Insider threats are often framed too narrowly around malicious employees.

The same risk can come from compromised credentials, a contractor with excessive access, a misconfigured privilege or simple human error.

No matter how the access was obtained, the bigger problem is how far someone can get once they are operating through a legitimate identity.

Insider threats go beyond malicious employees Focusing only on malicious employees is a costly narrowing.

It was watching what a legitimate identity did once it was already inside.