DiagramsThree Non-Interchangeable Approaches to an Insider Program
The same components in all three. What differs is the order they are put in.
17 AUGUST 2026 | DIAGRAM
Another thought on guidance. Bear with me. Give me six hours to chop down a tree and I will spend the first four sharpening the axe: the line is usually attributed to Lincoln, and whoever actually said it, I believe it is the most effective case ever made for building security frameworks.
National Protective Security Authority (NPSA), setting the latest conceptual foundations for a shared approach to insider risk, puts the problem plainly: “Organisations adopt a narrow perspective when considering the range of potential insider events and sometimes fail to consider all the ways in which insiders can cause harm.”
That perspective is the direct result of one’s approach. In my experience, three approaches are equally viable, represented below. All three share the same building blocks, but swap the order of the addends and, unlike in arithmetic, the sum changes. Surprisingly so.

Framing bias at its finest.
My own take: there is no best lane in absolute terms. There is an order of operations each organization must own, chosen against its exposure, its maturity, and the threats it can plausibly identify. Still, whoever starts technology-first must, at some point, switch lanes, or at least plant one foot in risk or in threat while the other stays where it started. The difference, one could argue, is thin. It is. Foundational choices usually are, until postponed long enough for the consequences to compound.
