SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Cybersecurity chiefs warn of evolving insider threats

Cybersecurity chiefs warn of evolving insider threats

Thu, 3rd Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Cybersecurity Executives Warn on Evolving Insider Threat Risks. Industry Leaders Link the Shift to Generative AI, Executive Impersonation and Data Visibility Gaps.

Security leaders are using Insider Threat Awareness Month to highlight how trusted insiders, both human and machine, now sit at the centre of some of the most complex cyber risks facing organisations. Executives from Vetric, Gravwell, CYGNVS and Cobalt describe a landscape in which attackers exploit identity, data and video, while companies give AI agents growing autonomy inside core systems.

Executive impersonation sits near the top of the agenda. Deepfake-style video is moving from public disinformation campaigns into targeted fraud aimed at employees already working in high-pressure digital environments.

"Executive impersonation is a growing insider threat method. Attackers can now combine publicly available video with knowledge of an organization's leadership, processes and culture to create highly convincing requests. A familiar face and voice can make an urgent instruction from a CEO, for example, to transfer funds, disclose sensitive information or bypass a control, feel legitimate, particularly when it appears through video platforms employees already use and trust. Falsified videos circulating online could also trigger unfounded internal and external reputational concern, depending on the content. This Insider Threat Awareness Month, organizations should focus on how legitimate insiders can be manipulated or tricked into believing fraudulent information. They need verification processes that do not depend on a video's apparent authenticity. Investigators, meanwhile, need visibility into how impersonation content is created, distributed and coordinated across difficult-to-monitor platforms. Video intelligence tools can help close those coverage gaps and identify patterns of harmful activity, enabling organizations to respond before a convincing impersonation causes widespread damage," said Amit Shuster, VP, Product and Engineering, Vetric.

Insider incidents often unfold slowly across multiple systems, and security teams frequently struggle because no single alert or log entry carries enough weight on its own.

"Insider threat activity often originates from people and systems that are already trusted. The warning signs rarely appear in a single alert or data source, which makes them especially difficult to detect. They emerge when security teams connect activity across identity, network, endpoint, cloud and other telemetry over time. That makes broad, full-fidelity visibility especially important. If critical data is filtered out, discarded or never collected because of cost or architectural limitations, teams may discover during an investigation that the context they need is simply gone. Insider Threat Awareness Month highlights the need for organizations to think beyond collecting alerts and focus on whether investigators can actually access and interrogate the data when it matters. Security teams need the freedom to retain diverse telemetry, look back historically and ask new questions of that data as an investigation evolves. You can't predict which piece of information will prove decisive in advance, so building a security data strategy around preserving visibility gives defenders a much stronger foundation for detecting, investigating and responding to insider activity," said Mike Wade, VP, Customer Success, Gravwell.

Several experts now argue that AI agents firmly belong in the insider risk category. Organisations are giving software-based agents credentials, transactional authority and access to sensitive information at increasing speed.

"Organisations are giving AI agents broad access to corporate systems and data, and unlike human insiders, they move at machine speed. They do not need malicious intent to cause serious damage. An agent pursuing the wrong objective, or the right objective without proper guardrails, can create a security, legal or regulatory crisis before the human response team even understands what happened. That gives Insider Threat Awareness Month a new twist. Different human insider situations require different response playbooks, and AI makes that challenge far more complex. Organisations are deploying agents faster than they are developing playbooks for when those agents cause harm, if they are building them at all. Response teams need answers before an incident occurs: Who has the authority to stop an agent? How do we contain it? What evidence do we preserve? What legal or regulatory obligations are triggered? They also need a trusted place to run that response. If the systems and communications you normally rely on are implicated in an AI incident, you do not want to collaborate on your response inside them. An out-of-band command centre gives security, IT, legal, communications and executives a separate environment to take control, contain the incident and make decisions when speed and trusted coordination matter most," said Arvind Parthasarathi, CEO and Founder, CYGNVS.

Testing and validation practices are also under scrutiny as non-human insiders gain more autonomy. Security teams are reassessing how they measure exposure once an identity, human or machine, enters the environment.

"Organisations are now giving AI agents credentials, access to internal systems and authority to take actions. Those agents are effectively non-human insiders. While we saw rogue agents in the OpenAI Hugging Face incident, AI agents can also operate exactly as designed but with more privilege and agency than anyone realized. That changes what insider-threat testing needs to look like. Going beyond identity access management, we need to understand what that identity can ultimately accomplish once it gets in. Autonomous pentesting gives defenders a way to safely test that blast radius, emulating what an over-privileged or compromised agent could discover, access, chain together, modify or exfiltrate at machine speed. The biggest lesson for this year's Insider Threat Awareness Month: before you give AI autonomy, test its authority. Monitoring can tell you what an agent did, but adversarial testing tells you what it could do," said Gunter Ollmann, CTO, Cobalt.