* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What’s an insider threat?
What’s an insider threat?
=========================
Published  February 10, 2026•*4*-minute read
Copy URL
Jump to section
---------------
OverviewTL;DRRisksWhy care about them?Who's behind them?Insider threat typesProtecting against themWhy Red Hat?
Overview
--------
An insider threat is leaked or misused [data](/en/topics/big-data) that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
Insider threats are among the most common organizational security threats, and they’re most often committed by regular people making regular mistakes.
Too long; didn't read
---------------------
Don't feel like reading? Here's a short video on insider threats, instead.
This video can't play due to privacy settings
To change your settings, select the "Cookie Preferences" link in the footer and opt in to "Advertising Cookies or try disabling adblockers."
Red Hat resources
-----------------
[Keep reading](/en/resources "Keep reading")
What are the risks of an insider threat?
----------------------------------------
Sometimes not much. Sometimes a lot. The context behind that vague answer has a lot to do with the damaging potential of a single trade secret, or the unnoticed repetitiveness of many smaller mistakes.
Some insider threats can bring down entire companies, embarrass people, threaten customer or business partner safety, cost money, or put a country’s national security or mission-critical infrastructure at risk. Just search "insider threat" in any search engine to see a dozen United States federal agencies talk about the risks of insider threats:
* [Cybersecurity & Infrastructure Security Agency (CISA)](https://www.cisa.gov/defining-insider-threats)
* [Department of Homeland Security (DHS)](https://www.dhs.gov/science-and-technology/cybersecurity-insider-threat)
* National Institute of Science and Technology’s (NIST’s) [Computer Security Resource Center (CSRC)](https://csrc.nist.gov/glossary/term/insider_threat)
* [Federal Bureau of Investigation (FBI)](https://www.google.com/url?q=https://www.fbi.gov/file-repository/spotting-insider-threat_508.pdf&sa=D&source=docs&ust=1651254612095529&usg=AOvVaw1ulUhNnvSxohhkeEevmiKD)
Even *we*—the leading enterprise [open source](/en/topics/open-source/what-is-open-source) company who believe everything thrives in the open—show trepidation towards insider threats. Our [open source development](/en/about/development-model) model for [Red Hat® Enterprise Linux®](/en/technologies/linux-platforms/enterprise-linux) gets released publicly through the [CentOS Stream](/en/topics/linux/what-is-centos-stream) open source community, but only *after* multiple reviews, tests, and quality control processes.
Why should I care about insider threats?
----------------------------------------
Because—contrary to popular belief—most insider threats are not perpetrated by former employees with malicious intent. They’re most often mistakes caused by normal people. Like you.
You’re probably not thinking of becoming a threat actor. You likely don’t even consider yourself an insider. But think of all the valuable information you have legitimate access to every day: intellectual property, software engineering processes, organizational network credentials, and company performance information.
That’s why it’s important to pay attention to the questions at the end of your corporate ethics courses. Try not to breeze past these questions. Think about them. *Really* think about them. They’ll help you become better at insider threat detection in the future.
* What are some potential insider threat indicators?
* What scenario might indicate a reportable insider threat?
* How many potential insider threat indicators can you spot?
Who are the people behind insider threats?
------------------------------------------
There are generally 3 classes of insider threats:
* **Malicious insider**: Someone actively trying to do harm or benefit from stealing or damaging data or services.
* **Whistleblower**: Someone who believes the company is doing something wrong.
* **User error**: Someone who simply makes a mistake.
What are the types of insider threats?
--------------------------------------
### Accidents
This one deserves its own category because it’s so common. Accidental insider threats happen when—for example—a critical service breaks after someone bypasses change procedures, accidentally leaking credentials or customer data to the internet.
### Malware
Malicious software that acts against the interest of the user. [Malware](/en/topics/security/what-is-malware) can affect not only the infected computer or device but potentially any other device the infected device can communicate with.
### Data theft
The purposeful and malicious practice of finding and removing or removing sensitive data from hardware, [cloud](/en/topics/cloud-computing), or [software-defined](/en/topics/data-storage/software-defined-storage) repositories. Also known as a data breach.
### Elicitation
A form of social engineering to glean private information from insiders are part of seemingly normal conversations.
And then, there’s **phishing**. Phishing is a form of social engineering in which an attacker tries to trick someone into handing over sensitive information or personal data through a fraudulent request, such as a spoof email or a scam offer. If an insider instigates a phishing attack, it’s an insider threat. If the instigator is outside—perhaps running off malware—it’s considered another type of security threat.
