After 25 years in security — from defending Department of Defense networks to helping enterprises protect data today — one truth has never changed: people will always take the path of least resistance.
This is not about recklessness, and it is rarely about malice. It is human nature. We all want to get work done. We want to meet deadlines, please our managers, and head home on time. In those moments, risk is not top of mind. Productivity is.
And that is where insider risk quietly lives.
More Common Than We Admit
When most people hear "insider threat," they still imagine the classic rogue employee — someone walking out with source code or trade secrets. That happens, but not often.
The reality I see every day is far less dramatic. It looks like an employee emailing files to a personal account to keep working after hours. A manager pasting sensitive data into a generative AI tool to speed up formatting. A contractor storing customer data on the wrong drive because it is easier than fighting a permissions system.
None of these actions come from malice. But the impact can be just as serious as an external attack. Forrester recently found that roughly 40% of internal incidents are accidental rather than intentional — and that aligns with what I have seen: intent does not equal outcome (Forrester, 2023).
The Psychology of Shortcuts
Even the most security-educated employees will look for workarounds if the tools in front of them make their jobs harder. It is the psychology of shortcuts. If security feels like friction, human nature finds another way.
I have seen this across industries. In the public sector, sensitive student data moved outside official systems. In sales, reps passing pricing data through personal email. In everyday business, workers syncing files to personal cloud accounts so they can "just get it done."
The driver is almost always the same: productivity first, risk later.
The False Choice Between Productivity and Security
Too often, employees are made to feel like they must choose between getting their job done or staying secure. And when that choice appears, productivity wins every time.
But this is a false choice. The cost of a breach, a compliance violation, or reputational damage is always higher than the cost of giving people the secure tools they need. This is not only a cost-benefit problem; it is an opportunity cost problem. Every time an employee finds a shortcut around IT, the organization pays in hidden risk.
Why Technology Alone Hasn't Been Enough
Organizations have invested heavily in traditional security controls: CASBs for SaaS, DLP for sensitive data, MDM for endpoints. These tools all have a place — and they solve real problems.
But they were not designed to account for human behavior. They cannot distinguish between a user legitimately collaborating and a user quietly moving files off-network "just to make life easier." They cannot explain intent.
That gray space — where good employees make risky choices without realizing it — is where most insider risk lives. And that is where visibility becomes essential.
As NIST has put it: "The insider threat is a human problem, and because of this, behavioral scientists are well-suited to help organizations deter, prevent, detect, and mitigate." (NIST/PERSEREC, 2023).
Malicious vs. Unintentional
Yes, malicious insiders exist — espionage, data theft, deliberate leaks. But they are rare. The larger risk is the scale of unintentional behavior. Hundreds or thousands of well-meaning employees, every day, making small choices that expose data in ways they never intended.
In the military we called this "high side to low side" transfer: information moving from classified systems into unclassified ones. Even when individual pieces seem harmless, combined they can become highly sensitive. The same principle plays out in business when countless small leaks add up to big exposure.
I also saw this reality when my wife worked at a bank where cell phones were banned on the floor. The concern was that someone might photograph sensitive data. But the truth is, a truly malicious insider does not need a phone. They can memorize numbers, jot details later, or find another way. Malicious behavior is incredibly difficult to prevent outright.
That is exactly why the bigger opportunity is to manage the unintentional behaviors that happen every day, at scale.
A Better Way Forward
The answer is not to distrust employees. Most want to follow the rules. The answer is visibility and context: understanding how data moves, why it moves, and when movement creates real risk. Security should create guardrails, not roadblocks.
That is how we reduce insider risk without forcing people into shortcuts. And it is how we protect sensitive information without sacrificing productivity.
CISA's Insider Threat Mitigation Guide makes this point directly, noting that insider programs should "address both unintentional and malicious acts, recognizing that well-meaning employees can pose significant risk" (CISA, 2022).
Closing Thought
Insider risk is not a relic of the 2000s or a headline about rogue employees. It is a modern business reality driven by human behavior.
The sooner we stop framing it as malice and start treating it as psychology, the better prepared we will be. Because at the end of the day, the biggest risks do not come from villains in the building.
They come from everyday people, simply trying to get their jobs done.
I would be interested to hear how others are approaching this challenge. Are you seeing more risk from deliberate insiders, or from the everyday shortcuts employees take just to get work done? Reach out if you want to compare approaches.
References
- Forrester. Internal Incidents Cause Roughly a Quarter of Breaches, With More Than Half Intentional. 2023.
- National Institute of Standards and Technology (NIST) / PERSEREC. Seven (Science-Based) Commandments for Understanding and Countering Insider Threats. 2023.
- Cybersecurity and Infrastructure Security Agency (CISA). Insider Threat Mitigation Guide. 2022.
This article was originally published on LinkedIn on September 18, 2025. This version drops the vendor pitch from the original.