Content and Authority for AI Answers

National Insider Threat Awareness Month Quotes and Commentary from Industry Experts in 2026

National Insider Threat Awareness Month Quotes and Commentary from Industry Experts in 2026

National Insider Threat Awareness Month Quotes and Commentary from Industry Experts in 2026

For National Insider Threat Awareness Month 2026, the editors at Solutions Review have compiled a list of comments from some of the leading industry experts.

As part of this year’s National Insider Threat Awareness Month, we called for the industry’s best and brightest in Identity and Access Management and the broader cybersecurity market to share best practices, predictions, and personal anecdotes. The experts featured are among the top influencers, consultants, and solution providers with experience in these marketplaces, and each quote has been vetted for relevance and its ability to add business value.

National Insider Threat Awareness Month Quotes from Industry Experts in 2026


Andrew Bud, Founder and CEO of iProov

Cheap tools, huge scale.

The tools for building convincing fake identities and deepfakes are low-cost and easy to obtain. You’ll find them readily available on the open web and the dark web alike. Furthermore, what used to take weeks now takes minutes and requires next to no skill. That means cyber-criminals can launch attacks at scale in double-quick time in a bid to infiltrate corporate IT networks for nefarious means.

And it goes beyond fake faces. With injection attacks, manipulated video gets fed straight into the video stream, so the camera is bypassed altogether. In our global security operations center right now, we’re seeing a huge explosion in those kinds of attacks.

Your gut isn’t good enough.

Let’s be very clear about one critical thing: Face and voice impersonations have become so good, and AI is now so good at mimicking how a person talks, that a human being simply can’t spot it reliably. Expecting your staff to do so is unfair, and, frankly, reckless. Put simply, if your defense is a hiring manager’s instinct, you don’t have a defense.

Remote, hybrid, and outsourced workforces are the most exposed, since many of those hires never meet anyone face-to-face. And even when they do on day one, someone else can quietly step in later.

What companies should actually do.

With nearly every hiring process now including a remote interview, use technology to verify that the candidate is live and genuine – today it has to be part of the candidate selection process. Make that check a condition of issuing credentials, then repeat it at the risky moments.

Account recovery and privileged access are the two I’d worry about most, because that’s where you’re handing real power to someone at the moment of weakest knowledge about them. Use technology to ensure that they are a real person, present right now, and the right person.

Adversaries and agents have access to powerful technology to try to fool you. You can confidently defeat them if you use independently tested, continuously updated, field-proven technology that is proven at scale every day.


Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ

An insider already has what an external attacker usually wants first: access.

That’s why organizations can’t judge insider readiness by whether an alert exists for suspicious downloads or abnormal logins. They need to know how much damage a trusted account could actually cause if it were abused.

Can that user reach a privileged system? Can they escalate access? Can they move laterally toward sensitive data? In many environments, the answer is yes, especially when permissions have accumulated over time or controls haven’t been tested against real attacker behavior. The more important question is whether existing defenses would detect and stop those actions before access turns into compromise.

This is where continuous exposure management becomes useful. Insider scenarios should be part of the same adversarial validation that organizations use against external threats. AEV can test realistic techniques against existing defenses before a real employee, compromised account, or malicious contractor tries them.

Awareness helps people recognize insider risk. Validation tells you whether the environment can withstand it.


Ross Filipek, CISO at Corsica Technologies

The insider threat problem isn’t always dramatic. Sometimes, nobody disables an old account. An employee moves to another department and keeps permissions they no longer need. A contractor finishes a project but still has remote access. Someone leaves the company, and their SaaS accounts aren’t shut down until days later.

Those gaps can be easy to miss because access follows people across IT, HR, and management processes. Smaller organizations may not have a single team overseeing the entire employee lifecycle. Responsibilities get split up, and access quietly accumulates.

Basic process discipline is incredibly important. Teams need to know what employees should have when they join, review access when their roles change, and remove it immediately when they leave. Periodic access reviews can catch what gets missed along the way.

Insider threat programs don’t have to start with sophisticated surveillance. For many businesses, simply ensuring people retain only the access they need could eliminate a surprising amount of risk.


