For CISOs, boards, and risk leadership

    The single destination for understanding and reducing insider risk.

    A working library for security, HR, legal, and executive teams — live incident reporting, a fifteen-year case archive, and a growing set of assessment tools and briefings, built around one principle: insider risk is a people, data, and governance problem, not only a monitoring one.

    12Live interactive tools & generators
    700+Documented incidents, 2010–2026
    65+Briefings & articles in development
    What’s here today: the Insider Risk Newsroom, the fifteen-year Threat Archive, and the full set of twelve interactive assessment tools and generators are live and ready to use. The leadership briefing series and research library below are in active development and shown as a roadmap so you can see the full scope of what’s coming.

    Insider Risk Newsroom

    Live · hand-researched snapshot

    Coverage limited to stories with a genuine insider-origin angle — a malicious, negligent, departing, or third-party insider at the center of the story. General breaches, malware, and vendor CVEs with no insider angle are deliberately left out.

    Open the Newsroom in full ↗ Ask Claude to “refresh the insider risk wire” any time to re-research and republish it.
    CURATED SNAPSHOT · INSIDER-ORIGIN INCIDENTS ONLY

    Insider Risk Wire

    SNAPSHOT · SEP 17, 2026
    Insider risk · insider threat · nothing else

    News about people, not perimeters.

    Every story here involves someone with legitimate access — an employee, a contractor, a departing hire — who caused harm, was accused of it, or is at the center of new insider-risk tooling, policy, or litigation. External hacks, generic malware, and vendor CVEs are left out on purpose.

    How this is kept current: a browser can’t safely pull live RSS into a hosted page, so this is a hand-researched snapshot instead of an auto-refreshing feed. Ask Claude in this chat to “refresh the insider risk wire” any time and it will re-research and republish this page with new cases.
    Stories in this snapshot
    Publishers cited
    Sep 17Snapshot date

    Lead case

    Insider-risk coverage, Jan–Sep 2026

    Sorted newest first

    Global Insider Threat Archive

    Live · 2010–2026

    A chronological record of documented insider-threat incidents, spanning espionage, trade-secret theft, sabotage, leaks, and compromised access, drawn from DOJ filings, FBI releases, SEC actions, and court dockets. The full archive is filterable by year and category — a sample of recent, independently sourced cases is shown below.

    Malicious2026

    Bank Manager Admits $335K Customer Account Theft

    A branch manager used forged withdrawal slips and a coworker’s credentials to drain more than 20 customer accounts and two local nonprofits over several years.

    DOJ Plea Agreement, Sept 2026 ↗
    Espionage2026

    Insider-Threat Specialist Pleads Guilty to Attempted Espionage

    A DIA insider-threat analyst admitted leaving classified files on a thumb drive for who he believed was a foreign government before being caught by an undercover FBI operation.

    DOJ / FBI, Aug 2026 ↗
    Sabotage2026

    Twin Brothers Convicted for Wiping 96 Federal Databases

    Rehired despite prior hacking convictions, the pair deleted 96 government databases across 45+ agencies within an hour of being fired, using AI tools to help erase forensic evidence.

    DOJ / FDIC-OIG, May 2026 ↗
    Espionage2026

    Cyber Division Executive Sentenced for Selling Exploits to Russia

    Former Trenchant general manager Peter Williams was sentenced to 87 months after selling eight zero-day exploits to a Russian broker for up to $4 million.

    DOJ / U.S. Treasury, Feb 2026 ↗
    Compromised access2026

    AI Assistant Exploited as One-Click Insider Data-Exfiltration Vector

    Researchers disclosed prompt-injection flaws letting a single malicious link turn a trusted Copilot session into a channel exfiltrating mailbox and SharePoint data with the user’s own permissions.

    Varonis Threat Labs, 2026 ↗
    Leak2026

    Negotiator Leaked Client Strategy to BlackCat Ransomware Gang

    A ransomware negotiator secretly fed BlackCat attackers confidential details of his employer’s clients’ negotiating positions and insurance limits in exchange for payment.

    DOJ, Mar 2026 ↗
    Open the full 15-year archive ↗ Filter by year (2010–2026) and by six incident categories in the full archive.

    Interactive Assessment Tools

    Live · 12 tools

    Twelve self-serve applications for scoring maturity, estimating cost and ROI, generating policies and charters, and pressure-testing response plans — built for security, HR, legal, and executive teams to use without a consultant in the room. Each carries a clear educational, not-legal-advice disclaimer.

    Live

    Insider Risk & Insider Threat Assessment

    Scores governance, HR coordination, detection, response, privacy, third-party controls, and offboarding, with a maturity score and recommended next steps.

    Live

    Insider Incident Cost Estimator

    Estimates the likely financial impact of an insider incident based on data type, headcount, and detection speed.

    Live

    Insider Risk Program ROI Calculator

    Models the return on investment of building or expanding an insider-risk program against expected incident reduction.

    Live

    Insider Risk Program Staffing & Budget Estimator

    Recommends headcount, roles, and budget ranges for an insider-risk program based on organization size and maturity target.

    Live

    Acceptable Use & Data Handling Policy Generator

    Generates a customized acceptable-use and data-handling policy draft ready for legal and HR review.

