- Overview
- Who is this guidance for?
- Resources
- Research overview
- Key findings
- How do you help leaders understand the threat?
- How do you position insider risk, so leaders engage?
- Which levers encourage a leader to act on insider risk?
- How do you make your insider risk plans more appealing?
- Think about insider risk: a checklist
- Further resources
- Annex
This guidance is also available as a PDF: Insider Risk: A Guide to Influencing Leaders
Overview
Who is this guidance for?
This guidance is for security professionals who want to set up an insider risk programme. NPSA defines insider risk as, “the likelihood of harm or loss to an organisation, and its subsequent impact, because of the action or inaction of an insider”.
If you want to get leadership on board with your insider risk programme, we can help. Drawing on extensive NPSA research into executive attitudes and behaviours, we have shared compelling insights to help you explore possible ways forward.
So, you can work out the best way to succeed.
Resources
Care is taken to build on (but not repeat) the wealth of freely available and intelligence-led advice on our dedicated content hub: npsa.gov.uk/insider-risk
60% of organisations don’t have insider risk policies and procedures that are formalised or followed1. Lack of leadership support is seen as a potential barrier to making that change.
1 NPSA (2023) Insider events. A communication guide to reduce their impact
Research overview
NPSA interviewed over 250 senior decision makers from a range of sectors to assess their current understanding of insider risk. Our aim was to understand the attitudes and behaviours that frame how they engage with, and act in relation to, their organisation’s risk of insider events. We looked at what could persuade them to better engage with the threat and which resources they would find most helpful.
Interviewees included those operating at executive board level and their seconds-in-command.
The findings shared a common thread. Insider risk is seen as an important issue to be tackled, but it’s hard to get senior decision makers to approve the resources required to manage it.
Security professionals who can help make insider risk real and relevant to their organisation are much more likely to get leadership support.
Key findings
- The research identified a gap between leader confidence in their existing capabilities compared to the actual robustness of the plans they have in place.
- Only 20% saw ‘insiders’ as a threat to their organisation. Insider events are seen as a collection of unrelated or irrelevant incidents. This leads to a piecemeal approach.
- Leaders are uncomfortable believing that ‘their people’ could intentionally seek to cause harm.
- The term, insider risk, is viewed unfavourably by non-security professionals.
- Many place disproportionate faith in their people or systems to detect and prevent incidents.
- Insider risk programmes can be dismissed as unnecessary bureaucracy.
Making insider risk real and relevant
- 2/3 have a low understanding of the potential threat.
- 69% don’t believe their assets are at risk.
- 80% don’t see insiders as a threat to their organisation.
- Confidence gap between executives and their seconds-in-command between existing capabilities and the actual robustness of the plans in place.
- 58% are more likely to engage when insider risk is framed as a specific risk (not a cluster of threats).
- Only 14% prioritise insider risk compared to cyber-attacks.
- Insider events are seen as a collection of unrelated, or irrelevant incidents. This leads to a piecemeal approach.
- Few see all insider events as relevant to them.
- The idea that staff would act against the organisation is unpalatable.
- Sense of complacency that insider events could happen in their workplace.
- The term insider risk is viewed unfavourably by non-security professionals.
- Many place disproportionate faith in their people or systems to detect and prevent incidents.
- Confidence gap between executives and their seconds-in-command.
- IR is easy to dismiss as unnecessary bureaucracy.
- Executives are much more likely to see time as a constraint.
- Financial and reputational damage are the strongest motivators for action.
- Appetite for tailored, proportionate solutions built from within your organisation.
- Desire to assign clear responsibilities across functions.
Interventions that most senior leaders find most helpful:
- Peer-to-peer recommendations and experience.
- Cross-board collaboration to provide more integrated decision making.
- Case studies on best practices.
How do you help leaders understand the threat?
- Leaders agree that insider risk preparedness is important in theory.
- This doesn’t mean an organisation will have formal procedures that are widely followed.
- Experiencing an insider event helps leaders prioritise threat, but few organisations claimed to have encountered one.
- Together this all leads to a low threat perception and a piecemeal or incomplete approach to managing it.
The research identified a gap between leader confidence in their existing capabilities compared to the actual robustness of the plans they have in place.
- 84% of leaders felt confident to prevent and respond to insider events, yet only 57% said they had formal policies and procedures in place to address the risk that were being widely followed.
- 84% of leaders agreed that being prepared helps build a psychologically and physically safe workforce.
- 72% agreed that preparedness helps enhance long-term profitability.
- 65% agreed that being prepared is essential for safeguarding corporate reputation.
