If you cannot explain how your organisation’s insider threat controls work in practice, start by testing the assumptions behind them. These ten questions help identify gaps in ownership, access management, reporting and response that deserve further investigation.

Look for gaps across the whole system: Review access; Test reporting and response; Check whether controls work.
An insider threat programme needs evidence of effectiveness.

Why insider threat risk resists normal risk methods

External threat modelling asks who might attack you and how. Insider threat collapses that question, because the threat actor and the legitimate user are the same person, using access you gave them for a reason you approved. A control that would stop an external attacker — multi-factor authentication, a firewall rule, a locked door — often does nothing against someone who is already inside the boundary with valid credentials.

This is why insider threat needs its own diagnostic, not a rebadged version of your external risk assessment. The questions below help distinguish documented arrangements from evidence that they work. They identify issues for investigation rather than proving that an insider threat is present.

The ten questions

Work through these with your leadership team, not just your security or HR lead. The answers usually differ, and the gap between them is informative.

For each answer, ask for the latest test, sample or incident record: what was checked, by whom, when, and what failed? These are control-effectiveness questions, not a score for having a programme. Use role-appropriate controls and approved personnel processes; personal circumstances alone do not establish an insider threat.

  1. Can you list the roles with access sufficient to cause serious harm, without checking a spreadsheet first? Test whether leaders can identify the critical roles and produce a current, owned access record. Recall alone does not establish whether that control works.
  2. When someone resigns, is access revoked before they leave the building, not sometime after? Check revocation against the approved departure time and circumstances. Resignation does not always mean immediate departure; access should end when authorised work ends, or earlier where an approved response requires it.
  3. Do line managers know what concerning behaviour looks like, or is that left to HR and security alone? Managers see behavioural change first. If they have never been told what to watch for, that early warning is wasted.
  4. Is a named person, not a mailbox, accountable for acting on a reported concern within a set number of days? A reporting channel with no owner and no deadline is a control that exists on paper only.
  5. Have you tested whether someone could remove the customer database, the source code, or the tender file, using only the access their role already has? Most organisations have not tried this. The answer is often more alarming than expected.
  6. Do background checks happen more than once, or only on the first day of employment? Check whether changes in role or exposure trigger a proportionate review under approved personnel processes. Re-screening should follow applicable requirements, rather than becoming indiscriminate monitoring.
  7. Can staff report a colleague’s concerning behaviour without going through that colleague’s manager? If the only reporting path runs through the person of concern, it will not be used.
  8. Is insider threat owned as its own function, or has it quietly become one person’s part-time addition to an IT security role? Ownership without capacity is not ownership.
  9. Has anyone actually rehearsed the first 48 hours after a suspected insider incident? A written response plan that has never been exercised will fail in ways a rehearsed one would not.
  10. If the board asked, could you show the programme changed a decision or an outcome in the last year, not just that a policy document exists? This is the question that separates a functioning control from a filed one.

A worked example: a hospital with rotating clinical staff

At fictional Meridian Hospital, locums move between wards, agency staff finish shifts overnight and equipment vendors need limited maintenance access. The risk committee tests controls against those working arrangements, rather than counting how many policies exist.

Question Evidence and control gap Possible register entry
Q1: which roles could cause serious harm? The privileged-role list covers IT administrators but misses bulk patient-record exports by clinical reporting staff. Unrestricted bulk export could allow an authorised user to disclose patient records beyond their clinical purpose.
Q2: when does access end? A sample of completed locum engagements shows records access still active two days after the agreed end time. A former locum could access patient information after their authorised work ends because the roster-to-IT offboarding trigger fails.
Q4: who acts on a concern? The reporting inbox has no named cover during weekends. A reported misuse of patient records could continue while the concern waits unassigned.
Q9: has response been rehearsed? The exercise cannot establish who can suspend a suspect account while preserving necessary clinical access. An untested containment decision could delay response or interrupt legitimate care.

The clinical operations director owns the offboarding hand-off, IT tests access removal against the agreed end time, and the privacy lead assigns weekend triage cover. The committee records owners, dates and evidence needed to close each gap. The findings justify control improvements; they do not accuse individual staff of wrongdoing.

Common mistakes

Where this sits in your broader framework

Insider threat should not be a stand-alone initiative sitting apart from the rest of your risk management. It belongs in the same risk register as your other operational and security risks, assessed with the same rigour, and reviewed on the same cycle — see our Security Risk Register Template (Free Word Download) if that register does not yet exist in a usable form. It should also be reflected in your top-level policy commitments; a one-page Security Risk Management Policy Template (Free, One Page) gives the board and executive a place to put that commitment in writing without producing another document nobody reads.

Organisations working under the Australian Government’s Protective Security Policy Framework already have personnel security obligations to meet; the ten questions above are a useful precursor to that compliance work, not a replacement for it. Either way, the underlying discipline is the same one ISO 31000:2018 asks of any risk: identify it specifically, assess it honestly, and treat it with a control you can point to evidence for.

Free working resource

Test whether the arrangements work

The Insider Threat Management Evaluation Tool is a PDF with ten high-level criteria and further reading to help develop checks for your setting. Use the criteria alongside actual control evidence and record gaps for assessment.

Download the free insider threat PDF checklist

Opens the SRMBOK product page. Add the free item to your cart and complete the $0 order to receive the download. Check the newsletter choice at checkout.