisations should review how effective their current response is and plan improvements to reduce risk before it escalates.

Principle 5: The foundations for effective interventions

To help design effective interventions that help reduce insider risk in organisations, we first need to understand how behaviours that result in unintentional or intentional insider events come about. This section helps understand human behaviours in the context of insider events and how we can use this to develop effective mitigations.

Human motivation is complex and individuals responsible for insider events may struggle to articulate or be unaware of the factors that motivate their behaviour. Motivations are influenced by both personal and external drivers as highlighted in Figure 4. Personal drivers may be automatic and unconscious (e.g. needs, habits, emotions) or reflective and conscious (e.g. values, goals, consequences). External drivers may include organisational factors (e.g. pay, management perceptions)and wider environmental factors (e.g. global conflict, financial challenges).

A representation of human motivation drivers, both external and personal

Figure 4: A representation of human motivation drivers

Capability Opportunity Motivation and Behaviour framework, in context of insider risk

Figure 5: Capability Opportunity Motivation and Behaviour (COM-B) in context of insider risk, Adapted from West and Michie’s COM-B framework2

Motivation alone is not sufficient to trigger behaviours associated with an insider event. For any behaviour to take place, a sufficient degree of capability and opportunity are also required (see Figure 5)2.

Capability refers to the skills, knowledge, and abilities (including both psychological and physical) that are demanded on the individual for the behaviour to take place.

Opportunity refers to the environment and the extent to which it facilitates the behaviour. This includes both the physical environment (e.g. physical access), digital environment (e.g. access to information), and social environment (e.g. organisational culture).

These three components do not sit in isolation. If someone has high capability and opportunity, then the motivation may not need to be as great; whereas a highly motivated person may seek out or enhance their capability or opportunity.

Similarly, a very capable individual may be able to operate in a less conducive environment (i.e. low opportunity), or an easy environment may allow the behaviour from a less capable actor.

When thinking about mitigations for insider risk, the utility of the COM-B model2 is twofold. It can be used for understanding and disrupting the components of unwanted behaviours (i.e. reducing or limiting capability, opportunity and/or motivations for harmful behaviours). It can also be used to increase the likelihood of desirable behaviours (i.e. increasing capability, opportunity, and/or motivation to elicit behaviour).

2West & Michie, A brief introduction to the COM-B Model of behaviour and the PRIME Theory of motivation (2020)

Organisations should consider how their workforce can support organisational security and how to encourage secure behaviour. NPSA’s ‘5Es Framework’, based on behaviour change theory, outlines key steps for improving and sustaining security behaviours. NPSA has a free online Security Culture Tool to help assess and strengthen your organisation’s security culture.

Did you find this page useful?
helpfulness rating