07/27/2026 | News release | Distributed by Public on 07/27/2026 08:16
By Gregg Wartgow, Special to the Association of Equipment Manufacturers (AEM) --
A lot of cybersecurity attention is directed toward outside hackers, and rightfully so. But insider threats can't fall off the radar.
The Cybersecurity and Infrastructure Security Agency (CISA) defines "insider threat" as a person who could use their authorized access or special understanding of an organization to harm that organization. The harm could be the result of malicious intent, but also the result of an unintentional act of negligence.
"Regardless, this type of event negatively affects the organization, its data, personnel, facilities, or resources," said Chris Brogger, program specialist for the Infrastructure Security Division of CISA, which is a component of the Department of Homeland Security (DHS). "Insider threats manifest in many ways, including fraud, theft, embezzlement, and workplace violence."
Employees represent the most obvious type of insider threat. But ultimately, an insider could be anyone the organization trusts and has access to systems and information.
Brogger said inside threat actors often go after information that is relatively easy to access, yet has a lot of value, i.e. blueprints, schematics, marketing plans, etc. Sometimes the intention is malicious, perhaps to sell the information to a competitor. Sometimes the insider threat's actions are unintentional, like inadvertently leaving an important document in a hotel room. Regardless, the insider threat actor's actions can cause harm to an organization.
Brogger said there are two types of malicious insider threat actors.
Collusive threats are when an insider collaborates with an outsider. Brogger said foreign adversaries like to target U.S. manufacturers. Outside threat actors often approach employees with bribes or blackmail. Sometimes they deploy phishing attacks to establish these employee connections.
Third-party threats are when informal members of an organization, such as vendors and contractors, have been granted some level of access to facilities, systems, networks, and people.
Along with the access they've been granted, third-party insider threats introduce another layer of risk.
"When granting certain access to a third party, keep in mind that you're also inheriting their potential vulnerabilities," Brogger said. "That's something to consider when you're establishing new business relationships with third parties. What are their cybersecurity best practices, and what kind of training do they do? It's important to look at those things before granting them access to your information."
Brogger said the best line of defense against insider threats is a good work culture and observant employees.
"When you notice something that seems odd, don't just brush it off," Brogger advised.
To that point, Brogger said it's important for companies to have work cultures that encourage employees to raise concerns without fear of retaliation. Clear processes for confidential reporting should be in place, and it must be clear that company leadership supports it.
This is the second installment in a two-part series on strengthening cybersecurity in manufacturing Check out the first article here.
AEM members have exclusive access to help them stay on top of emerging issues and trends via member education webinars. Experts break down industry issues and pinpoint critical changes in the landscape to help attendees refine their company's strategy.
For more information on the upcoming series of member education webinars, contact your Account Success Advisor.