The Cybersecurity and Infrastructure Security Agency (CISA) released an updated version of its Insider Threat Mitigation Guide on September 9. The revised guide, first issued in 2020, incorporates new case studies, statistics, and specific guidance addressing the evolving landscape of workplace risks, including hybrid and remote work models, the use of artificial intelligence, and adverse employee separations.
CISA stated that the update acknowledges the increasing impact of insider threats on critical infrastructure. It aims to support security and human resources professionals managing insider threat programs, as well as leaders at all organizational levels, regardless of their security program's maturity. The agency emphasized that the guide is designed to be accessible to any organization.
The new material is presented in a more streamlined format with consolidated sections. It expands on emerging workplace trends, particularly the rise of hybrid and remote work, and how these models alter an organization's control over physical and digital access. Regarding artificial intelligence, the guide specifically addresses its potential use for manipulation or deception.
Additional content in the guide covers access control, visitor screening, and strategies for mitigating risks associated with adverse employee separations. CISA intends for the guide to help employees understand behavioral indicators that may signal a potential risk.
Scott Breor, CISA's acting executive assistant director for infrastructure security, highlighted that insider threats continue to evolve with technological advancements. He urged organizations to establish programs that protect key assets, prevent violence, reduce losses, safeguard sensitive data, and ultimately save lives. This framing indicates CISA's broader perspective on insider threats, extending beyond just data loss to include physical security concerns.
The guide also points to newly released CISA resources designed to support preparedness and early risk detection. CISA framed these resources as a practical entry point for organizations that do not yet have an established insider threat program.
Breor noted that the update was informed by feedback from both industry and government partners. He encouraged organizations to review the guide and use it to assess their existing programs. CISA has not provided a timeline for any future revisions to the guide.