For many, insider risk seems remote and unlikely. This in turn makes it easy to underestimate. Those who had experienced an insider event were much more likely to prioritise the threat. However, this was less than half of respondents. As a result, only 20% saw ‘insiders’ as a threat to their organisation, with two-thirds having only a basic understanding of the topic.
Data also suggests that around a third of risk registers don’t explicitly address insider risk, grouping it up into other incidents. This leads to managing insider events in an ad hoc and, sometimes, ineffective way.
To make insider events feel real, think:
- How could you recreate the experience of an insider event in your organisation?
NPSA simulations have proven to be an effective way of bringing multiple stakeholders together to test responses in a safe environment. Check out the free and easy-to-use resources, page 19. - How can you make your insider risk specific?
Leaders want to safeguard priority assets. Looking at your organisation’s priorities, how could insider events harm these? Would framing your discussions in highly specific examples help you secure support? - How can you use everyday language to better engage a non-security audience?
Using words like leaking (unauthorised disclosure), fraud (process corruption) or preventing unauthorised access (facilitated third party access), may be easier for non-security professionals to understand. Linking events to priority assets helped make it feel real.
How do you position insider risk, so leaders engage?
- Insider events are not something that leaders prioritise as a significant threat to their business.
- Insider risk is seen as a collection of unrelated or irrelevant incidents, leading to ad hoc, piecemeal and siloed solutions.
- There’s disbelief and complacency that insider events ‘could happen here’.
- Many, don’t feel comfortable thinking that their staff would intentionally act against the organisation. There is over-confidence in existing systems.
Compared to priority threats like cyber-attacks and protection of organisational and personal data, insider risk was rarely prioritised (14%)2. Most (69%) did not believe that their assets were at risk from insider events.
The breadth of incidents clustered together can make the threat feel intangible. Viewed as a collection of seemingly unequal (and unconnected) acts, insider risk lacks relevance. Incidents like sabotage are dismissed as improbable, while process corruption - fraud - was managed in silos. A lack of understanding about how insider events could happen, especially in technical areas like IT, reinforces perceptions of low probability.
There’s a disproportionate confidence in existing HR systems, like pre-employment screening or off-boarding, to prevent an insider event from happening. Leaders are uncomfortable believing that ‘their people’ could intentionally seek to cause harm.
Staff are often viewed in relational terms, and the thought that they would intentionally act against the organisation is unpalatable. In this context, the term ‘insider risk’ is viewed unfavourably by non-security professionals.
To make insider risk feel relevant, think:
- How can you promote the protective effect of your people?
Positively framing how your people can help prevent and detect a potential insider event may be more effective than generic threat awareness. - How might leaders engage with insider events if you communicated their relational aspects?
We found that leaders hold their staff in positive esteem. If an incident was seen as a potential outcome of not displaying a duty of care or a welfare issue left unresolved, would this help leaders better understand and get behind a plan of action? - Are there ways to build cross-functional collaboration?
Insider risk needs different experts to work together. By identifying opportunities to share responsibilities across HR, IT, Legal, can you build understanding and more regular opportunities to collaborate?
Which levers encourage a leader to act on insider risk?
- Executives are more confident than their seconds-in-command in the preventative measures they have in place.
- Insider risk programmes can be dismissed as unnecessary bureaucracy.
- Leaders believe they can adequately respond to insider events that happen.
- They were more engaged when risk was specifically defined.
- Action is motivated by financial consequences and reputational damage.
We found that leaders place disproportionate faith in their people and systems to detect and prevent incidents. The majority (84%) is confident in their ability to prevent and respond, yet only 51% say they have formal policies and procedures in place.
Insider acts are difficult to define. Organisational needs vary by sector and size, but leaders were more likely to engage when insider risk was defined through specific risks they prioritise. Most (58%) said that clear communication on what insider risk is and why it matters to them, would help them better address the threat.
Insider risk programmes can be dismissed as unnecessary bureaucracy. Some leaders suggested that penalties or recovery plans may cost less than prevention.
“It hasn’t happened here, and it probably won’t happen here” thinking contributes to a lack of prioritisation. Low experience of insider events is a contributing factor. Focusing on the financial consequences along with the prospect of costly reputational damage helped convince leaders to press for stronger insider risk policies.
To make insider risk feel real and relevant, think:
- How can you explain what an insider event would cost your organisation?
NPSA’s Asset Cost Estimation Tool (ACET) helps estimate the financial impact of a security incident. When another organisation experiences an event, how might you communicate their reported losses internally - Can you highlight possible improvements to your existing processes?
Could internal round table forums help signpost and improve on current measures? It might be something as simple as discussing ‘vetting processes of the future’. NPSA’s Personnel Security Maturity Assessment (PSMA) tool will help you identify weaknesses in your policies and procedures and provide helpful guidance on how to improve. - How might you incorporate insider risk into your existing governance processes?
