Zero Day Room
Live
Threats

CISA Updates Insider Threat Mitigation Guide

CISA has revised its Insider Threat Mitigation Guide with new case studies and guidance addressing hybrid work, AI deception, and employee separations.

CISA has revised its Insider Threat Mitigation Guide with new case studies and guidance addressing hybrid work, AI...

The Cybersecurity and Infrastructure Security Agency (CISA) updated its Insider Threat Mitigation Guide on September 9. The revision adds new case studies, statistics, and guidance focused on hybrid work, artificial intelligence, and adverse employee separations.

First issued in 2020, the guide is designed for security and human resources professionals who manage insider threat programs. CISA states any organization can use it, regardless of its security maturity. The agency said the update acknowledges the growing impact of insider threats on critical infrastructure.

Guide Simplify Format and Expands on Risks

The revised guide features a more simplify format with consolidated sections. It expands on emerging workplace trends, chiefly the rise of hybrid and remote work. The new material examines how these models change an organization's control over physical and digital access.

On artificial intelligence, the guide covers AI used to manipulate or deceive. It also adds content on access control, visitor screening, and mitigating risks from adverse employee separations.

Focus on Behavioral Indicators and Early Detection

The guide is intended to help employees understand behavioral indicators that may signal a risk. It points to newly released CISA resources supporting preparedness and early risk detection. CISA frames this as a practical starting point for organizations without an existing program.

"Insider threats continue to evolve as technology becomes more advanced," said Scott Breor, CISA's acting executive assistant director for infrastructure security. He urged organizations to build a program that "protects key assets, prevent violence, reduce losses, safeguard sensitive data, and save lives."

Broader Scope Encompasses Physical Security

CISA's framing extends beyond data loss to include physical security. Breor's statement links protecting assets with preventing violence and saving lives. The guide resides in the agency's physical security section, alongside the new material on access control and visitor screening.

Breor said feedback from industry and government partners informed the update. He encouraged organizations to review the guide and assess their own programs against it. CISA provided no timetable for future revisions.

The update arrives amid rising concern about employees and AI tools. The new AI material specifically addresses its use for manipulation or deception, rather than offering a broader assessment of the technology's role in insider incidents.

Topics

#Threats

Related coverage

More from Threats