CISA Expands Insider Threat Guidance
Updated guidance addresses risks involving AI, remote work, physical access and employee separations.
- By Chelsey Arries
- Sep 10, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated Insider Threat Mitigation Guide addressing changes in technology, workplace practices and physical security.
The revised guide provides a framework for developing or strengthening insider threat programs. It adds material on artificial intelligence, hybrid and remote work, access control, visitor screening and involuntary employee separations.
Insider threats may involve malicious conduct, negligence or unintentional actions. Examples include stealing information, sabotaging equipment, allowing unauthorized physical access or accidentally exposing sensitive data.
The guide recommends that organizations establish multidisciplinary governance groups with representatives from physical security, human resources, information technology, legal and privacy teams. These groups can combine information from different parts of an organization when assessing concerning activity.
For hybrid and remote workplaces, CISA identifies risks involving organizational equipment, documents, home internet connections and additional digital storage. The guide advises organizations to review security procedures, network expectations and employee training for work performed outside primary offices.
The artificial intelligence section warns that insiders with privileged access could poison training data, alter model parameters or expose sensitive information through unapproved AI systems. External attackers could also use AI-generated phishing messages or deepfakes to deceive employees. CISA advises organizations to train employees on AI use, secure existing tools, classify sensitive data and review agreements governing system use.
The guide also addresses security during involuntary employee separations. Recommended steps include coordinating with information technology and security personnel, removing physical and remote access based on risk, recovering equipment and preventing unescorted facility access after a departure.
CISA cites research estimating that the average annualized cost of insider threat incidents rose from $16.2 million to $17.4 million between 2023 and 2024. The same research placed the average containment period at 81 days.
The updated guide positions insider threat mitigation as a continuing process of detection, assessment and risk management.
About the Author
Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.