Could you highlight easy adaptations by bringing together functional leaders from HR, Legal, IT and Communications to review existing people processes through an insider risk lens? - Can you make the consequences of an insider event feel real?
Using simulation exercises might help bring home the real-world impacts of an insider event to your leaders. NPSA has developed a range of helpful exercises that can be customised to your organisation. Many are free.
How do you make your insider risk plans more appealing?
- Insider risk can be a difficult (intangible) concept for executives. This prevents their seeing it as abstract, or a series of smaller, unlikely issues. NPSA’s Personnel Security Maturity Assessment (PSMA) tool can provide an assessment of your organisation’s personnel security maturity to help you formulate bespoke improvement plans to share with seniors.
- Seconds-in-command find it harder to prioritise insider risk because of resource scarcity (time and money).
- Gold-standard approaches can be unwieldy and might feel unnecessary. Make plans specific to your risk.
- Peer-to-peer recommendations, integrated board-level decision making and case studies can increase executive support.
To increase the likelihood that leaders support insider risk measures, we recommend two approaches: First, make the threat feel real for executives; then create a solution that feels relevant for their seconds-in-command.
Insider risk programmes can be seen as unwieldy and bureaucratic with no single owner. Exhaustive, gold-standard plans only added to this impression. Instead, research showed that focusing on specific risks to deliver a proportionate plan was viewed more positively.
Peer-to-peer recommendations and experience was considered helpful in securing executive support. Leaders valued evidence of integrated board-level decision making, so finding ways to integrate other functional leaders in plans was seen favourably.
Reviewing real-world incidents drove threat engagement. Case studies from industry, helped quantify the threat, and provided learning opportunities. Holding learning reviews of how another organisation handled insider events was seen to be valuable. Senior leaders valued tools to prove the financial ROI of insider risk programmes.
To make insider risk feel relevant, think:
- How might you synthesise the most important aspects of your plan?
- Who in your organisation could help make your plans better? What do they need to hear to get involved?
- How might you use case studies to educate and inspire colleagues in relevant departments to make the threat real?
- How can you share responsibilities across functions to demonstrate more integrated decision making?
- Within your sector, can you find ways to share experiences and recommendations with peers?
Are there closed industry forums where you could share peer-to-peer leadership insights in a trusted setting? How might you help assess your relative capabilities?
Think about insider risk: a checklist
- How could you recreate the experience of an insider event in your organisation?
- How might you define your insider risk?
- How could you use everyday language to engage a non-security audience?
- How can you show what an insider event would cost your organisation?
- How could you make the consequences of an insider event feel real?
- Within your sector, can you find ways to share your learnings with peers?
- How might you promote the protective effect of your people?
- Are there ways you can make insider acts relatable?
- How could you discuss process limitations in a dynamic way?
- How might you incorporate insider risk into your existing governance processes?
- How can you find ways to build cross-functional collaboration and decision making
- Who in your organisation could help make your plans better? What do they need to hear to get involved?
- How might you synthesise the most important aspects of your plan?
Further resources
For effective security risk management, an organisation should have defined governance and oversight of its protective security management systems. The principles laid out in this model help guide strategic decision making. Organisations should consider their critical assets and the key threats faced in shaping a response.
Visit NPSA’s dedicated hub to access expert resources, guidance and training materials to build organisational resilience. Along with authoritative advice, it contains free educational campaign materials that can be downloaded, and a library of insider event case studies.
NPSA has developed innovative, immersive exercises to give you a better idea how an insider event might play out in your workplace. This allows you to test your crisis communications response, using effective communication to break down organisational silos.
ACET NPSA’s Asset Cost Estimation Tool (ACET) has been developed to help organisations understand the financial impact from the loss of an asset, following a security incident. The tool is free to access.
The NPSA self-service Personnel Security Maturity Assessment (PSMA) is designed to specifically assess an organisation's personnel security maturity. This is a key factor, in addition to physical and cyber security measures, in strengthening an organisation's resilience to insider and wider external security threats. Security professionals can use the results of an assessment to report up to seniors areas of weakness and share improvement plans.
Annex
| Insider | Any person who has or previously had authorised access to or knowledge of the organisation’s resources, including people, processes, information, technology and facilities. |
| Insider risk | The likelihood of harm or loss to an organisation and its subsequent impact because of the action or inaction of an insider. |
| Insider threat | An insider or group of insiders that either intends to or is likely to cause harm or loss to the organisation. |
| Insider event | The activity, conducted by an insider (whether intentional or unintentional), that could result in or has resulted in harm or loss to the organisation. |