Security

Insider Threat Awareness: Campaign Blueprint

Design an insider threat awareness campaign that raises signal without creating suspicion — warning signs, reporting channels, and a no-blame culture.

Updated 29 July 2026
10 min read

Insider risk is uncomfortable to campaign on. Done badly, it turns colleagues into suspects. Done well, it gives people a language for spotting warning signs, a safe way to raise concerns, and a culture where reporting is a form of care — for the person and for the business. This blueprint shows how to run one that raises signal without creating fear.

The three insider risk categories

  1. Negligent insiders. The most common by far. Well-intentioned people mishandling data, using shadow IT, or bypassing controls under pressure. Awareness works.
  2. Compromised insiders. Credentials stolen, accounts hijacked. The insider doesn't know. Awareness of the signs — unusual login prompts, unexpected access alerts — helps them raise the alarm early.
  3. Malicious insiders. Rare, but the highest impact. Usually preceded by observable warning signs — grievances, stress, unusual data access. Colleagues often see them first.

Warning signs to teach

The goal is not for colleagues to profile each other. It is for them to notice a combination of signals and know it is OK to raise it.

  • Sudden interest in areas of the business or data outside the person's role.
  • Repeated attempts to access systems they normally don't use.
  • Working unusual hours with no operational reason.
  • Large downloads or transfers to personal storage.
  • Significant behavioural change — withdrawal, agitation, financial stress publicly disclosed.
  • Openly expressed grievances tied to specific data, systems, or people.

The safe reporting model

The campaign lives or dies on the reporting channel. It must be:

  • Confidential by default. Handled by a small, named team — not published as a mass-email inbox.
  • Framed as care. Reports often result in support (financial, mental health, personal) before any security action.
  • Transparent about outcomes. Publish anonymised aggregate outcomes so people see the system is used and works.
  • Independent of the person's line manager. Escalation must never route through the subject's chain of command.

Four-week campaign structure

Week 1 — Reframe insider risk

Lead with negligent and compromised categories. Most insider risk is accidental. This removes the 'am I accusing someone?' friction that stops reports.

Week 2 — Warning signs in plain language

Use scenarios, not lists. A short animated vignette works better than a poster of red flags.

Week 3 — How to report

Publish the channel, publish the team, publish the promise: confidentiality, care-first, no line manager gate.

Week 4 — Close the loop

Share anonymised examples of past reports that led to support or a control improvement. Reporting has to feel useful, not risky.

Cultural pitfalls to avoid

  1. Framing every colleague as a potential threat. Trust collapses fast, and reports collapse with it.
  2. Turning HR concerns into security investigations by default. Route based on evidence, not category.
  3. Publishing individual cases. Even redacted, small orgs will identify the person and reporting will stop.
  4. Running the campaign once. Awareness fades in six months. Refresh annually with new scenarios.

Related resources

Turn this topic into a complete campaign

Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.