Medium New version us

CISA releases updated Insider Threat Mitigation Guide addressing hybrid work and AI risks

Original title: CISA Releases Updated Insider Threat Mitigation Guide

CISA released an updated version of its Insider Threat Mitigation Guide, originally published in 2020, to address evolving threats in the modern operational landscape. The updated guide includes new case studies, statistics, and consolidated sections covering emerging workplace trends such as hybrid and remote work, AI-enabled manipulation and deception, access control, visitor screening, and managing risks during employee separations. Organizations across all security maturity levels can use this guide to assess their insider threat programs and implement recommended mitigation steps to protect key assets, prevent violence, safeguard sensitive data, and reduce losses.

What changed

  • Guide restructured in more streamlined format with consolidated sections and enhanced content delivery designed for continued relevance and better information accessibility
  • New case studies and statistics added to demonstrate insider threat scenarios and provide practical examples for organizations to learn from
  • Expanded coverage of hybrid and remote work arrangements as operational trend affecting insider threat risk assessment and program design
  • New guidance on AI-related risks, including detection and mitigation of AI used to manipulate or deceive employees and systems
  • Enhanced sections on access control, visitor screening protocols, and mitigation strategies for adverse employee separations (offboarding risks)

Who is affected

All organizations regardless of security maturity level. Particularly relevant for security professionals, human resource leaders, and managers responsible for insider threat programs in critical infrastructure sectors and organizations handling sensitive data.

Action
Action required
Language
EN

Frameworks

CISA

Open the original source