TL;DR: Insider threats accounted for 12% of confirmed breaches in the 2026 Verizon DBIR, while convenience drove 60% of insider misuse and malicious insider incidents averaged $4.92 million, according to Verizon and IBM. Traditional perimeter tools miss the identity and behavioural context that distinguishes normal work from harmful data movement.
NHIMG editorial — based on content published by Cyberhaven: The 10 Insider Threat Types Every Security Team Needs to Detect
By the numbers:
- The leading motive behind insider misuse was convenience (60%), not malice or financial gain.
- The average breach cost for incidents involving malicious insiders was $4.92 million, the most expensive breach category in the IBM 2025 Cost of a Data Breach Report.
- Third-party involvement in breaches reached 48% in the 2026 Verizon DBIR, up from 30% the prior year.
Questions worth separating out
Q: What breaks when insider threat detection is not identity-aware?
A: Perimeter tools miss the difference between legitimate work and harmful activity when the account itself is trusted.
Q: Why do privileged users and contractors create the highest insider risk?
A: They already have access, so they do not need to break in before they can cause harm.
Q: How do security teams know whether shadow AI is creating insider risk?
A: Look for sensitive data moving into unauthorised models, browser extensions, or workflow tools that are not approved for that content.
Practitioner guidance
- Deploy identity-aware insider detections Correlate role, entitlements, file sensitivity, timing, and destination so alerts identify when authorised access no longer matches expected behaviour.
- Classify and block unsanctioned AI destinations Create a policy layer for approved and unapproved AI tools, browser extensions, and workflow integrations.
- Tighten privilege review around role change events Trigger access reviews when users change roles, move between projects, or leave the organisation.
What's in the full article
Cyberhaven's full blog post covers the operational detail this post intentionally leaves for the source:
- The behavioural signal table for all 10 insider profiles, including the specific indicators Cyberhaven associates with each type.
- The article's breakdown of how source code, AI tools, personal cloud accounts, and HR events map to insider threat patterns.
- The source's discussion of why traditional perimeter tools miss insider activity and how behavioural context changes detection design.
- The article's closing guidance on building insider risk management programmes around data visibility and identity awareness.
👉 Read Cyberhaven's analysis of the 10 insider threat types security teams need to detect →
Insider threat detection - are your controls identity-aware enough?
Explore further
Insider threat detection is an identity governance problem disguised as a monitoring problem. The article makes clear that the core risk is not simply hostile behaviour, but authorised access used outside intended context. That means IAM, PAM, and data controls must work together to answer who can act, what they can reach, and whether the access still fits the role. Practitioners should treat identity context as the control surface, not just a log attribute.
A question worth separating out:
Q: Who is accountable when subcontractor access remains open after a project ends?
A: The prime contractor remains accountable for proving that delegated access was removed or reduced at the right time, even when the access sat with a third party. In CMMC terms, accountability follows the organisation that claims compliance, not the external party that received the access.
👉 Read our full editorial: Insider threat detection now depends on identity-aware visibility