Writing · Insider Threat

Why your biggest security risk is probably someone you trust

By Mahmoud Lotfy · Mar 2026 · 9 min read

Most security conversations start in the wrong place.

They start with hackers. With sophisticated attacks, nation-state actors, zero-day exploits. With the image of someone in a dark room, somewhere far away, trying to break through your defences.

That threat is real. But it's not usually where things go wrong.

"The threat that keeps most security professionals up at night isn't the sophisticated hacker. It's the unlocked door that nobody noticed was still open."

83% of organisations reported at least one insider attack in the last year, according to Cybersecurity Insiders' 2024 Insider Threat Report. IBM's research shows that insider-related breaches take an average of 292 days to identify and contain. Nearly ten months. In most organisations, that's long enough for significant damage to have already been done.

The breach that actually hurts tends to start much closer to home. With someone who already has the keys.

The version nobody talks about

When people hear "insider threat" they picture the disgruntled employee who steals data on their way out the door. That happens. But it's the least common version of the problem.

62% of insider incidents are attributed to negligence or compromised users, not malicious intent. The more common version looks like this:

None of these people are malicious. Most of them aren't even aware of the access they still hold. But every one of them is a risk, not because of who they are, but because of what they can reach.

Why this is harder in the Gulf

There's something specific about how businesses operate in this region that makes insider risk more acute.

Teams here are often built on personal relationships. Trust is extended quickly, and that's not a weakness, it's part of what makes the culture work. But in the absence of formal access controls, trust becomes the de facto security model. And trust is not a security model.

This is exactly the problem Zero Trust architecture was designed to address. The principle is straightforward: no user, device, or system is trusted by default, regardless of whether they're inside or outside the network. Access is granted based on continuous verification, not assumed based on identity or relationship.

93% of respondents in the 2024 Insider Threat Report said that strict visibility and control was important to them, yet only 36% actually had an effective solution in place. Most organisations are operating on the opposite assumption to Zero Trust. If you're on the inside, you're trusted. If you've been here long enough, you probably have more access than you should.

Zero Trust doesn't require a complete infrastructure overhaul to start applying. It begins with a mindset shift: stop asking "do we trust this person?" and start asking "does this person need this access, right now, for this specific task?"

The access audit nobody does

There's a simple exercise that most organisations have never done. List every person who currently has access to your critical systems, and ask whether they should.

Not whether you trust them. Whether they need it, right now, for their current role.

You'll usually find three things:

The principle behind this is called least privilege. Every person and system should have access to exactly what they need, and nothing more. It sounds obvious. Only 25% of organisations report having a fully mature insider risk programme with defined metrics and executive oversight.

What leaving looks like

Offboarding is where most organisations are most exposed. When someone leaves, the checklist tends to focus on the visible things:

What gets missed is the invisible infrastructure:

It takes 81 days on average to detect and contain an insider threat incident, according to the 2025 Cost of Insider Risks Global Report by Ponemon Institute. For a former employee with lingering access and a reason to use it, 81 days is a long time.

Three things to do this week

You don't need a consultant to start fixing this. Here's where to begin:

  1. Run an access audit. List every system, every user, every permission level. Ask whether each one is still necessary.
  2. Build an offboarding checklist. Make it systematic, not ad hoc. Every departure should trigger the same process regardless of how it ends.
  3. Apply least privilege going forward. When someone joins or changes roles, give them exactly what they need. Nothing more. Review it every six months.

This isn't about distrust

None of this requires you to treat your team like suspects. Insider risk management isn't a cultural shift, it's a handful of practical controls that most mature organisations have had in place for years.

The threat that keeps most security professionals up at night isn't the sophisticated hacker. It's the unlocked door that nobody noticed was still open.

Sources: Cybersecurity Insiders 2024 Insider Threat Report; IBM Cost of a Data Breach 2024; Ponemon Institute 2025 Cost of Insider Risks Global Report.