by Ryan Nobili & Paul Curby

What does Insider Threat mean to you?
Is it something that is regularly on your mind? What risk does it present to you and your particular organisation? The risk will vary depending on your organisation. For instance, an organised crime group infiltrating a police force, a bank or government will provide the perpetrator with different opportunities.
The reality is that insider threat is a serious security issue that looks different in every organisation. The risk ultimately depends on who has access and to what extent, which determines the severity of misuse. That is why understanding our own environment is key to mitigating the risk of insider theat.
The purpose of this article is to highlight some of the dangers posed by insider threats and to outline controls that can be implemented to reduce these risks.
Who is an Insider Threat?
Accidental Insider: A person who accidentally exposes the company to external threats. This is typically due to poor cyber hygiene practices, lack of cyber awareness training and lack of oversight by supervisors. This person is not a malicious actor. An example of this type of insider would be an employee clicking on a link sent to them by a cyber attacker, failing to recognise a phishing scam.
Negligent Insider: This is a person who intentionally exposes the company for their own, or a third party’s benefit. This will occur if the insider senses a vulnerability in the company’s security system and/or practices, capitalising on a lack of adequate security measures.
Malicious Insider: A person who capitalises on access or security gaps within a system with the intention of copying or removing data, commit fraud and may collaborate with external actors. For instance, a malicious insider might attempt to acquire colleagues’ credentials, particularly in situations where multi-factor authentication is not implemented during the login process.
What is the Impact of Insider Threats on Businesses?
Insider threats pose a significant concern for businesses due to the risk of financial and reputational damage. The Association of Certified Fraud Examiners (ACFE) 2024 report revealed that occupational fraud is the largest and most costly form of financial crime. Occupational fraud is made up of three branches – Asset misappropriation, corruption and financial statement fraud. Annual losses related to these schemes are estimated to be in the trillions of dollars.
In short, the risks associated with insider threat mostly come from the ease at which employees can access workplace tools and sensitive information. Remote work, mobile devices and Software as a Service (SaaS) platforms allow people to connect to data systems from almost anywhere. Whilst this is convenient and may improve efficiencies within a business, it also increases the chance of mistake or intentional misuse, especially if controls aren’t appropriately managed. Compounding this challenge is the growing difficulty in identifying when an insider fraud is taking place. As employees often have legitimate access to various business platforms, misuse can easily be disguised as standard activity, blurring the line between regular use and fraudulent activities.
How can organisations Control and Mitigate the risk of Insider Threats?
Employee Training and Awareness
Training sessions are an effective method of communicating with staff due to collective learning. Cyber hygiene, fraud awareness and code of conduct are all topics strong enough to headline an employee training module or seminar and are important to deter insider threats. Through adequate training, even the accidental insider can improve their ability to detect fraudulent activity and/or identify common cyber-attacks such as phishing and ransomware.
Identity and Access Management
Identity and Access Management (IAM) protects organisations from insider threats by restricting user permissions to only what is necessary, providing management with more oversight and reducing misuse risks.
Reporting Channels
Having accessible reporting channels plays a crucial role in deterring insider threats. If employees notice behaviour that could pose a risk from within the organisation, they need a safe way to report it. Whistleblower avenues must be easy to use, confidential, and widely promoted so staff feel protected when voicing concerns (Public Interest Disclosures for government-related bodies). Leadership teams should prioritise maintaining and reviewing these systems as part of a strong security strategy. This would not only enable greater oversight of potential threats but also foster a healthier workplace culture.
What is an example of an Insider Threat that has recently been in the news?
Let’s look at the real case of Peter Williams and its national security implications involving government and private sector risks.
The recent guilty plea by former defence contractor executive Peter Williams, for selling eight sensitive cyber exploits to a Russian broker, has sent shockwaves through the cybersecurity and intelligence communities. Williams, who previously worked for the Australian Signals Directorate, exploited his position of trust and sold classified tools intended for national security to a foreign actor. This case raises a critical question: Would the risks have been any different if Williams had been working directly in government, rather than in the private sector?
Insider threat, anywhere, is a real issue. A senior trusted individual who may misuse their relationships and access to information is a challenge to any organisation. Both government agencies and private contractors handling classified material face similar risks. You need access to the relevant information, motivation (financial or some other reason), a potential change of personal circumstances and to work in an environment that has complex detection and prevention challenges.
How these risks manifest and how they are managed may vary from business to business. There will be regulatory challenges as well as gaps in an organisation’s ability to monitor staff. Issue around reporting of suspicions by colleagues and an appropriate organisational response to any red flags identified. All businesses have to work on an element of trust with their staff. All businesses have to strike a balance between securing against the risk of unlawful access and theft, versus enabling people to do their work efficiently.
In the Williams case, were the operational guard rails in place sufficient? Were there any red flags that may have been raised and not have been adequately responded to? Were there any red flags ignored?
While we may never know the full extent in the lead up to the exfiltration of information, I am always reminded by a comment made by a senior executive to her CEO while discussing the merits I was pitching for a proactive fraud and corruption risk assessment. The CEO asked the senior executive for her opinion of the proposal and she responded, “Well, for me, I can only guarantee you my integrity for today, I don’t know what is going to happen tomorrow.”
The control environment in all businesses have loopholes that that can be exploited. For the most part employees, while they may know where the loopholes exist, they don’t exploit the weaknesses. But they also don’t tell anyone about the loopholes, unless they are asked.
Interestingly, in this case, the organisation Williams worked for, Trenchant, their whole business is structured to promote (and incentivise their staff) the finding of loopholes for exploitation. Williams exfiltrated information that he, and many other people, had access to and/or worked on. He operated outside of the guard rails. This type of activity is open to being done in both the government and private sector.
The risk of insider threat is real, evolving, and demands vigilance. The difference lies not in the risk itself, but in how you choose to mitigate it.
ABOUT THE AUTHORS
Ryan Nobili is an undergraduate and Analyst at CurbyMcLintock, and in his final year of completing his Bachelor Degree in International Security Studies.
Paul Curby is the founding Partner at CurbyMcLintock with over 35 years’ experience in the area of investigation, fraud risk and governance, including 15 years with law enforcement in Australia.
WHO IS CURBYMCLINTOCK?
CurbyMcLintock is a boutique forensic services firm that helps organisations respond to misconduct matters quickly and efficiently. We can undertake independent investigations where there are allegations of bullying, (sexual) harassment, fraud or other misconduct. Our philosophy is to leave an organisation in a better condition following our work.
CurbyMcLintock can also assist with mitigation strategies including training and risk reviews to build resilience to avoid an incident occurring in the first place (e.g. governance reviews, fraud risk reviews etc.). This includes the implementation and management of Whistleblower hotlines.
A proactive approach is a sensible and cost-effective method to prevent fraud occurring in the first instance. We typically find that organisations rely on standard controls supported by policy and procedures as the only line of defence against fraud. This is simply not enough, and your stakeholders and regulators expect you to take a more robust, proactive approach to protecting your organisation from financial loss and other associated risks.
CurbyMcLintock can assist you become fraud resilient by adopting a methodology which combines skilled interviewing techniques and tapping into the knowledge of your staff who are at the coalface of business operations, to help uncover where your organisation is exposed to internal and external fraud. We will then provide you with mitigation strategies to reduce the risk of a fraud

