Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New CISA Guidance Targets Insider Threat Risks
News

New CISA Guidance Targets Insider Threat Risks

Team-CWDBy Team-CWDJanuary 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The risk posed by insiders with authorized access to sensitive systems has prompted a renewed call to action from the US Cybersecurity and Infrastructure Security Agency (CISA).

The government entity has released a new infographic designed to help organizations prevent, detect and respond to insider threats that can disrupt operations and undermine trust.

The resource is aimed at critical infrastructure operators and state, local, tribal and territorial (SLTT) governments. It outlines practical steps for building teams that can manage insider risk in a structured and coordinated way, drawing on expertise across security, legal, human resources and operational functions.

Insider threats can emerge through deliberate acts or unintentional mistakes, CISA warned. Malicious insiders may abuse access for personal gain or retaliation, while negligent behavior and human error can create vulnerabilities that external adversaries exploit. In both cases, the impact can include data loss, reputational damage and harm to people or essential services.

“Insider threats remain one of the most serious challenges to organizational security because they can erode trust and disrupt critical operations,” said acting CISA director, Madhu Gottumukkala.

“CISA is committed to helping organizations confront this risk head-on by delivering practical strategies, expert guidance, and actionable resources that empower leaders to act decisively – building resilient, multi-disciplinary teams, fostering accountability and safeguarding the systems Americans rely on every day.”

A More Secure Framework

At the center of the infographic is a framework that treats insider threat management as an essential capability rather than an optional program. CISA emphasizes that teams should be scalable, trained and embedded within existing organizational structures to reflect risk tolerance and culture.

The key benefits highlighted include:

  • Broader visibility into risk factors through varied perspectives

  • Faster recognition of patterns during incidents

  • Improved resilience as organizations grow and change

Read more on insider threat mitigation: Insider Threats Surge: What CISOs Must Know to Protect Their Organizations

The guidance sets out a four-stage model: plan, organize, execute and maintain. This approach encourages organizations to define priorities, select appropriate team members and establish clear processes before incidents occur. It also stresses the need for confidentiality, legal compliance and coordination with external partners such as law enforcement.

“Insider threats can disrupt operations, compromise safety and cause reputational damage without warning,” said CISA executive assistant director for infrastructure security, Steve Casapulla.

“Organizations with mature insider threat programs are more resilient to disruptions, should they occur.”

CISA added that effective insider threat management depends on people as much as technology. By fostering a culture of reporting and trust, organizations can identify concerns early and reduce the likelihood that internal vulnerabilities turn into major security incidents.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
Next Article CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How chatbots can help spread scams

October 14, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Managing risks to your loved one’s digital estate

April 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.