A Holistic Approach for Insider Threat Assessment and Mitigation
Downloads
In recent times, insider threats have become one of the most complex and persistent cybersecurity challenges to manage, primarily because insiders are trusted and have legitimate access to organisational systems and data. Both public and private organisations face considerable risks of financial losses, data breaches, operational disruptions, and reputational damage resulting from malicious or negligent insiders. This study introduces the All-inclusive Threat and Organisational Mitigation (ATOM) Framework, a comprehensive and adaptable model designed to understand, detect, and mitigate insider risks through an integrated, layered, and structured approach. Unlike traditional strategies that focus narrowly on individual or technical factors, the ATOM framework aligns security measures with organisational objectives, governance policies, and regulatory compliance requirements. It emphasises proactive protection of sensitive digital assets and advocates a holistic approach that combines human behaviour analysis, technical monitoring, and organisational resilience. The framework provides practical tools and insights that assist organisations in anticipating, assessing, and counteracting insider threats more effectively. It also explores innovative analytical and technological methods to enhance detection, prevention, and response capabilities. The framework underscores the importance of proactive monitoring of human behaviours, vulnerabilities, and indicators of insider threats to close cybersecurity gaps and strengthen the resilience of critical systems and information. Additionally, the work is currently examining artificial intelligence (AI)-driven adaptive deception techniques that generate convincing fake data to mislead and monitor insider behaviour, while carefully considering associated ethical considerations.
Akinrolabu, O., Nurse, J. R., Martin, A., & New, S. (2019). Cyber risk assessment in cloud provider environments: Current models and future needs. Computers and Security, 87, 101600.
Alsowail, R. A., & Al-Shehari, T. (2022). Techniques and countermeasures for preventing insider threats. PeerJ Computer Science, DOI 10.7717/peerj-cs.938Alsowail RA & Al-Shehari T. (2021). A multi-tiered framework for insider threat prevention. Electronics. 10(9):1005, pp 1-30, DOI 10.3390/electronics10091005.
Agrafiotis, I., Nurse, J. R., Goldsmith, M., Creese, S., & Upton, D. (2018). A taxonomy of cyber-harms: Defining the impacts of cyber-attacks and understanding how they propagate. Journal of Cybersecurity, 4(1), Vol. 4, Issue 1, pp. 1 - 4.
Al-Mhiqani, M. N., Ahmad, R., Zainal Abidin, Z., Yassin, W., Hassan, A., Abdulkareem, K. H., & Yunos, Z. (2020). A review of insider threat detection: Classification, machine learning techniques, datasets, open challenges, and recommendations. Applied Sciences, 10(15), 5208, 1-41.
Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics, 12(6), 1333. Pp 1-42.
https://doi.org/10.3390/electronics12061333
Bedford, J. (2018). Organisational vulnerability to intentional insider threat. (Doctoral dissertation, University of Southern Queensland).
https://www.researchgate.net/publication/304345269 Accessed 24 July, 2024.
Boakye-Gyan, K. (2021). An Approach to a Comprehensive Framework for Insider Threat (Doctoral dissertation, Capitol Technology University).
Bilusich, D. A. N. I. E. L., Chim, L. E. U. N. G., Nunes-Vaz, R. A., & Lord, S. (2018). There is no single solution to the ‘insider’problem but there is a valuable way forward. WIT Transactions on Engineering Sciences, 121, 135-146.
Chauhan, K. (2024). Insider Threats Mitigation: Role of Penetration Testing. arXiv
preprintarXiv:2407.17346. https://www.researchgate.net/publication/382527078
Clea Ostendorf (2023), 11 Real-Life Insider Threat Examples, https://www.code42.com/blog/insider-threat-examples-in-real-life/ assessed on May 20,
Clifton, A. (2024). Strategies for Insider Threat Mitigation and Detection (Doctoral dissertation, Walden University).
Gamachchi, A., Sun, L., & Boztas, S. (2018). A graph-based framework for malicious insider threat detection. https://arxiv.org/abs/1809.00141
Gelles, MG (2016). Insider Threat: Prevention, Detection, Mitigation, and Deterrence, Butterworth-Heinemann, https://www.researchgate.net/publication/268687978 Accessed August 15, 2024.
Global cybersecurity outlook (2022) insight report
https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2022.
Greitzer, F. L. (2019). Insider threats: It’s the HUMAN, stupid! NCS ’19: Proceedings of the Northwest Cybersecurity Symposium, 1–8.
doi:10.1145/3332448.3332458
Haran, M. H. (2016). Framework Based Approach for the Mitigation of Insider Threats in E-governance IT Infrastructure. International Journal of Scientific Research, 3(4), 5-10.
