September marks National Insider Threat Awareness Month (NITAM), a collaborative campaign led by the Defense Counterintelligence and Security Agency (DCSA) and the Center for Development of Security Excellence (CDSE) to emphasize the critical role of vigilance, reporting, and proactive risk mitigation. While organizations allocate massive budgets to keep external adversaries out, the most complex security challenges often originate on the inside—where users already hold valid badges, VPN credentials, and legitimate access.
Managing insider risk isn’t about running surveillance on your workforce or hunting for Hollywood-style sabotage. It’s about recognizing that the human layer is dynamic, vulnerable, and ultimately an organization’s greatest asset—while simultaneously understanding how emerging technologies expand the attack surface.
To mark NITAM 2026, three cybersecurity leaders from CyberProof share their distinct frontline perspectives on navigating this challenge:
- The Threat Hunting Lens: Kithu Shajil (Senior Threat Hunter & Incident Responder) explains why context, actionable telemetry, and psychological safety matter far more than dashboard vanity metrics.
- The Strategic Lens: Michael Restivo (Chief Revenue Officer) explores the business realities of human error and how shifting from suspicion to shared accountability transforms security posture.
- The SOC Analyst Lens: Amit Arad (Agentic SOC Lead) examines how rapid cloud and generative AI adoption redefine the perimeter, and why pairing AI behavioral analytics with analyst context is vital to scaling modern defenses.
The Ordinary Face of Insider Threat: Why Context and Trust Beat More Tools
Author: Kithu Shajil, Senior Threat Hunter & Incident Responder | CyberProof
What strikes me most about insider threat is how ordinary it usually looks. It’s rarely a mastermind plotting something dramatic, it’s a stressed employee forwarding company files to a personal email before a job change, a well-meaning admin reusing the same login everywhere, or an account that’s been quietly hijacked and is now doing things the real person never would. National Insider Threat Awareness Month matters because it puts the spotlight on the people side of security instead of just the technology, and it’s a reminder that the person behind the screen is both an organization’s greatest asset and its biggest variable.
That’s why the organizations that handle this well aren’t the ones running the most monitoring tools, they’re the ones that treat access as something to actively manage rather than something to set once and forget. That means real least-privilege enforcement instead of permissions that only ever grow, paying attention to specific behaviors that actually matter, like unusual data movement, off-hours access to sensitive systems, or remote administration tools showing up outside normal patterns, and having someone who actually acts on those signals instead of letting them sit in a dashboard. It also means not assuming insider risk is always about bad intent. A compromised account behaves exactly like a malicious insider from a detection standpoint, and plenty of programs miss that because they’re only looking for someone acting in bad faith.
None of this works without people who trust the process enough to say something when it looks off, and that’s really the point of a month like this. Insider threat programs live or die on whether someone feels safe flagging a colleague’s odd behavior, or their own mistake, before it turns into an investigation.
Holding the Door Open: Why the Human Layer Is Still an Attacker’s Favorite Target
Author: Michael Restivo, Chief Revenue Officer | CyberProof
Organizations spend millions defending against attackers trying to break in, yet some of the biggest risks already have a parking pass, VPN access, and an employee ID. That’s what makes National Insider Threat Awareness Month so important. Insider threats aren’t limited to the dramatic cases of disgruntled employees stealing data that often dominate Hollywood films. More often, they’re ordinary employees doing extraordinary things accidentally, like forwarding a sensitive file, approving a fraudulent request, or giving away information to a convincing imposter. Cybercriminals know people are easier to manipulate than technology, which is why the human layer remains their favorite attack surface.
The best organizations recognize that insider risk is ultimately a people challenge, not just a technology challenge. Awareness training, strong processes, and behavioral analytics all play an important role, but culture matters most. When employees feel responsible for protecting the business and empowered to speak up when something looks suspicious, insider threats become easier to prevent. The goal is not to create a workplace built on suspicion. It’s to create one built on shared accountability.
Hackers spend all day looking for a way in. Insider Threat Awareness Month is a reminder to make sure we’re not accidentally holding the door open for them.
The AI-Driven Insider: Balancing Innovation, Access, and Cloud Security
Author: Amit Arad, Agentic SOC Lead | CyberProof
Insider threats are no longer limited to the traditional image of a malicious employee. In today’s AI-driven workplace, risk often comes from trusted users making well-intentioned decisions, sharing sensitive information through new technologies, or operating with more access than they actually need. As organizations accelerate the adoption of AI and cloud services, visibility into user behavior and data interactions has become a critical component of cyber resilience.
The most effective organizations focus on reducing risk rather than policing people. This means enforcing least-privilege access, continuously reviewing permissions, promoting security awareness, and leveraging AI to identify behavioral anomalies that may indicate elevated risk. Security teams can no longer rely solely on static rules when user activity, collaboration patterns, and data movement evolve so rapidly.
From my perspective in modern security operations, the future of insider threat management lies in combining AI-driven analysis with human expertise. AI can surface subtle indicators of risk at scale, while security analysts provide the context needed to distinguish legitimate business activity from genuine threats. Together, they enable organizations to detect potential issues earlier, reduce unnecessary alert fatigue, and build a stronger security posture without sacrificing productivity.





