Security News

CISA Refreshes Insider Threat Guide with New Advice on Remote Work and AI Risks

Infosecurity Magazine · 11 Sept 2026
Key Takeaway Small businesses should review CISA's updated guide and use it to build or strengthen simple insider threat awareness practices, even without a formal security program in place.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Insider Threat Mitigation Guide, first published in 2020. The revision, issued on 9 September, adds new case studies, statistics, and guidance for security and HR professionals responsible for managing insider risk, and CISA says it can be used by organisations of any size or security maturity.

The update reflects changes in how people work and the tools now available to bad actors. It expands on how hybrid and remote work arrangements affect an organisation's control over physical and digital access, and includes new material on artificial intelligence being used to manipulate or deceive employees. CISA has also added guidance on access control, visitor screening, and managing risks associated with employees leaving under difficult circumstances.

The guide is designed to help staff recognise behavioural warning signs and points organisations toward newly released CISA resources for early detection and preparedness. Scott Breor, CISA's acting executive assistant director for infrastructure security, said insider threats continue to evolve alongside technology and urged organisations to build programs that protect assets, prevent violence, reduce losses, safeguard sensitive data, and save lives. CISA said the update was shaped by feedback from industry and government partners, though no timeline was given for future revisions.

insider threat CISA workplace security AI risk access control
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.