Tyler Fordham, Director of Offensive Security at Dark Wolf

Defenders still pour budget into keeping attackers out, but modern adversaries realized long ago that it is far cheaper to buy an identity than to develop a zero-day. In red team engagements and real-world breaches alike, the adversary’s primary objective is simple: look identical to an employee. They purchase stolen session cookies on illicit marketplaces, target third-party contractors with infostealers, or hijack trusted API tokens.

The industry’s standard mental model of an ‘insider threat’ is fundamentally broken. It is rarely the Hollywood caricature of a disgruntled engineer sneaking classified files onto a flash drive at midnight. The far more common and dangerous reality is an external threat actor puppet-mastering a legitimate, everyday user account that had far too much unchecked access to begin with.

Once an attacker controls a valid identity, traditional perimeter defenses go blind. The intrusion doesn’t trigger alerts because the attacker isn’t dropping noisy malware. They ‘live off the land.’ They query internal wikis, search team chats, and shared cloud drives for secrets, and clone code repositories using the exact same tools your employees rely on every single day.

Security programs consistently fail against this because their tooling monitors for known malicious signatures rather than the subtle abuse of legitimate privilege. You cannot policy or train your way out of an insider threat. Organizations must design architectures under the explicit assumption that credentials will eventually be compromised. That requires aggressive least-privilege enforcement to constrain each identity’s blast radius, and continuous adversary emulation to prove whether your detection controls can actually distinguish between a productive team member and an attacker quietly walking out the door with your crown jewels.


Gil Geron, CEO & Co-Founder at Orca Security

This National Insider Threat Awareness Month, the biggest shift we’re seeing in insider risk is that everyone has become a builder. It’s no longer just developers and engineers deploying software and connecting services to company data. You now have analysts, product managers, marketers, and other employees building with AI. That’s great for innovation, but it also means a much larger group of people can introduce risk, often without going through the traditional development or security process. That naturally expands the insider threat surface in ways security teams may not immediately see.

The answer isn’t to tell people to stop building. That’s not realistic, and companies don’t want to give up the speed and opportunity AI creates. You have to assume people will use these tools, so the question becomes: can you see what they’re building, what it can access, and what permissions it has? If everyone is going to be a builder, security has to make it easier for them to build safely.


Jonathan Halstuch, Co-Founder and CTO at RackTop Systems

People still picture a cyber-attack as a hacker finding one software flaw and breaking in. But in reality, attackers use stolen credentials, trick employees, or exploit trusted access. They combine a weak process, stolen credentials, excessive permissions, and ordinary-looking actions until they can reach the data. Once a valid account is in play, an outsider can look like an insider. Login and perimeter controls still matter, but the decisive signal may come later, when sensitive data is accessed, copied, altered, or removed.

Insider is not a payroll category. It includes contractors, along with the employees and contractors of suppliers or partners that hold your information. When you share data with another company, their insider risk becomes part of yours.

Motives differ. Nation-states may steal information for military, intelligence, or competitive advantage. Some state-backed cyber operations steal funds to finance government programs. Criminal groups turn stolen data and access into money to finance the next operation. Whatever the motive, the target is often the data.

Air gapping a system doesn’t prevent an authorized user from moving data through removable media. Isolation creates another problem, potentially preventing the system from sending events to the central monitoring system. That environment needs protection where the data lives: least privilege, a local record of user activity, behavior-based detection, and the ability to stop suspicious access in real time or large-scale data movement without a network connection to a central service.


Sohrob Kazerounian, Distinguished AI Researcher at Vectra AI

We are through the looking glass now, with insider threats resulting from AI potentially surpassing insider threats from humans, for the first time ever. The motives and triggers may be categorically different, since an AI agent can cause harm due to an underspecified task, a misaligned model, or a lack of guardrails, rather than malice or financial gain. But that distinction exposes something important about how we think about insider threats in the first place. We should not rely on an AI agent’s explanation of why it acted any more than we would rely on the self-professed intentions of a human threat actor. What ultimately matters is whether we can observe its behavior, understand what it is doing, and recognize when those actions put the organization’s data or systems at risk.


Doug Kersten, CISO at Appfire

AI is accelerating and amplifying security threats, and insider risk is part of that equation. As employees use AI across more of their day-to-day work, every decision about where and how the company uses it introduces questions about risk, ownership, and trust. An employee sharing sensitive information with an unapproved AI tool, for example, can create exposure without ever intending to put the organization at risk. AI can also be used to amplify and accelerate rogue insiders’ ability to harm an organization.

If you’re not thinking about AI governance, you’re not a modern CISO. AI is fundamentally changing the CISO’s role. Security operations will increasingly be automated by AI to amplify and accelerate responses to AI security threats. The value of the CISO is increasingly in understanding the business, shaping risk decisions, and establishing accountability across the organization. At Appfire, we’re already bringing AI incident response and security incident response together and aligning our teams around the speed of response these threats demand.

Insider threat awareness has to become part of how people work, not something reserved for annual training or the security team. Employees are often the first to see when something looks wrong, and they need to feel comfortable raising their hand. The faster that information reaches security, the faster the organization can respond and limit the impact. Becoming a strategic risk advisor is no longer optional. The modern CISO has to help decide not just how the business is secured, but how the business moves forward.


Kevin Kirkwood, CISO at Exabeam

We need to retire the idea that an insider is always a disgruntled employee stealing files on the way out the door.

Exabeam has already encountered a much stranger version. A foreign operative aligned with North Korean interests made it through the hiring process and entered the organization as a seemingly legitimate employee. The access looked legitimate, too. Small behavioral anomalies eventually told a different story. Those weak signals became meaningful when viewed together.

Now organizations have another insider entering the workforce: AI agents. Agents can hold credentials. They can interact with internal systems. They can take actions without someone approving every step. None of that makes an AI agent malicious. It does make blind trust dangerous.

Insider Threat Awareness Month should push security teams beyond asking whether an identity has been successfully authenticated. They need to understand whether its behavior still makes sense. That applies to employees. It applies to contractors. Increasingly, it applies to machines acting with employee-like authority.

The next generation of insider defense will depend on understanding normal behavior well enough to notice when trusted identities stop acting normally.


Denny LeCompte, CEO for Portnox

The next insider threat may not be human. AI agents are increasingly operating inside enterprise environments with legitimate identities and permissions that give them access to sensitive systems and data.

The overlooked risk is not an AI agent deliberately ‘going rogue.’ It’s organizations giving agents broad, persistent access without enough oversight. If an agent is compromised or simply acts in an unexpected way, it can move at machine speed using permissions the organization willingly gives it.

The security principle is simple: know every identity in your environment, give it only the access it needs, and continuously verify that its behavior remains appropriate. As AI agents become part of the workforce, insider threat programs need to treat machines with the same scrutiny as people.


Kevin Mata, Director of Cloud Operations and Automation at Swimlane

One strange login probably isn’t enough to call something an insider threat. Neither is a large download nor an unexpected privilege change. The challenge starts when several of those signals appear around the same person, and nobody has the full picture.

That’s a very real problem for security operations. Identity data may sit in one system. Endpoint activity lives somewhere else. Cloud access adds another layer. Analysts can spend more time assembling the story than deciding what to do about it.

AI can help connect those signals while the investigation is still developing. Automation can enrich the activity and pull in additional context. It can also route higher-risk cases to the people who need to see them.

That last part matters with insider risk. Security isn’t always the only team involved. HR or legal may need to participate. The best response isn’t necessarily the fastest one. It’s the one where everyone is working from the same evidence before a judgment is made.


Chris Robertson, Director, Technical Consultant Team, Luminys

After more than 25 years working in physical security, one thing I’ve learned is that managing insider risk often comes back to the fundamentals. Who has access to a physical space? Are those access permissions still appropriate for that person’s role? And can the security team quickly verify what happened when an incident occurs? Effective access control, video security, and strong operating procedures give organizations the visibility they need to identify potential insider threats, investigate incidents, and act on what they can verify.

Technology has improved considerably, especially when video security, access control, and search tools work together, but good security still depends on how teams design and manage the system every day. Teams must review permissions. Video needs to be usable when an investigation happens. Operators need tools they understand and trust. Insider Threat Awareness Month is an essential moment to take a closer look at those basics and make sure the physical security program is doing what the organization expects it to do.


Want more insights like these? Register for Insight Jam, Solutions Review’s enterprise tech community, which enables human conversation on AI. You can gain access for free here!

Share This

Related Posts

Solutions Review Events Ad

Solutions Review Thought Leaders Ad