ArticlesInsider Threat or Insider Risk?
The word you choose builds the program you get.
24 JUNE 2026 | 4 MIN READ
Is it a linguistic problem or an approach problem?
In security and risk management, words drive meanings. The labels we choose are not decoration on top of the work. They define the work. Insider is the clearest case I know, because we use two words for it almost interchangeably, and the two words are not the same thing.
We say insider risk. We say insider threat. The discipline’s richness and its confusion come from the same root: most programs are built on the difference between those two words without ever naming it.
Threat is the event. An actor, a capability, an act, something to detect and investigate. Risk is the condition. The posture that makes an event more or less likely, more or less consequential, whether or not any specific actor is moving. One is a person you are looking for. The other is a state you are managing.
Here military doctrine offers a definition worth borrowing. NATO’s AJP-2 describes a threat actor as one defined by intent, capability, and motivation. Three terms, not a mood. An actor who can but will not is not a threat. An actor who would but cannot is not one either. You need them present together, and then you weigh the probability that they meet in an act.
That formula is built for an external adversary. Turn it inward, and something interesting happens.
For the insider, capability is close to a constant. The employee already has the access, the credentials, the knowledge of where things live and how they move. That is what makes them an insider. Capability is granted on the first day and rarely questioned again.
Which leaves intent and motivation: the two terms that describe not what a person can do, but whether and why they would. They are the only parts of the equation that actually move, and the ones no system measures well. Telemetry sees the act. Access logs see the capability. Neither sees the why: the pressure, the grievance, the resignation already written but not sent. The hardest terms in the formula are the ones that decide everything, and they live in no dashboard.
This is where the linguistic question becomes an organizational one. Ask five functions what insider risk is and you get five answers. IT describes anomalous activity. HR describes a person under strain. Compliance describes a control that has to hold. Legal describes liability. Security describes an adversary already inside. None of them is wrong. Each is describing the discipline from the door it entered through.
And the door you enter through quietly decides which word wins. A program born in IT security optimizes for threat: detection, investigation, the event. A program born in governance drifts toward risk: conduct, condition, prevention. Most organizations never choose. They inherit the definition of whichever function arrived first, then spend years wondering why the program hunts events it should have prevented, or manages a posture while an actual case walks past it.
A mature program is not the one with the most tools. It is the one that has walked through every door on purpose.
That is the part most programs skip. Recognizing that threat and risk are different words is the diagnosis, not the cure. Choosing the right one is not enough, and neither is the tidy answer of using both. A serious program has to satisfy each door deliberately: the detection IT expects, the human read HR owns, the control evidence compliance needs, the defensibility legal requires, the adversary lens security brings. Not as slogans. As a plan, with an owner for each.
It will rarely be balanced, and it should not try to be. One organization will lean hard toward threat because its crown jewels are technical and its adversary is real. Another will lean toward risk because its exposure is conduct, culture, and concentrated trust. The weighting follows the business: the sector, the assets, the regulatory weather, a long list of variables that are specific to you and that no framework can preset. Imbalance is not a flaw. It is the program fitting its organization.
What is not optional is the reconciliation. If five functions each run their slice with their own definition and there is no point where those slices are brought back together, you do not have an insider program. You have five adjacent ones, each convinced it is the whole. Somewhere the threads have to meet: one posture, one place where the doors reconcile, one person accountable for holding it. Whether that owner sits in the CISO’s chair, the CSO’s, HR’s, or somewhere built for the purpose matters far less than the fact that the seam exists and someone is named to it.
So the question for the next program review is not how many cases we opened. It is two quieter ones. Which doors does our program actually serve, and where do they reconcile. In the insider world, capability was never the hard part. Intent and motivation are, and so is the seam. Find them, and you stop counting events long enough to manage the thing that produces them.
