
A Month Built Around an Uncomfortable Question
September marks National Insider Threat Awareness Month, a program the National Counterintelligence and Security Center, DHS, and the Defense Counterintelligence and Security Agency have run since 2019. It exists because the security conversation at most companies, understandably, points outward: firewalls, phishing emails, ransomware gangs. Insider risk points a different direction, toward the people already inside the building with legitimate access to everything worth protecting.
The 2025 Ponemon Cost of Insider Risks report puts real numbers behind why this deserves a month of its own. The average organization now spends $2.7 million dealing with insider incidents over a two year window, and experiences roughly eight separate incidents in that same period. Forty five percent of file security breaches trace back to a negligent or malicious insider rather than an outside attacker. Maybe the most telling figure: 60% of organizations say they couldn’t detect an insider incident within a week of it happening, meaning by the time most businesses notice, the damage has had plenty of time to compound.
None of this requires assuming your employees are a threat, most insider incidents come from carelessness, not malice: a departing employee who still has access to a shared drive, a contractor whose account never got reviewed, a well meaning staffer who moves client files to a personal cloud account to work from home. The intent barely matters once the data’s out.
Three Checks Worth Doing This Month
You don’t need a massive program to make real progress here, three practical checks cover most of the exposure:
- Access reviews. Pull a list of who has access to what, right now, and compare it against who actually needs it. Old vendor accounts and long departed employees showing up on that list is more common than most owners expect.
- Same day offboarding. When someone leaves, access should end that day, not at the end of the pay period. This is one of the simplest fixes on this list and one of the most consistently skipped.
- Basic file transfer visibility. You don’t need enterprise grade monitoring to know when large volumes of files move to an external drive or personal email account. Even basic alerting closes a real gap.
These checks sit squarely in the kind of compliance readiness work that matters well beyond any single framework. Whether or not your business is preparing for a formal audit, the underlying discipline, knowing who has access to what and proving it, is the same one regulators and cyber insurers are both increasingly asking about.
Awareness Months Only Matter If Something Changes
It’s easy to let an awareness month pass as a headline and nothing else. The businesses that get value out of September are the ones that use it as a deadline: pull the access list this week, confirm offboarding actually happens same day, and check whether anyone would even notice if a large batch of files left the building electronically.
None of that requires new hardware or a big budget line. It requires someone actually doing the review, and September is as good a prompt as any to make sure that happens.
Find Out Where You Stand
Schedule a free security assessment with Cloud9 and we’ll help you run through these checks, and quite a few more, so Insider Threat Awareness Month turns into an actual answer instead of just a headline on your calendar.
