Desk live·
ForensicPost
Cloud/Analysis/File 26-0719

Research Puts Three Quarters of Insider Incidents Down to Negligence, Not Sabotage

Research puts about 75% of insider incidents down to negligence and credential theft rather than deliberate sabotage. The programmes built to catch the other quarter are aimed at the wrong population.

Constructed geometry · not a chart of case data
TargetEnterprise organisations
ActorInsider
D. Kennedy10 min readConfidence: medium3 sources reviewed

Published research indicates around 75% of insider incidents are non-malicious, driven by negligence and credential theft rather than deliberate action. Reported costs have risen — average annual insider-related costs around $24.0 million in one regional dataset, up from $22.2 million, with a single negligent incident averaging roughly $747,000.

Take the percentages as directional. The composition finding is the one with operational consequences.

Insider Programmes Are Built For The Minority Case

The word "insider threat" evokes a disgruntled employee exfiltrating deliberately, and programmes are designed accordingly: departure monitoring, behavioural risk indicators, investigation capability.

That machinery addresses a quarter of the incidents. The other three quarters are someone forwarding a file to a personal address to work at the weekend, or clicking something and having their credentials stolen. Neither is caught by watching for grievance, and treating both under a "threat" framing pushes people to conceal mistakes.

Credential Theft Is Not An Insider Event At All

Counting credential theft as insider activity is a categorisation choice worth arguing with. The employee is a victim, not a threat, and the incident is an external intrusion using a legitimate identity — the pattern this desk has filed all year, from vishing to CRM access.

It matters because it determines where the budget goes. Classified as insider risk, it funds monitoring of staff. Classified accurately, it funds phishing-resistant authentication and session controls that would prevent it.

Where an organisation genuinely wants to reduce the 75%, the levers are ordinary and unexciting: make the secure path the convenient one, remove the need for workarounds, and make reporting a mistake safe enough that people do it quickly.

How we reported this

This is an analysis file built on published research, listed below. Figures are drawn from vendor and industry surveys with differing methodologies and populations; we treat proportions as directional. Corrections: corrections@forensicpost.com.

Sources
  1. Insider threat statistics for 2026: facts and figuresSyteca
  2. Insider threat statistics: 45+ facts on cost and riskStationX
  3. Insider threat statistics for 2026SentinelOne
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary