Cybersecurity Insights: Recognizing the Risk of Insider Threats

Share:

7/27/2026

Glowing padlock icons connected across a blue digital grid background.By Gregg Wartgow, Special to the Association of Equipment Manufacturers (AEM) --

A lot of cybersecurity attention is directed toward outside hackers, and rightfully so. But insider threats can’t fall off the radar.

The Cybersecurity and Infrastructure Security Agency (CISA) defines “insider threat” as a person who could use their authorized access or special understanding of an organization to harm that organization. The harm could be the result of malicious intent, but also the result of an unintentional act of negligence.

“Regardless, this type of event negatively affects the organization, its data, personnel, facilities, or resources,” said Chris Brogger, program specialist for the Infrastructure Security Division of CISA, which is a component of the Department of Homeland Security (DHS). “Insider threats manifest in many ways, including fraud, theft, embezzlement, and workplace violence.”

Employees represent the most obvious type of insider threat. But ultimately, an insider could be anyone the organization trusts and has access to systems and information.

Brogger said inside threat actors often go after information that is relatively easy to access, yet has a lot of value, i.e. blueprints, schematics, marketing plans, etc. Sometimes the intention is malicious, perhaps to sell the information to a competitor. Sometimes the insider threat’s actions are unintentional, like inadvertently leaving an important document in a hotel room. Regardless, the insider threat actor’s actions can cause harm to an organization.

Brogger said there are two types of malicious insider threat actors.

Collusive threats are when an insider collaborates with an outsider. Brogger said foreign adversaries like to target U.S. manufacturers. Outside threat actors often approach employees with bribes or blackmail. Sometimes they deploy phishing attacks to establish these employee connections.

Third-party threats are when informal members of an organization, such as vendors and contractors, have been granted some level of access to facilities, systems, networks, and people.

Along with the access they’ve been granted, third-party insider threats introduce another layer of risk.

“When granting certain access to a third party, keep in mind that you’re also inheriting their potential vulnerabilities,” Brogger said. “That’s something to consider when you’re establishing new business relationships with third parties. What are their cybersecurity best practices, and what kind of training do they do? It’s important to look at those things before granting them access to your information.”

Brogger said the best line of defense against insider threats is a good work culture and observant employees.

“When you notice something that seems odd, don’t just brush it off,” Brogger advised.

To that point, Brogger said it’s important for companies to have work cultures that encourage employees to raise concerns without fear of retaliation. Clear processes for confidential reporting should be in place, and it must be clear that company leadership supports it.

This is the second installment in a two-part series on strengthening cybersecurity in manufacturing Check out the first article here

About Member Education Webinars  

AEM members have exclusive access to help them stay on top of emerging issues and trends via member education webinars. Experts break down industry issues and pinpoint critical changes in the landscape to help attendees refine their company’s strategy.   

For more information on the upcoming series of member education webinars, contact your Account Success Advisor.  

AEM Updates

For more AEM news and updates, subscribe to the AEM Industry Advisor.

Related Articles

Global Compliance in Focus Part 4: Key Takeaways from JTLM 2026

For 36 years, theJoint Technical Liaison Meeting (JTLM) has helped provide product compliance professionals in the non-road equipment manufacturing industry with the requisite...

At Ag in Motion, AEM Brings Agriculture Innovation and Policy Priorities to Life

AEM brought high-ranking Canadian government officials and agriculture media together with leading equipment manufacturers at Ag in Motion, near Saskatoon, Saskatchewan, for a...

AEM’s Enhanced Regulatory Activity Dashboard Puts Compliance Intelligence at Your Fingertips

Staying up-to-date and informed on timely and relevant regulatory issues has never been easier for AEM members. The association’s Safety & Product Leadership team is pleased to...

Federal Resources to Help Manufacturers Strengthen Cybersecurity

By Gregg Wartgow, Special to the Association of Equipment Manufacturers (AEM) --American manufacturers remain a top target of cyber criminals, particularly in the case of...

Global Compliance in Focus Part 3: Key Takeaways from JTLM 2026

For 36 years, the Joint Technical Liaison Meeting (JTLM) has helped provide product compliance professionals in the non-road equipment manufacturing industry with the requisite...

View all AEM Updates