    Live

    Insider Threat Program Charter Generator

    Builds a program charter defining scope, governance, roles, and authority for a new or existing insider-threat program.

    Live

    Tabletop Exercise Scenario Generator

    Generates realistic insider-risk tabletop scenarios — suspicious downloads, a resignation, stolen credentials, contractor abuse — to pressure-test response plans.

    Live

    High-Risk Offboarding Checklist

    Interactive checklist covering identity, devices, tokens, repositories, cloud services, privileged access, shared credentials, and post-exit monitoring.

    Live

    Privileged Access Review Tracker

    Tracks and schedules recurring reviews of privileged accounts and access grants across systems and owners.

    Live

    Shadow IT and SaaS Discovery Checklist

    Walks through discovery steps for unsanctioned apps, browser extensions, and SaaS tools that create unmonitored exfiltration paths.

    Live

    Decision Support Hub: Escalation Tree & NIST CSF Mapper

    An interactive escalation tree paired with a NIST CSF mapper to guide response decisions during a live incident.

    Live

    Advanced Extensions Hub: Vendor Risk, Remote Audit & Roadmap

    Extends the core program with vendor-risk scoring, a remote-audit workflow, and a forward-looking program roadmap.

    Leadership Briefing Series

    In development · 21 episodes planned

    A recurring audio and video series for CISOs, HR, general counsel, and boards. Each episode will ship with a full recording, an audio-only version, a transcript, a five-minute summary, a related article, and a downloadable checklist.

    01Why Insider Risk Is Different from External ThreatsFoundations
    02Malicious, Negligent, and Compromised InsidersFoundations
    03The Psychology of Insider ThreatsFoundations
    04Offboarding Is a Security ControlProcess
    05How Data Exfiltration Actually HappensProcess
    06Insider Risk and Privileged AccessProcess
    07Building an Insider-Risk Program from ZeroProgram
    08HR and Security: Creating a Joint Risk ProcessProgram
    09Insider Risk in Remote and Hybrid WorkProgram
    10Third-Party and Contractor Insider RiskProgram
    11AI Tools and the New Insider-Risk SurfaceTechnology
    12Can Behavioral Analytics Predict Insider Risk?Technology
    13Data-Centric Security versus User-Centric MonitoringTechnology
    14Insider Risk in HealthcareIndustry
    15Insider Risk in Financial ServicesIndustry
    16Protecting Source Code and Intellectual PropertyIndustry
    17Investigating Without Creating a Surveillance CultureGovernance
    18The Insider-Risk Incident Response PlaybookGovernance
    19Lessons from Real Insider-Risk CasesGovernance
    20The Future of Insider Risk ManagementOutlook
    21CISO, General Counsel, and CHRO RoundtableOutlook

    Research & Content Library

    In development · 45+ resources planned

    Twenty-five foundational articles, four case studies, a governance framework, checklists and templates, a glossary, a vendor directory, and a weekly executive newsletter — organized so security, HR, legal, and compliance teams can each find what applies to their part of the program.

    Articles (25 planned)

    • What Is Insider Risk? / Insider Threat versus Insider Risk / The Four Types of Insider Risk
    • Top 20 Insider-Risk Warning Signals
    • How to Build an Insider-Risk Policy / Insider-Risk Governance Model
    • The Insider-Risk Incident Lifecycle / How to Investigate Suspicious Employee Activity
    • Privacy by Design in Insider-Risk Programs
    • How DLP Supports Insider-Risk Management / UEBA and Insider Risk
    • Why Context Matters More Than Alerts
    • Insider Risk in Microsoft 365 / Insider Risk in Cloud-Native Organizations
    • Protecting Source Code from Insider Exfiltration
    • Insider Risk and Generative AI
    • How to Secure Privileged Users / Contractor Access Management
    • The Security Offboarding Playbook
    • Insider Risk Metrics That Matter
    • Reducing False Positives in Insider-Risk Detection
    • How to Run an Insider-Risk Tabletop Exercise
    • Insider Risk for Small Businesses / for Security Operations Centers
    • A 90-Day Insider-Risk Program Roadmap

    Case studies

    Accidental Data Exposure · Departing Developer · Compromised Executive Account · Contractor with Excessive Access

    Frameworks & templates

    Insider-Risk Program Framework · Daily Analyst Checklist · Executive Offboarding Checklist · Sensitive Data Inventory Checklist · Investigation Record · HR-Security Escalation Matrix

    Reference

    Insider Risk Glossary · Insider-Risk Tool Directory (DLP, UEBA, endpoint monitoring, data lineage, IAM, PAM, SIEM — categorized, not endorsed)

    Editorial Standards

    Live

    Sourcing

    Every newsroom and archive entry is checked individually for a genuine insider-origin angle — a malicious, negligent, departing, or third-party insider at the center of it — before publication. General breaches, malware, and vendor CVEs with no insider angle are excluded by design.

    Facts, allegations, and findings

    Coverage distinguishes confirmed facts from allegations, company statements, law-enforcement findings, and expert interpretation. Where a source is uncertain, the item is left out rather than published with an invented attribution.

    Privacy by design

    Interactive tools will use privacy-conscious, proportionality-aware language throughout, and the program’s editorial position is that insider risk is a people, data, identity, and governance problem — not only a monitoring one.