
THREAT‑WATCH
Glossary
Insider Threat
A security risk originating from someone with legitimate access, such as a current or former employee, contractor, or partner.
Insider threats can be malicious (a disgruntled employee deliberately stealing or sabotaging data) or unintentional (an employee falling for phishing, misconfiguring a system, or losing a device). Because insiders already have legitimate access, their activity often doesn't trigger the same alarms as external attackers, making behavioral monitoring and least-privilege access particularly important defenses.