Meet Above at Black Hat USA | August 4-6, 2026 | Las Vegas, NV
Book a meeting
This is part 2 in a series by Israel Bryski on a CISOs perspective of modern insider risk.
Every security leader I know has their incidents that they still think about well beyond their tenure at the company. One of mine was a classic intentional exfiltration story that we have come to associate with “insider threat.” However, it wasn’t the technical signals or even the fact I had to work during Father’s Day to address it that made it memorable. It was how many human signs had been missed well before the data went out the door.
We all want to trust our employees, especially a talented and well paid senior one. After ten years of service to the company, they left - for a competitor, and not empty-handed Three weeks before they resigned, they uploaded source code that they hadn’t touched in months to a third party SaaS tool. It took a few days to become aware of the situation, much less do anything about it.. By the time the activity surfaced, the source code was already in his personal note-taking SaaS account.
The post-mortem was uncomfortable, as you can expect. But for a different reason than most people would guess.
It wasn't uncomfortable because we missed the exfiltration. We could see, with the benefit of hindsight, exactly when the data left. It was uncomfortable because by the time they started uploading, the case was already over. The behaviors that mattered, the ones that would have given us a real chance to intervene, were not visible in a single place or captured in a coherent timeline.
The signs lived in a quiet manager complaint that never made it to security, in small data aggregation actions prior to upload, in team meetings where this employee's mannerisms changed. These slightly risky actions were looked at in siloes which made them seem disconnected to each other. I recall spending hours investigating this user’s actions, manually stringing together disparate system logs, so I could document it into a coherent timeline for the user’s manager and HR. At the end of the investigation, it was deemed the employee intended to act maliciously.
The tools couldn’t catch intent - they had no context bridging these individual actions together, which is why we missed it.
The pattern I investigated had a name. I just didn't know it.
In 2015, Eric Shaw and Laura Sellers published Application of the Critical-Path Method to Evaluate Insider Risks (CPIR) in the CIA's Studies in Intelligence. ItCPIR had been in development at the insider threat arm of Carnegie Mellon’s Computer Emergency Response Team (CERT) for over a decade by then, building on Shaw's earlier work with Jerrold Post going back to 1998. What Shaw and Sellers articulated wasn't a detection model. It was a developmental one.
"a multifactorial model of accumulating risk in a person over time, incorporating predisposing factors, stressors, concerning behaviors, and maladaptive organizational response as well as mitigating factors."
The framework has five elements: personal predispositions, stressors, concerning behaviors, problematic organizational responses, and the eventual hostile act itself.
A point that was made clear was that this is an intelligence framework, not an incriminating one. One of the model's authors emphasized that the model doesn't predict who will become an insider. It describes the conditions under which someone moves closer to becoming one.
The distinction matters. It's not a profile, it's a sequence.
I want to be careful here. The point is not that struggling employees are dangerous. This research is based on retrospectives of people who did harm their employer. That’s not the same thing as stating that a person experiencing personal, professional, or financial stress should be viewed as a threat. The fact is simply that the stressors were almost always present in the cases observed. In most instances they were even visible to someone in the organization, just not to security.
These are the dispositional factors a person brings to the organization, patterns of behavior, personality traits, prior history. "Hostile insider acts were found to be perpetrated by people with a range of specific predispositions." History of rule violations. Certain personality features. Sometimes prior workplace incidents that didn't surface in background checks. The predispositions themselves are not predictive, most people with them never harm an employer. "Normal and well-adjusted individuals rarely commit hostile insider acts." But they create the soil.
In financial services, the relevant predispositions are not always exotic. They look more like a pattern of subtle policy edges over years, or an interpersonal style that creates friction with peers without ever crossing into anything actionable.
This is where the model earned my respect. "All of us have stress in our lives but in the case of insiders, significant personal, professional and financial events appear to trigger their underlying personal predispositions, leading to an increased risk of insider acts."
Stressors come in three categories: personal (a divorce, an illness, a family crisis), professional (a missed promotion, a public reprimand, a team reorganization), and financial (debt, a market loss, the impending end of a bonus cycle that won't pay what was expected). Looking back, every one of the cases I studied had at least two of these. Most had all three.
"Individuals may then exhibit problematic behaviors, such as violating internal policies or laws, or workplace misconduct."
This is the layer where most insider programs spend most of their time, and yet where most insider programs are weakest. Concerning behaviors tend to be visible to managers and peers long before they're visible to security tooling. Declining performance. increased volatility in tone, sudden interest in systems or data that doesn't match current work. "Office access at odd hours, declining performance and engagement" are the ones the literature most often cites.
The case I opened this post with had a concerning-behaviors layer that lasted a few months. Some of which was documented in the user’s performance file. Security never saw any of it. The performance reviews didn't trigger a workflow that crossed our line, that was HR’s business.
Problematic organizational responses. This is the element of the model that I think most security leaders underweight, and the one that did the most to change how I thought about my own program.
When a person on the pathway exhibits concerning behaviors, the organization responds. Sometimes, the response diffuses the situation but other times the response exacerbates it. The model catalogs maladaptive responses like "demotion without changing access" and "loss/suspension of rights and privileges,” actions that intensify a person's grievance while leaving their capacity to act on it intact.
Observing responses of an organization that can make the situation better (or resolve) vs. what are the responses that can actually make things worse is invaluable insight for preventing or detecting future incidents
In my own retrospectives, the organizational response was rarely the proximate cause of the act, but it was almost always an accelerant. A manager who handled a difficult feedback conversation poorly. An HR process that took too long. A compensation decision communicated badly. None of these were security incidents in any traditional sense, bll of them belonged in the case timeline.
Eventually, the person acts. The script, the actual technical sequence of steps that produces the exfiltration, sabotage, or fraud, is the part insider programs see best, because it's the part that touches systems. The Ponemon Insider Threat Kill Chain articulates this layer as five steps: Reconnaissance, Circumvention, Aggregation, Obfuscation, and Exfiltration.
And here is where the technical precursors finally surface in your tooling - at the very end. Searches across systems the user doesn't normally touch. Volume changes in document access. Tests of controls, small unsuccessful attempts that look like errors but are reconnaissance. Sudden cleanup of personal artifacts on a corporate device.
It is also, depressingly, where the data is most consistent. The Ponemon research, cited in SIFMA's Cybersecurity Insider Threat Best Practices Guide (3rd edition), found that 74% of malicious insiders exfiltrate sensitive data via corporate email. Not exotic channels, not dark forums - the email account the firm pays for. Most insiders, even sophisticated ones, default to the path of least resistance. (which clearly still works)
I want to address something here, because I see this misread routinely.
The Critical Pathway is not a detection algorithm. It is a heuristic for case-building, organizational design, and cross-functional conversation. CMU SEI has been explicit about this: the CPIR's "utility may lie in its ability to tell a story about the evolution of insider risk that makes sense to practitioners." The original authors are equally direct that "this framework is not a substitute for more specific risk evaluation methods" and shouldn't be used as a blanket profile.
When I see programs apply it badly, the mistake is almost always the same: treating predispositions as a watchlist criterion. That's not what the model is for, and using it that way creates more problems than it solves. The model's value is in case retrospectives, in program design, and in the conversations it forces across Security, HR, Legal, and Manager Effectiveness. Insider risk isn’t just a security problem, it’s a holistic business problem.
The single most valuable use I've personally found for the framework is post-incident. Walk a closed case backwards through the five stages. Every gap in the timeline, every place where a stressor was known to HR but not to security, every place where a concerning behavior was logged in a 360 but never escalated, every place where the organizational response made things worse rather than better, is a process gap you can actually fix.
The second-most valuable use is in the hiring conversation for the program itself. If your insider risk team is staffed entirely with former investigators, the team will be excellent at the script-and-action stages and structurally blind to the earlier ones. That's how I ended up with a homicide unit in a city full of traffic accidents. (To borrow a line from last post.)
Three things.
1. Build the program with explicit data feeds from outside cybersecurity. Identity and HR related data (the “Why now?” layer), electronic communications (the “What are they signaling?” layer), and data and file movement (the “What is leaving?” layer), among a few others. Not all of these belong in security tooling. All of them belong in a cross-functional risk review that must include the security team.
2. Invest as much in the organizational-response layer as in the detection layer.
That means training managers on how to deliver difficult feedback in ways that don't accelerate grievance, and partnering with HR on the design of processes that intersect with employees in stress. This is not work security can do alone. It's also not work security can outsource and pretend it has addressed the risk.
3. Be honest with the board that the early-stage indicators we're watching are not the ones that actually predict harm.
The paper indicators: login at odd hours, downloads over a threshold, USB device connections, are the ones we can detect because they touch systems. The working indicators, the divorce, the missed promotion, the manager who handled the feedback badly, are the ones that move people along the pathway. The gap between the two is the program's real exposure.
Next time in Part III I'll get into the insider category that breaks the model I just walked through. The Critical Pathway is a story about human grievance accumulating into action. AI agents have no grievance, they just have access, and a lot of it. The question is whether insider risk programs designed around human pathways can govern an actor with no psychology at all.