Join our Newsletter — 33% off our NHI Course

What do organisations get wrong when they try to stop insider threats with VPNs and firewalls alone?

The common mistake is treating insider risk like an external perimeter problem. VPNs and firewalls help against outside intrusion, but they do not stop someone who already has legitimate access from misusing it. Insider defense needs access restriction, session visibility, and behaviour monitoring so organisations can detect misuse inside the trusted boundary, not just block traffic at the edge.

Why VPNs and firewalls miss the real insider problem

VPNs and firewalls are boundary controls, so they are strongest when the question is whether to let a connection in from outside. Insider threats are different because the actor is already inside the trusted path, often using valid credentials, normal protocols, and approved devices. That means the failure is usually one of trust, privilege, and visibility, not simple perimeter blocking.

Once access is granted, an insider can often move through systems without triggering an edge denial. A firewall may allow the traffic, and a VPN may make the session look routine, but neither one tells you whether the activity is appropriate for the person, time, system, or data involved.

What effective insider defence has to add

Stopping insider misuse requires controls that limit what a trusted user can do, record what they actually do, and surface behaviour that departs from normal patterns. The practical shift is from network access alone to access governance, session visibility, and detection of misuse against the business process the user can reach.

That usually means combining least privilege, time-bounded access, and reviewable activity logs with alerting that looks for unusual data movement, privilege escalation, or access at odd times. If the control stack cannot tell you who did what inside the session, it is too thin to manage insider risk.

Why perimeter-only thinking creates blind spots

Perimeter controls can create a false sense of security because they measure ingress and egress, while insider incidents often unfold through legitimate workflows. The risk is especially high where shared files, privileged admin tools, remote access channels, or sensitive repositories can be reached without a second layer of contextual control.

Organisations also underestimate how long misuse can remain invisible when logs are sparse, sessions are not tied to purpose, and managers rely on ticket approval as proof of legitimacy. The result is not simply an access issue, it is an assurance gap that lets harmful but permitted activity blend into ordinary operations.

  • The 52 NHI breaches Report shows how misuse of trusted access can become a material breach path once privilege is excessive or poorly governed.
  • CISA cyber threat advisories is a useful external reference for understanding how trusted access paths are abused in real incidents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC — Access Control Insider risk here depends on limiting what trusted users can reach and do.
DE.CM — Continuous Monitoring The question hinges on visibility into misuse inside trusted sessions.
DE.AE — Anomalies and Events Insider threats often surface as unusual behaviour within valid access paths.
Recommendation — Enforce least privilege and review access paths that insiders can use to reach sensitive assets. Monitor user activity and session behaviour for signs of misuse beyond edge traffic. Tune detections for unusual access timing, volume, and data movement by legitimate users.
NIST Zero Trust (SP 800-207) SC-4 — Policy Enforcement Point Zero Trust shifts enforcement from the perimeter to continuous policy decisions.
SC-3 — Access to Resources Insider defence needs resource-level control, not just network admission.
Recommendation — Place policy enforcement around each request and session rather than relying on network location. Grant access per resource and context so trusted users only reach what they truly need.
CIS Controls v8 6 — Access Control Management The issue is excessive or poorly governed access for already authenticated users.
8 — Audit Log Management Session visibility and traceability are central to detecting insider misuse.
12 — Network Infrastructure Management VPNs and firewalls are network controls, but they must be paired with stronger access governance.
Recommendation — Restrict, review, and remove access paths that let insiders exceed their job need. Collect and retain audit evidence that can reconstruct insider activity inside the trusted boundary. Harden network access points while avoiding reliance on them as the primary insider control.
MITRE ATT&CK T1078 — Valid Accounts Insiders and compromised insiders abuse legitimate accounts to bypass perimeter controls.
T1021 — Remote Services VPN-enabled remote access can be used as a normalised path for insider abuse.
Recommendation — Hunt for misuse of valid accounts across internal systems and administrative tools. Inspect remote access usage for unusual destinations, timing, and session patterns.

Practitioner Guidance

What to prioritise: Start with the accounts and sessions that can reach the most sensitive data or administrative functions. If those paths are not tightly scoped, monitored, and reviewable, VPN and firewall placement adds very little practical protection.

What to verify: Confirm that you can distinguish ordinary use from suspicious use using logs, alerts, and access policy, not just network origin. If a reviewer cannot reconstruct what happened inside the session, the control set is not yet mature enough for insider defence.

Common mistake: Treating remote access controls as a substitute for privilege control. A trusted channel does not make trusted behaviour, and that distinction is where insider programmes usually fail.

Practitioner takeaway: Insider defence should be judged by how well it constrains and explains actions after access is granted, because the edge can only block outsiders, it cannot by itself govern misuse from within.