Protecting against insider threats
----------------------------------
Security is everyone’s responsibility. Security teams can maintain security policies and help everyone become more mindful of security protocols, but relying on specialists alone to control every aspect is an exercise in futility.
Protective systems are always in place—whether or not there are security controls, computer emergency response teams (CERTs), or insider threat programs within your own company. Consider all the local, state, federal, and international agencies with cybersecurity and antitrust charges.
While the most obvious way to protect against insider threats is to have well maintained permissions and firewalls for the sake of data loss prevention, there are also 3 components of an effective security team:
* **Education:** Security teams can decrease the chances of external threats and insider attacks just by teaching people how to do things correctly, or emphasizing how much power everyday employees have. Educating insiders that many flagged reports will not be threatening can build a sense of community—that the security team exists as a partner, not judge and jury.
* **Default to secure:** This is the simplest route to security—lock it all down and make access the exception to the rule. It’s easier to do the right thing by default when the easiest route is also the secure route. Defaulting to secure can look like [role based access control](/en/topics/security/what-is-role-based-access-control) (RBAC), or only providing exactly what a user needs by following the principle of least access
* **Good communication:** Try to encourage people to feel comfortable talking to you. This will encourage more people to tell you the truth, the whole truth, and (ideally) the proactive truth. Set yourself up as a partner; someone to work alongside of to verify jobs are performed with security in mind.
* **Humility:** Remember that the human condition is one fraught with mistakes. You are not a judge and jury. You are the fire department. You fix the problem. Try not to care that a mistake was made. Punishing mistakes by default will forge a culture of fear and unwillingness, where people will wait until the last minute to flag issues.
Why Red Hat?
------------
We start with upstream open source communities to make enterprise-ready software that’s hardened, tested, and securely distributed. The results are enterprise open source products you can use to build, manage, and automate security across hybrid clouds, [supply chains](/en/solutions/trusted-software-supply-chain), applications, and people.
The official Red Hat blog
-------------------------
Get the latest information about our ecosystem of customers, partners, and communities.
[Keep reading](/en/blog "The official Red Hat blog")
All Red Hat product trials
--------------------------
Our no-cost product trials help you gain hands-on experience, prepare for a certification, or assess if a product is right for your organization.
[Keep reading](/en/products/trials "All Red Hat product trials")
Keep reading
------------
### What is SOAR?
SOAR refers to 3 key software capabilities that security teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence.
[Read the article](/en/topics/security/what-is-soar "article | what is soar")
### What is post-quantum cryptography?
Learn about Red Hat’s approach to post-quantum cryptography, which refers to encryption algorithms that can resist attacks from quantum computers.
[Read the article](/en/topics/security/post-quantum-cryptography "What is post-quantum cryptography?")
### What is lightweight directory access protocol (LDAP) authentication?
Lightweight directory access protocol (LDAP) is a protocol that helps users find data about organizations, persons, and more. It stores data in the LDAP directory and authenticates users to access the directory.
[Read the article](/en/topics/security/what-is-ldap-authentication "article | what is lightweight directory access protocol ldap authentication")
Security resources
------------------
### Related content
* Blog post
  [Chasing the holy grail: Why Red Hat’s Hummingbird project aims for "near zero" CVEs](/en/blog/chasing-holy-grail-why-red-hats-hummingbird-project-aims-near-zero-cves)
* Blog post
  [Zero CVEs: The symptom of a larger problem](/en/blog/zero-cves-symptom-larger-problem)
* Blog post
  [Extend trust across the software supply chain with Red Hat trusted libraries](/en/blog/extend-trust-across-software-supply-chain-red-hat-trusted-libraries)
* Blog post
  [Elevate your vulnerabiFrom challenge to champion: Elevate your vulnerability management strategy lity management strategy with Red Hat](/en/blog/elevate-your-vulnerability-management-strategy-red-hat)
### Related articles
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [What is SOAR?](/en/topics/security/what-is-soar)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is edge security?](/en/topics/security/what-is-edge-security)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is security automation?](/en/topics/automation/what-is-security-automation)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [What is risk management?](/en/topics/management/what-is-risk-management)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is financial services security (and compliance)?](/en/topics/security/security-and-compliance-financial-services)
* [What is API security?](/en/topics/security/api-security)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
[More about this topic](/en/topics/security "More about this topic")