
In May 2024, a former employee of FinWise Bank used retained system access to infiltrate the bank's records, ultimately exposing sensitive data belonging to approximately 689,000 customers, including Social Security numbers, dates of birth, and account numbers. The most alarming detail in the entire incident was not the scale of the exposure. It was the timeline. FinWise did not detect the suspicious activity until June 2025, more than a year after the unauthorized access began, according to reporting on the breach. The access that caused the breach was never revoked when the employment relationship ended.
This is the defining characteristic of insider risk, and the reason it requires a fundamentally different approach than the controls organizations build to stop external attackers. The threat does not need to break in. It already has a key.
Insider risk is frequently discussed as though it describes a single category of malicious behavior: an employee deliberately stealing data to sell or sabotage. The reality is broader and, in most organizations, the majority of insider incidents are not malicious at all.
According to the 2025 Cost of Insider Risks Global Report, conducted by the Ponemon Institute and sponsored by DTEX Systems, three distinct risk profiles account for insider incidents: negligent insiders, malicious insiders, and credential thieves who use stolen insider credentials to operate as though they belong inside the organization. The negligent category is by far the largest. An employee forwarding a sensitive file to a personal email account for convenience, a contractor with access nobody reviewed in months, a password reused across a personal account that was already compromised in an unrelated breach: none of these involve intent to cause harm, yet all of them create the same exposure as a deliberate attack.
Insider risk has grown sharply both in frequency and in financial consequence. The 2025 Ponemon and DTEX report, based on data from 349 organizations and over 8,300 security practitioners, found that the total average annual cost of insider risk incidents reached $17.4 million per organization in 2025, up from $16.2 million in 2023 and more than double the $8.3 million recorded when the study began in 2018. North American organizations bear the heaviest burden, spending an average of $22.2 million annually addressing insider-related incidents.
The volume of incidents has grown in parallel. The number analyzed in the most recent study reached 7,868, more than double the 3,269 incidents recorded in the 2018 study. The financial impact of containment delay is stark: incidents contained within 31 days cost an average of $10.6 million, while incidents that took longer than 91 days to contain averaged $18.7 million, nearly double the cost simply because detection was slow.
Not every insider profile carries the same financial signature. Negligent incidents are far more frequent, averaging 13.5 per organization annually, but each one costs less individually. Malicious insiders and credential thieves are rarer but considerably more expensive per incident, with IBM's 2025 Cost of a Data Breach Report placing the average cost of a malicious insider breach at $4.92 million, making it the most expensive single category of breach origin IBM tracks. The practical implication is that prevention budgets need to address both ends of the spectrum: broad controls that catch the high-volume negligent cases, and targeted controls that catch the rarer but more damaging malicious and credential-theft cases.
The Ponemon and DTEX research found that the average insider incident now takes 81 days to contain, an improvement from 86 days in the prior year but still long enough for substantial damage to accumulate before anyone notices. The FinWise case illustrates why detection lags so badly: an insider, or someone using an insider's retained credentials, is operating inside systems that are specifically designed to trust authenticated users. There is no perimeter to breach and no malware signature to catch. The activity looks exactly like normal use, because in a meaningful sense, it is normal use, performed by someone who should not have access anymore.
According to the same research, organizations spend an average of $211,021 per incident on containment but only $37,756 on monitoring, a ratio that helps explain why detection takes so long. Money is being spent reactively, cleaning up after an incident is discovered, rather than proactively, on the visibility that would catch the incident sooner. Organizations with mature insider risk management programs report meaningfully different outcomes: 65% say their program was the only security strategy that allowed them to pre-empt a breach by detecting insider risk before it escalated.
Most security architecture is built around a clear assumption: the threat is outside the perimeter, and the job of the security stack is to keep it there. Insider risk inverts that assumption entirely. The party that causes the incident already has legitimate credentials, already understands where sensitive data lives, and already knows what controls are in place to avoid.
This creates a detection problem that is structurally different from detecting an external intrusion. A firewall, an intrusion detection system, and endpoint protection are all built to recognize unauthorized access attempts. None of them are well suited to recognizing that an authorized user is doing something they should not be doing, because from a pure access-control perspective, nothing unauthorized has occurred. The access itself is valid. The behavior is the problem, not the credential.
CrowdStrike's 2025 Global Threat Report found that insider threat operations accounted for 40% of incidents the firm investigated, with adversaries increasingly recruiting insiders directly rather than relying solely on technical exploitation. This includes cases of employees being offered payment in exchange for credentials or access, blurring the line between a negligent insider and a deliberately recruited one.
A handful of recurring patterns account for most insider risk incidents, and each one points toward a specific, addressable control gap.
Retained access after departure. The FinWise case is the clearest illustration: an employee's access remained functional well after their employment ended, and nobody noticed until the resulting breach had already been underway for more than a year. Offboarding that does not include immediate, verified revocation of every system the departing employee touched leaves a door open indefinitely.
