Insider threats are often framed too narrowly around malicious employees.
The same risk can come from compromised credentials, a contractor with excessive access, a misconfigured privilege or simple human error.
No matter how the access was obtained, the bigger problem is how far someone can get once they are operating through a legitimate identity.
Insider threats go beyond malicious employees Focusing only on malicious employees is a costly narrowing.
It was watching what a legitimate identity did once it was already inside.