The Insider Threat You Are Not Tracking: Compromised, Not Malicious
Most insider threat frameworks focus on disgruntled employees. The more prevalent and harder-to-detect risk is the employee who has been coerced, blackmailed, or socially engineered.
Insider threat programmes are almost universally designed around a single model: the disgruntled employee who makes a deliberate decision to harm their employer. This model captures a real category of risk. It does not capture the category that is more common and considerably harder to detect: the employee who has been placed under external coercive control through blackmail, social engineering, or personal compromise, and who is providing access or information under duress rather than by deliberate intention.
The externally compromised insider presents a fundamentally different detection and response challenge. Their access patterns are often indistinguishable from legitimate activity, because they are using their legitimate access for purposes that appear, from a system perspective, entirely normal. Their behavioural indicators are often attributable to personal stress or welfare concerns rather than security risk. And they are frequently not detected until the damage is done, because their actions do not trigger the anomaly-detection rules calibrated for the malicious insider model.
The pathways to external compromise are numerous. Blackmail and sextortion create immediate coercive control with immediate leverage. Long-horizon grooming operations build relationships over months before activating the access dimension. Personal financial pressure creates vulnerability that hostile parties actively look for and exploit. And in some cases, family members of employees are the point of leverage, with the employee providing access to protect a relative rather than themselves.
The organisational response requires expanding the insider threat model to encompass external compromise as a primary risk category. This means training security teams to recognise the specific indicators of external coercion alongside those of deliberate malice; building welfare pathways that allow compromised employees to disclose their situation without facing automatic disciplinary action; and establishing intelligence-sharing mechanisms with relevant law enforcement that treat employee compromise as a serious security event.
Custodia One works with organisations to assess their insider threat architecture for gaps in the external compromise model and to build the detection, response, and welfare protocols that address this risk category effectively.
"The most dangerous insider threat in your organisation may be the employee who is most distressed about what they are being asked to do. Detection systems calibrated for malicious intent will not find them."
Custodia One Advisory Perspective
What Your Organisation Should Do
Expand your insider threat model to explicitly include the externally coerced employee as a distinct risk category
Build welfare disclosure pathways that do not automatically trigger disciplinary action: compromised employees need a route out
Train security and HR jointly on the behavioural indicators that distinguish external coercion from deliberate malice
Establish intelligence-sharing protocols with relevant law enforcement for employee compromise incidents
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
