CISA’s Updated Insider Threat Guide: Addressing AI Manipulation and Emerging Risks

5

CISA's Refreshed Insider Threat Guide Flags AI Manipulation and Machine Identities as Emerging Risks

The U.S. Cybersecurity and Infrastructure Security Agency has updated its Insider Threat Mitigation Guide for the first time since 2020, adding new guidance on hybrid work, AI-enabled deception, and adverse employee separations amid a rapidly shifting threat landscape.

The revision arrives at a consequential moment. Enterprise environments now host growing populations of AI agents operating alongside human employees, remote work has dissolved traditional security perimeters, and recent industry data suggests insider incidents are costing organizations millions. The update positions CISA's foundational resource for a threat category that has quietly become one of cybersecurity's most complex and expensive problems.

What the Updated Guide Actually Covers

Scott Breor, CISA's acting executive assistant director for infrastructure security, framed the revision as a direct response to feedback from industry and government partners. "Insider threats continue to evolve as technology becomes more advanced," Breor said. "We urge organizations to establish a mitigation program that protects key assets, prevents violence, reduces losses, safeguards sensitive data, and saves lives."

The guide's substantive additions address four areas:

  • Hybrid and remote work environments, acknowledging that distributed workforces have erased the clean boundary between physical and digital access control. A badge reader at the front door no longer defines an organization's security perimeter.
  • AI-enabled manipulation and deception, covering phishing-style social engineering, deepfake-assisted pretexting, and similar techniques used against employees.
  • Access control and visitor screening, renewing emphasis on physical-side fundamentals.
  • Adverse employee separations, providing guidance on managing the elevated-risk window around involuntary or contentious departures.

The guide is aimed at security and HR professionals running insider threat programs as well as organizational leaders more broadly. CISA positions it as usable regardless of the maturity of an organization's existing program.

The Scale of the Problem

The numbers underpinning the update are stark. Recent industry research cited alongside the release found that 41% of organizations reported their most serious insider incident cost between $1 million and $10 million. Another 9% reported losses exceeding that figure. Over a prior 18-month window, 77% of organizations experienced insider-related data loss, with 21% of those recording more than 20 separate incidents.

These figures reinforce why recognizing the behavioral warning signs and employee red flags that precede insider incidents has become a foundational capability for security and HR teams alike.

The timing also carries an unspoken subtext. CISA's own acting director recently uploaded sensitive contracting documents to a public version of ChatGPT under a temporary Department of Homeland Security exception — an episode the guide does not reference but one that illustrates precisely the kind of credentialed, non-malicious risk the update is designed to address. Insider risk does not require malicious intent to cause significant harm. That distinction is central to understanding why the updated guide matters.

The Gap Practitioners Are Flagging

Security leaders who reviewed the update broadly welcomed it while pointing to a significant blind spot: the insider risk created by AI systems themselves, rather than AI used against human employees.

Machine Identities and the Expanding Definition of "Insider"

Rex Booth, CISO at SailPoint, argued that the definition of "insider" now extends beyond human employees to include "machine accounts or AI agents operating within the enterprise" alongside contractors, vendors, and partners. The detection challenge is acute. When someone or something is using legitimate credentials, Booth noted, "it's incredibly difficult to decipher whether their actions stem from malicious intent, a simple human mistake, or a compromised account." His prescription centers on unified, continuous visibility across the identity ecosystem rather than point-in-time access reviews.

Understanding identity and access management best practices is increasingly essential as organizations grapple with the governance challenges posed by non-human identities operating at scale inside enterprise environments.

Morey Haber, Chief Security Advisor at BeyondTrust, broke insider incidents into three categories: malicious, negligent, and compromised. He flagged the compromised-credential path as the one that many modern ransomware campaigns now use as an initial entry point rather than perimeter exploitation. His sharpest comments concerned non-human identities specifically. Organizations are deploying autonomous AI agents with broad and often persistent permissions, and when those systems lack secure-by-design governance, Haber warned, they can expose data or take action "beyond their intended scope" without any human intent involved at all.

Behavioral Detection Over Reactive Investigation

Aviv Nahum, co-founder and CEO of Above Security, welcomed CISA's move away from the outdated image of insider risk as "a disgruntled employee stealing files on the way out," noting that an insider can just as easily be "compromised, coerced, or completely unaware that they are helping an attacker." His structural critique is that most organizations still treat insider risk as an incident-response problem, reconstructing what happened only after HR or Legal raises a flag. That model does not scale. Organizations need continuous and contextual understanding of behavior before a concern becomes a breach.

Mika Aalto, co-founder and CEO of Hoxhunt, reframed the detection problem in memorable terms. Insider threats are not "needles inside haystacks," he said, but "needles in boxes of needles," because the population being monitored consists of authorized users doing legitimate work. His alternative to surveillance-heavy approaches rests on behavioral science and real-time coaching, treating employees as "an active, intelligent human sensor network" rather than a liability to be policed. This framing represents a meaningful shift in how mature security programs are beginning to approach the problem.

Carl Windsor, CISO at Fortinet, grounded the discussion in how most insider data loss actually occurs: not dramatic sabotage but routine negligence — a sensitive file emailed to the wrong address, a USB transfer, or an upload to personal cloud storage. Windsor emphasized visibility across generative AI usage specifically and treating everyday collaboration tools as the primary data egress points requiring protection.

The AI Agent Governance Gap

The practitioner commentary collectively surfaces a governance challenge that CISA's guide does not fully address. As organizations accelerate the deployment of agentic AI systems, those systems carry insider-equivalent access without the behavioral accountability frameworks that apply to human users. The risks and challenges that artificial intelligence introduces for businesses extend well beyond external threats — the internal governance dimension is where many organizations remain significantly exposed.

When an AI agent with broad permissions acts outside its intended scope, no malicious actor needs to be involved for the damage to be real. That reality sits at the center of what the updated guide gestures toward but does not yet fully resolve. For a more detailed treatment of the non-human identity governance challenge, the CISA Insider Threat Mitigation Guide itself remains a useful starting reference alongside emerging frameworks from NIST and industry bodies.

What Organizations Should Take Away

A consistent thread runs across every practitioner perspective: the definition of insider has expanded faster than most governance programs have adapted. Contractors and remote employees represented yesterday's expansion of the attack surface. AI agents, service accounts, and autonomous workflows are today's equivalent.

CISA's guide addresses workforce-management and physical-security fundamentals it has historically covered well. It does not claim to be a governance framework for agentic AI or non-human identity. Organizations that treat it as covering that ground will carry a meaningful blind spot into their programs.

Three Practical Priorities for Security and Risk Leaders

For security and risk leaders, the update points toward three practical priorities worth acting on now.

First, use CISA's revised guide as a baseline audit tool to identify gaps in your current insider threat program, particularly around hybrid work policies and separation procedures. The guide's renewed focus on adverse employee separations is worth taking seriously — the elevated-risk window around involuntary departures remains one of the most consistently underestimated exposure points in enterprise security.

Second, expand your identity governance inventory to include service accounts and AI agents, applying the same least-privilege and behavioral monitoring principles you use for human users. Persistent, broad permissions assigned to autonomous systems represent a structural vulnerability that point-in-time access reviews will not catch.

Third, supplement compliance-based training with behavioral science approaches that provide real-time feedback rather than annual awareness exercises. As Windsor and others make clear, the most common source of actual data loss is not sophisticated sabotage — it is routine, preventable negligence that better-designed feedback loops can meaningfully reduce.


SecureWorld Detroit, scheduled for September 17, 2026, will bring together CISOs and security practitioners to address many of these converging challenges around AI risk and identity governance.

You might also like