If you cannot explain how your organisation's insider threat controls work in practice, start by testing the assumptions behind them. These ten questions help identify gaps in ownership, access management, reporting and response that deserve further investigation.

Why insider threat risk resists normal risk methods
External threat modelling asks who might attack you and how. Insider threat collapses that question, because the threat actor and the legitimate user are the same person, using access you gave them for a reason you approved. A control that would stop an external attacker — multi-factor authentication, a firewall rule, a locked door — often does nothing against someone who is already inside the boundary with valid credentials.
This is why insider threat needs its own diagnostic, not a rebadged version of your external risk assessment. The questions below help distinguish documented arrangements from evidence that they work. They identify issues for investigation rather than proving that an insider threat is present.
The ten questions
Work through these with your leadership team, not just your security or HR lead. The answers usually differ, and the gap between them is informative.
- Can you list the roles with access sufficient to cause serious harm, without checking a spreadsheet first? If leadership cannot name them from memory, the organisation has not actually thought about who its highest-risk positions are.
- When someone resigns, is access revoked before they leave the building, not sometime after? A same-day-but-not-same-hour answer is common, and it is a gap, not a technicality.
- Do line managers know what concerning behaviour looks like, or is that left to HR and security alone? Managers see behavioural change first. If they have never been told what to watch for, that early warning is wasted.
- Is a named person, not a mailbox, accountable for acting on a reported concern within a set number of days? A reporting channel with no owner and no deadline is a control that exists on paper only.
- Have you tested whether someone could remove the customer database, the source code, or the tender file, using only the access their role already has? Most organisations have not tried this. The answer is often more alarming than expected.
- Do background checks happen more than once, or only on the first day of employment? Risk profile changes over time — financial pressure, grievance, external influence — and a single point-in-time check cannot see that.
- Can staff report a colleague's concerning behaviour without going through that colleague's manager? If the only reporting path runs through the person of concern, it will not be used.
- Is insider threat owned as its own function, or has it quietly become one person's part-time addition to an IT security role? Ownership without capacity is not ownership.
- Has anyone actually rehearsed the first 48 hours after a suspected insider incident? A written response plan that has never been exercised will fail in ways a rehearsed one would not.
- If the board asked, could you show the program changed a decision or an outcome in the last year, not just that a policy document exists? This is the question that separates a functioning control from a filed one.
A worked example: Meridian Water
Meridian Water is a fictional mid-size utility with around 400 staff split between office, treatment plant and field crews. When its risk committee worked through the ten questions, the following illustrative gaps emerged.
| Question | Meridian's answer | What it revealed |
|---|---|---|
| Q1 — high-risk roles named | Partial — SCADA operators named, but not the finance team with payment authority | Blind spot outside "obvious" technical roles |
| Q2 — same-day access revocation | No — IT ticket queue meant 24-48 hour lag | A real, fixable gap, not a policy failure |
| Q4 — named owner for reports | No — concerns went to a shared HR inbox | No accountability, no service standard |
| Q9 — rehearsed response | No — plan existed, never tested | Untested plan, unknown reliability |
None of these are dramatic findings on their own. Together, they told Meridian's committee that its insider threat program existed mainly as a document, and gave them a short, funded list of fixes rather than a vague mandate to "do more."
Common mistakes
- Treating insider threat as a subset of IT security. Data loss prevention tooling addresses one pathway. It says nothing about the finance officer under financial pressure or the contractor with a grievance.
- Building a reporting channel with no accountable owner. A hotline or inbox that nobody is measured on responding to will quietly stop being used.
- Running background checks once and calling the risk managed. Personnel risk is not static. A single pre-employment check tells you about the day someone was hired, not the person they are three years later.
- Confusing a documented policy with a working control. A practical distinction matters here: a policy that has never been tested against a realistic scenario is an assumption, not a control.
- Leaving line managers out of the design. They see the early behavioural signals. If they were not consulted when the program was built, they will not know what to escalate.
Where this sits in your broader framework
Insider threat should not be a stand-alone initiative sitting apart from the rest of your risk management. It belongs in the same risk register as your other operational and security risks, assessed with the same rigour, and reviewed on the same cycle — see our Security Risk Register Template (Free Word Download) if that register does not yet exist in a usable form. It should also be reflected in your top-level policy commitments; a one-page Security Risk Management Policy Template (Free, One Page) gives the board and executive a place to put that commitment in writing without producing another document nobody reads.
If you want to pressure-test question five properly — whether someone could actually exfiltrate the data you care about using only their normal access — a structured workshop is the right tool, and it is easy to run one badly. Twelve Ways a Bow-Tie Workshop Goes Wrong is worth reading before you schedule that session.
Organisations working under the Australian Government's Protective Security Policy Framework already have personnel security obligations to meet; the ten questions above are a useful precursor to that compliance work, not a replacement for it. Either way, the underlying discipline is the same one ISO 31000:2018 asks of any risk: identify it specifically, assess it honestly, and treat it with a control you can point to evidence for.
Get the checklist
The ten questions above can reveal gaps that need closer examination. The Insider Threat Management Evaluation Tool gives senior managers a ten-item checklist to work through the same ground in a structured, repeatable way, built to sit alongside SRMBOK's control effectiveness framework and adaptable to your sector. Download the Insider Threat Management Evaluation Tool and take it to your next risk committee meeting.
