National Insider Threat Awareness Month (NITAM) is drawing to a close. This year’s theme, “Protect Our Potential” speaks directly to the impact insider incidents can have. According to Forrester data, insider incidents account for 25% of data breaches. A third of those incidents are due to malicious intent. Yet, many organizations still don’t have dedicated insider risk management teams or functions.

Insider incidents involving intellectual property theft, sabotage, and unauthorized data exfiltration can cost organizations financially as well have impacts like ceded competitive advantage, lost opportunities, and diminished customer trust. These are organizations’ potential: the future innovations in which they’ve invested, the ability to deliver for customers, and future customer relationships.

Insider incidents can take away that potential.

Insiders have inside knowledge of their organization. They know what the crown jewels are and where they are stored. Insiders may also have some knowledge of how those crown jewels are secured. Managing insider risk requires specific focus to protect against insider incidents, detect them, and respond to them.

Forrester clients can view our Best Practices: Insider Risk Management research which provides 10 steps for establishing an insider risk management program and best practices for addressing insider risk.

AI Agents Are Insiders Too

To-date, insider risk management has only focused on human insiders. AI agents add a new type of insider due to their autonomy, decision-making ability, and access. Security teams need to be aware of the risks posed by their human insiders and the non-human insiders they create and enable.

Forrester’s AEGIS framework provides guidance for securing agentic AI across domains. Each of these domains is built to evolve with the technology, not lag behind it. AEGIS introduces principles such as least agency, continuous assurance, and explainable outcomes to help security leaders adapt to the new agentic paradigm.

Allie Mellen and I will be presenting new research focused on “rogue agents” at the upcoming Forrester Security & Risk Forum in Washington, DC. Our talk, “Defending Against Rogue Agents With AEGIS“ will overview the risks posed by AI agents operating inside enterprise environments and provide recommendations for securing these.

Connect With Me

Forrester clients with questions related to this research can connect with me through an inquiry or guidance session.

Share