Hoffmann, R., Napiórkowski, J., Protasowicki, T., & Stanik, J. (2020). Risk based approach in scope of cybersecurity threats and requirements. Procedia Manufacturing, 44, 655-662.
Homoliak, I., Toffalini, F., Guarnizo, J., Elovici, Y., & Ochoa, M. (2019). Insight into insiders and it: A survey of insider threat taxonomies, analysis, modelling, and countermeasures. ACM Computing Surveys (CSUR), 52(2), 1-40.
Inayat, U., Farzan, M., Mahmood, S., Zia, M. F., Hussain, S., & Pallonetto, F. (2024). Insider threat mitigation: Systematic literature review. Ain Shams Engineering Journal, 103068. Accessed on May 15, 2025.
ISACA Whitepaper (2021). A Holistic Approach to Mitigating Harm from Insider Threats.
https://www.isaca.org/resources/white-papers/a-holistic-approach-to-mitigating-harm-from-insider- threats on July 25, 2025.
Kara Nagel, (2021). Establishing a Foundation and Building an Insider Threat Program.
Kim, A., Oh, J., Ryu, J., & Lee, K. (2020). A review of insider threat detection approaches with IoT perspective. IEEE Access, 8, 78847-78867.
Liu, L.; De Vel, O.; Han, Q.-L.; Zhang, J. & Xiang, Y. (2018). Detecting and Preventing Cyber Insider Threats: A Survey. IEEE Commun. Surv. Tutor. 1397–1417.
Liu, J. (2020). "The Impact of Cloud Computing on Insider Threats: A Comprehensive Review." Future Generation Computer Systems, 108, 146-155.
Maasberg, M., Warren, J., & Beebe, N. L. (2015). The dark side of the insider: detecting the insider threat through examination of dark triad personality traits. In 2015 48th Max Alexander, C. I. S. M., & CRISC, C. (2018). Protect, Detect and Correct Methodology to Mitigate Incidents: Insider Threats. https://www.isaca.org/resources/isaca-journal/issues/2018/volume- 3/protect-detect-and-correct-methodology-to-mitigate-incidents-insider-threats. Accessed June 28, 2025.
Modini, J., Vanzomeren, M., Fowler, S., Joiner, K., & Lynar, T. (2020). Rising to the Challenge of Insider Threats for Middle Powers. Academic
Conferences International Limited. 92 http://dx.doi.org/10.34190/ICCWS.20.131
Nurse, J. R. C., Buckley, O., Legg, P., Goldsmith, M., Creese, S., Wright G. & Whitty, M. (2014) Understanding insider threat: A framework for characterizing attacks. Retrieved from
https://www.cs.ox.ac.uk/files/6576/writ2014_nurse_et_al.PDF.
Pureti, N. (2022). Insider Threats: Identifying and Preventing Internal Security Risks. International Journal of Advanced Engineering Technologies and Innovations, 1(2), pp.98-132.
Rafae, A., Aiche, A., & Erritali, M. (2025). Mitigating insider threats: a trust-based security framework for energy grid plants with dynamic authentication and role-based training. Cluster Computing, 28(15), 1000.
https://link.springer.com/article/10.1007/s10586-025-05652-y
Rakhi, S., Sampada, H. K., Balodi, A., Shobha, P. C., & Kumar, R. (2025). Insider Threat Detection and Prevention: New Approaches and Tools. Emerging Threats and Countermeasures in Cybersecurity, 241-262.
Rama K. (2023). The Different Types of Insider Threats and How to Stop Them.
https://www.securonix.com/blog/stop-insider-threats/. Viewed 31 August, 2024.
Safa, N. S., & Abroshan, H. (2025). The Effect of Organizational Factors on the Mitigation of Information Security Insider Threats. Information, 16(7), 538.
Schmitt, M. (2023). Securing the Digital World: Protecting smart infrastructures and digital industries with Artificial Intelligence (AI)-enabled malware and intrusion detection. Journal of Industrial Information Integration, 36, 100520.
Singleton, C. (2021). X-force threat intelligence index (Tech. Rep.). Armonk, NY: IBM.
https://www.cybersecurity-insiders.com/portfolio/2023-insider-threat-report-gurucul/
Subhani, A., Khan, I. A., & Zubair, A. (2021). Review of insider and insider threat detection in the organizations. Journal of Advanced Research in Social Sciences and Humanities, 6(4), 167-174.
Thompson, N. (2020). A unified classification model of insider threats to information security.In 31st Australasian Conference on Information Systems (pp. 1-4).
https://aisel.aisnet.org/cgi/viewcontent.cgi?article=1018&context=acis2020
Uche M. Mbanaso & Emmanuel Dandaura (2021). Mastering Cybersecurity for Professionals & Practitioners. Center for Cybersecurity Studies, Nasarawa State University, Keffi, 3rd Edition.
