IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Why insider threats are still Australia's most under-managed risk

Why insider threats are still Australia's most under-managed risk

Tue, 1st Sep 2026 (Today)
Maxime Cousseau
MAXIME COUSSEAU Founder & CISO OutsourcedCISO

Every September, National Insider Threat Awareness Month prompts the same conversation in Australian boardrooms: Do we have controls for this? The honest answer, for most organisations, is no… and not because they're negligent.

The problem is that insider threats are structurally harder to talk about than external threats. Naming it means acknowledging that the risk lives inside your own perimeter, in the hands of your staff, contractors, and trusted partners. That is an uncomfortable conversation, and most organisations defer it indefinitely.

What we see in client engagements

In my work as a fractional CISO across professional services, healthcare, financial services and technology companies, the pattern is consistent. Organisations invest meaningfully in perimeter defences (e.g. EDR, email filtering) while leaving the insider threat almost entirely unaddressed.

The most common gaps I encounter are:

  • No baseline of normal behaviour. If you don't know what normal data access looks like for a given role, you can't detect anomalies. Most organisations cannot tell you how many files a typical finance analyst downloads per week, or what a normal pattern of after-hours access looks like.
  • Overly broad access rights. Least privilege is a principle most organisations have heard of, but few actually implement. Staff routinely hold access to systems and data sets far beyond their day-to-day requirements, which means a compromised account or a disgruntled employee has far more reach than necessary.
  • No offboarding process that matches modern infrastructure. Offboarding has become significantly more complex in a cloud-first world. Revoking Active Directory credentials doesn't automatically revoke access to all SaaS platforms, shared drives, or client portals. Leavers frequently retain access to systems for weeks or months after departure.
  • Confusion between malicious and accidental insiders. Most insider incidents are not deliberate sabotage: they are accidental data exposure, misconfigured sharing settings, or well-intentioned workarounds that bypass security controls. The control frameworks that address malicious insiders are very different to those that address negligent ones. Conflating the two leads to controls that are either too draconian or too permissive.

Why the underreporting problem is real

The ASD's Annual Cyber Threat Report consistently shows that insider incidents are underreported relative to their actual prevalence. There are structural reasons for this.

First, insider incidents often don't trigger the same detection mechanisms as external attacks. There's no malware signature, no unusual source IP, no phishing email to trace. The indicators are subtler: unusual data volumes, access at atypical times, changes in communication patterns.

Second, organisations are reluctant to report insider incidents because they involve employees. There are HR implications, legal complexities, and reputational considerations that don't apply to external breaches. The instinct is to manage these quietly. 

Third, many organisations simply don't know they've had one. Without behavioural monitoring, a data exfiltration event by a departing employee may only be discovered when the data turns up elsewhere, months later, in a competitor's possession or in a regulatory investigation.

What good looks like

The good news is that baseline insider threat controls are not expensive or technically complex. The foundations are straightforward:

  1. Access reviews on a regular cycle: quarterly is reasonable for most roles, monthly for privileged access. Know who has access to what and why.
  2. Joiners, movers, leavers processes that cover SaaS: not just Active Directory. Every platform where data lives needs to be on your offboarding checklist.
  3. Data loss prevention (DLP) policies: even basic rules around bulk downloads, external sharing, or USB device use catch a significant proportion of insider incidents.
  4. A culture where it is safe to raise security concerns: employees who notice unusual behaviour from colleagues need to feel comfortable reporting it. In organisations where security is treated as a compliance exercise rather than a shared responsibility, this rarely exists.

The opportunity this September

National Insider Threat Awareness Month is a useful reminder for security teams who want to put this topic on the leadership agenda. However, the controls aren't seasonal: they need to be in place year-round.

If organisations have not reviewed access rights, offboarding processes, or DLP policies in the past 12 months, September is a good time to start. The insider threat doesn't wait for an awareness campaign.