Published research indicates around 75% of insider incidents are non-malicious, driven by negligence and credential theft rather than deliberate action. Reported costs have risen — average annual insider-related costs around $24.0 million in one regional dataset, up from $22.2 million, with a single negligent incident averaging roughly $747,000.
Take the percentages as directional. The composition finding is the one with operational consequences.
Insider Programmes Are Built For The Minority Case
The word "insider threat" evokes a disgruntled employee exfiltrating deliberately, and programmes are designed accordingly: departure monitoring, behavioural risk indicators, investigation capability.
That machinery addresses a quarter of the incidents. The other three quarters are someone forwarding a file to a personal address to work at the weekend, or clicking something and having their credentials stolen. Neither is caught by watching for grievance, and treating both under a "threat" framing pushes people to conceal mistakes.
Credential Theft Is Not An Insider Event At All
Counting credential theft as insider activity is a categorisation choice worth arguing with. The employee is a victim, not a threat, and the incident is an external intrusion using a legitimate identity — the pattern this desk has filed all year, from vishing to CRM access.
It matters because it determines where the budget goes. Classified as insider risk, it funds monitoring of staff. Classified accurately, it funds phishing-resistant authentication and session controls that would prevent it.
Where an organisation genuinely wants to reduce the 75%, the levers are ordinary and unexciting: make the secure path the convenient one, remove the need for workarounds, and make reporting a mistake safe enough that people do it quickly.
This is an analysis file built on published research, listed below. Figures are drawn from vendor and industry surveys with differing methodologies and populations; we treat proportions as directional. Corrections: corrections@forensicpost.com.