CISA has refreshed its Insider Threat Mitigation Guide, issued on 9 September 2026, with new case studies, statistics and guidance addressing hybrid and remote working, artificial intelligence and adverse employee separations. First published in 2020, the guide aims to support security and human resources professionals running insider threat programmes and is pitched as usable by organisations at any security maturity level.
The update emphasises the growing impact of insider threats on critical infrastructure and adds new use cases for a dynamic and evolving operational landscape.
The revised guide is presented in a more streamlined format with consolidated sections, and expands on workplace trends such as hybrid and remote work and how they alter control over physical and digital access. It also adds material on AI used to manipulate or deceive, guidance on access control and visitor screening, and strategies to mitigate risks associated with adverse employee separations.
CISA notes the resource is designed to help employees recognise behavioural indicators that may signal risk and points readers to newly released resources to support preparedness and early risk detection. Agency officials, including acting executive assistant director Scott Breor, urge organisations to review the guide and assess their programmes accordingly, while noting there is no timetable for further revisions.