Insider Threat Awareness: Campaign Blueprint
Design an insider threat awareness campaign that raises signal without creating suspicion — warning signs, reporting channels, and a no-blame culture.
Insider risk is uncomfortable to campaign on. Done badly, it turns colleagues into suspects. Done well, it gives people a language for spotting warning signs, a safe way to raise concerns, and a culture where reporting is a form of care — for the person and for the business. This blueprint shows how to run one that raises signal without creating fear.
The three insider risk categories
- Negligent insiders. The most common by far. Well-intentioned people mishandling data, using shadow IT, or bypassing controls under pressure. Awareness works.
- Compromised insiders. Credentials stolen, accounts hijacked. The insider doesn't know. Awareness of the signs — unusual login prompts, unexpected access alerts — helps them raise the alarm early.
- Malicious insiders. Rare, but the highest impact. Usually preceded by observable warning signs — grievances, stress, unusual data access. Colleagues often see them first.
Warning signs to teach
The goal is not for colleagues to profile each other. It is for them to notice a combination of signals and know it is OK to raise it.
- Sudden interest in areas of the business or data outside the person's role.
- Repeated attempts to access systems they normally don't use.
- Working unusual hours with no operational reason.
- Large downloads or transfers to personal storage.
- Significant behavioural change — withdrawal, agitation, financial stress publicly disclosed.
- Openly expressed grievances tied to specific data, systems, or people.
The safe reporting model
The campaign lives or dies on the reporting channel. It must be:
- Confidential by default. Handled by a small, named team — not published as a mass-email inbox.
- Framed as care. Reports often result in support (financial, mental health, personal) before any security action.
- Transparent about outcomes. Publish anonymised aggregate outcomes so people see the system is used and works.
- Independent of the person's line manager. Escalation must never route through the subject's chain of command.
Four-week campaign structure
Week 1 — Reframe insider risk
Lead with negligent and compromised categories. Most insider risk is accidental. This removes the 'am I accusing someone?' friction that stops reports.
Week 2 — Warning signs in plain language
Use scenarios, not lists. A short animated vignette works better than a poster of red flags.
Week 3 — How to report
Publish the channel, publish the team, publish the promise: confidentiality, care-first, no line manager gate.
Week 4 — Close the loop
Share anonymised examples of past reports that led to support or a control improvement. Reporting has to feel useful, not risky.
Cultural pitfalls to avoid
- Framing every colleague as a potential threat. Trust collapses fast, and reports collapse with it.
- Turning HR concerns into security investigations by default. Route based on evidence, not category.
- Publishing individual cases. Even redacted, small orgs will identify the person and reporting will stop.
- Running the campaign once. Awareness fades in six months. Refresh annually with new scenarios.
Related resources
Turn this topic into a complete campaign
Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.
Related resources
How to Run a Security Awareness Campaign
Turn dry security policies into engaging, measurable campaigns. Covers phishing, password hygiene, physical security, and reporting culture.
SecurityPhishing Awareness Campaign: How to Build One That Works
A step-by-step phishing awareness campaign — baseline simulations, teachable-moment messaging, reporting culture, and metrics that actually shift behaviour.
SecurityPassword Security Awareness Campaign Guide
How to run a password security awareness campaign that actually changes habits — passphrases, MFA adoption, and password manager rollouts.