CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA urges critical infrastructure to strengthen insider threat programs against cyberattacks, data theft and sabotage

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7004

As cited

Copy frozen at (site build).

ot ics

CISA urges critical infrastructure to strengthen insider threat programs against cyberattacks, data theft and sabotage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an updated Insider Threat Mitigation Guide designed to help critical infrastructure operators establish or improve programs to counter insider threats including data theft, sabotage, and workplace violence. The guide provides a framework covering prevention, detection, assessment, response, and continuous improvement, supported by multidisciplinary teams and emphasizing both security measures and employee well-being. CISA highlights that insider threats impose substantial costs, citing a 2011 case where stolen proprietary source code cost a U.S. energy company over $1 billion in shareholder equity and nearly 700 jobs, and noting that an estimated one in seven Americans do not feel safe at work.

Why it matters: Critical infrastructure operators must evaluate and strengthen insider threat programs to protect intellectual property, prevent sabotage and cyberattacks, and reduce financial and operational losses that can exceed $1 billion per incident.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary