The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has refreshed its flagship Insider Threat Mitigation Guide for the first time since 2020, and the timing is not incidental.
The revision lands as organizations wrestle with hybrid workforces, a fast-growing population of AI agents operating inside enterprise environments, and—as it happens—a recent controversy involving CISA's own acting director uploading sensitive contracting documents to a public version of ChatGPT under a temporary DHS exception. That episode isn't referenced in the guide itself, but it underscores exactly the kind of everyday, credentialed, non-malicious risk the update is trying to address.
CISA says the resource update was informed by industry and government partner feedback, and consolidates the guide into a more streamlined format while adding new case studies and statistics. Scott Breor, CISA's acting executive assistant director for infrastructure security, framed the update as a response to an evolving threat landscape, urging organizations to build programs that "protect key assets, prevent violence, reduce losses, safeguard sensitive data, and save lives," and crediting industry and government partners for informing "this timely update."
The substantive additions fall into a few buckets:
Hybrid and remote work – The guide now addresses how distributed work has eroded the clean boundary between physical and digital access control—an organization's perimeter is no longer a badge reader at the front door.
Artificial intelligence – CISA's AI content is narrower than the framing might suggest: it covers AI used to manipulate or deceive employees, not a broader assessment of AI's role in insider risk generally (including the exposure from machine identity and agentic AI that several practitioners below say is the more urgent gap).
Access control and visitor screening – Renewed emphasis on physical-side fundamentals.
Adverse employee separations – Guidance on managing the elevated-risk window around involuntary or contentious departures.
"Insider threats continue to evolve as technology becomes more advanced. We urge organizations to establish a mitigation program that protects key assets, prevents violence, reduces losses, safeguards sensitive data, and saves lives," said Breor. "CISA appreciates the industry and government partner feedback that informed this timely update. CISA encourages organizations to review this updated guide, assess their program, and recommended steps to bolster their threat mitigation program."
First published in 2020, the guide is aimed at security and HR professionals running insider threat programs, plus organizational leaders more broadly, and CISA positions it as usable "regardless of the maturity" of an organization's existing program. Recent industry research cited alongside the release paints a sobering baseline: 41% of organizations reported their most serious insider incident cost between $1 million and $10 million, with another 9% reporting even higher losses, and 77% experienced insider-related data loss over the prior 18 months—21% of those with more than 20 incidents in that window.
CISA's decision to scope its AI content specifically to manipulation and deception—phishing-style social engineering, deepfake-assisted pretexting, and the like—is a reasonable, bounded starting point. But, it's worth being direct about what the guide does not yet cover: the insider risk created by AI systems themselves, as opposed to AI used against employees. That's the gap several security leaders flagged when asked to weigh in on the update, and it's a meaningful one given how quickly agentic AI and machine identities have proliferated inside enterprise environments over the past year.
Aviv Nahum, co-founder and CEO of Above Security, welcomed CISA's move away from the outdated stereotype of insider risk as "a disgruntled employee stealing files on the way out," noting that an insider can just as easily be "compromised, coerced, or completely unaware that they are helping an attacker." His sharper critique is structural: most organizations still treat insider risk as an incident-response problem, reconstructing the story only after HR or Legal raises a flag. That model, he argued, doesn't scale; organizations need continuous, contextual understanding of behavior "before a concern becomes a breach," and the work has to sit across Security, HR, Legal, and the business rather than living entirely in the SOC.
Rex Booth, CISO at SailPoint, pushed the definition of "insider" further than CISA's guide explicitly goes, arguing that the category now includes "machine accounts or AI agents operating within the enterprise" alongside contractors, vendors, and partners. His point about detection difficulty is the crux of the problem: when someone, or something, is using legitimate credentials, "it's incredibly difficult to decipher whether their actions stem from malicious intent, a simple human mistake, or a compromised account." Booth's prescription leans on identity fundamentals: unified, continuous visibility across the identity ecosystem rather than point-in-time access reviews.
Morey Haber, Chief Security Advisor at BeyondTrust, offered the most granular breakdown, splitting insider incidents into malicious, negligent, and compromised categories—and flagging the compromised-credential path as the one that "many modern ransomware campaigns" now use as an initial entry point rather than perimeter exploitation. Haber's most pointed comments concerned non-human identities: organizations are deploying autonomous AI agents with broad, often persistent permissions, and when those systems lack secure-by-design governance, they can expose data or take action "beyond their intended scope" without any human intent involved at all. His recommendations track a familiar identity-security playbook—least privilege, just-in-time access, and continuous behavioral analytics—but applied explicitly to AI agents and service accounts, not just human users.
[RELATED: How Over-Permissioned AI Is Quietly Dismantling ID Infrastructure]
Mika Aalto, co-founder and CEO of Hoxhunt, reframed the problem in probabilistic terms: insider threats aren't "needles inside haystacks," he said, but "needles in boxes of needles," because the population you're monitoring is made up of authorized users doing their actual jobs. His critique is aimed at the industry's historical response to that ambiguity—"fear-based monitoring and punitive, once-a-year-or-quarter compliance training"—which he says has failed to change behavior. Aalto's alternative rests on behavioral science and real-time, in-the-moment coaching rather than surveillance, treating employees as "an active, intelligent human sensor network" rather than a liability to be policed.
Carl Windsor, CISO at Fortinet, grounded the discussion in the mundane reality of how most insider data loss actually happens: not dramatic sabotage, but routine negligence—a sensitive file emailed to the wrong address, a USB transfer, an upload to personal cloud storage, or reliance on unsanctioned SaaS or AI tools. His operational guidance emphasized visibility across GenAI usage specifically, behavioral analysis rather than simple movement-tracking, and treating everyday collaboration tools as the primary egress points that need protecting.
Strip away the vendor framing and a consistent thread runs across all five perspectives: the definition of "insider" has expanded faster than most governance programs have adapted. Contractors and remote employees were yesterday's expansion of the attack surfacer; AI agents, service accounts, and autonomous workflows are today's. CISA's guide, understandably, is scoped to the workforce-management and physical-security fundamentals it has always covered—behavioral indicators, HR coordination, separation risk. It is not, and doesn't claim to be, a governance framework for agentic AI or non-human identity, and organizations that treat it as covering that ground will have a blind spot.
That's not a knock on the update itself, which fills real gaps around hybrid work and AI-enabled social engineering. Rather, it's a reminder that the practitioner community currently sees two distinct and only partially overlapping insider-risk problems: the traditional one CISA's guide addresses, and the identity governance problem created by autonomous systems operating with delegated privileges—a problem that, on the evidence of the commentary above, most enterprise programs are not yet built to handle.