Privilege that outlives its purpose. Access is frequently granted for a specific project, engagement, or role, and then never revisited once that purpose ends. A contractor who needed access to a single folder for a three month engagement may still have that access two years later, simply because nobody scheduled a review.
Credential reuse and theft. IBM's X-Force Threat Intelligence Index 2025 found that 30% of attacks now use valid account credentials as the initial access vector, and infostealer malware delivered via phishing increased 84% year over year. These are technically external attacks, but they are functionally indistinguishable from insider misuse once the attacker is inside, because the system sees a valid, authenticated login.
Convenience-driven workarounds. Negligent insider behavior is rarely about indifference to security. It is usually about a sanctioned process being slower or more cumbersome than an unsanctioned alternative. An employee who emails a file to a personal account or uploads it to an unapproved cloud service is very often solving a real workflow problem the organization's own systems failed to solve for them.
It is tempting to treat negligent insider behavior as a character failure: an employee who simply was not careful enough. That framing rarely survives contact with the actual circumstances. An employee who emails a sensitive file to a personal account is very often trying to work from home over a weekend, using the only tool that let them do it in the moment. A contractor who saves files to an unapproved cloud service is usually trying to collaborate with someone outside the organization who has no other way to receive them. The sanctioned process was either unavailable, too slow, or did not account for the situation the employee was actually in.
This reframes a meaningful share of insider risk reduction as a design problem rather than a discipline problem. If the secure, sanctioned path to move a file is slower or more cumbersome than the insecure workaround, a percentage of employees will choose the workaround, not because they are careless, but because the organization built a process that loses to convenience. Security and IT teams that treat every negligent incident as a training failure, rather than asking whether the legitimate path was actually usable, tend to see the same patterns repeat indefinitely, because the underlying workflow gap was never addressed.
A distinct and growing category of insider risk does not originate from carelessness or from a long-standing grievance. It originates from direct recruitment by an external party. CrowdStrike's 2025 Global Threat Report noted adversaries increasingly approaching employees directly, offering payment in exchange for credentials or system access, rather than relying solely on technical compromise. A widely reported case involved a BBC employee being offered a cut of a ransom payment in exchange for their login credentials.
This blurs a distinction that security architecture often treats as clean: insider versus external threat. The person providing access is, on paper, an insider. The motive, planning, and ultimate beneficiary of the breach are external. The practical implication is that insider risk programs cannot be built purely around detecting accidents and disgruntled behavior. They also need to account for the possibility that an otherwise unremarkable employee has been offered money to become the entry point, which is a different psychological and detection problem than catching a mistake.
The imbalance between containment spending and monitoring spending, $211,021 per incident on cleanup against just $37,756 on visibility, is not simply a resource allocation quirk. It reflects how most organizations fund security work: reactively, after an incident has already forced the issue, rather than proactively, before one occurs. A monitoring investment is difficult to justify to a budget committee in the abstract, because its value is measured by incidents that did not happen. A containment cost is impossible to avoid funding, because the incident is already underway and visible to everyone.
This creates a structural trap. Organizations spend the least where spending would do the most good, and the most where spending is, by definition, too late to prevent the damage that already occurred. Reversing that ratio is less a technology purchase than a budgeting decision, and the Ponemon and DTEX data on organizations with mature insider risk programs suggests it pays for itself: those organizations report measurably faster detection and a meaningfully higher rate of pre-empting incidents before they become breaches.
There is a real tension worth naming directly. Insider risk programs that feel like blanket surveillance, monitoring every keystroke, treating every employee as a suspect by default, can erode the trust that makes a workforce resilient in the first place. Heavy-handed monitoring correlates with higher turnover and lower morale, and a workforce that feels distrusted is not a workforce that reports anomalies, near misses, or its own mistakes. A negligent insider who is afraid of punitive consequences for admitting an error is far less likely to disclose it early, which is exactly when disclosure would do the most good.
The organizations that manage this tension well tend to draw a clear distinction between monitoring access to sensitive systems, which is a legitimate and necessary control, and monitoring employees as people, which tends to backfire. Visibility into who accessed what, from where, and in what volume is a system-level control. It is not the same thing as treating every employee interaction as evidence of guilt until proven otherwise, and conflating the two is one of the more common ways well-intentioned insider risk programs damage the culture they were meant to protect.
Insider risk is not a problem that can be solved by better screening of new hires or more security awareness training, although both have a role to play. It is also not solved purely by adding more technical controls, since the controls that govern access and detect anomalies are necessary but address only half the problem.
The other half is organizational: whether the sanctioned way of doing work is actually usable enough that employees choose it over a workaround, whether security spending is funding visibility before an incident or cleanup after one, and whether a monitoring program builds enough trust that people report their own mistakes early rather than hiding them. FinWise's year-long blind spot was a process failure as much as a technical one. Closing the gap between when insider risk begins and when it is noticed requires treating both halves of the problem, the technical and the organizational, as part of the same effort, rather than assuming a control list alone will catch a threat that, by definition, already has a key.


