Insider threats on the rise as organisations face growing human risk

17th March 2026
Employee reviewing sensitive information

A growing number of organisations are reporting a rise in insider-driven cyber incidents, highlighting an evolving challenge for security teams across the UK and beyond.

Recent industry research indicates that 42% of organisations have seen an increase in malicious insider threats over the past year, bringing deliberate actions in line with accidental incidents as a leading cause of security breaches. This shift suggests that insider risk is no longer limited to human error, but increasingly includes intentional misuse of access.

While accidental data loss and misconfigurations have traditionally dominated insider risk conversations, the data points to a changing landscape. Security leaders are now being forced to address a more complex mix of behaviours, from negligence to deliberate data exfiltration, often within the same environments.

The findings also highlight the frequency and cost of insider-related incidents, with organisations reporting multiple incidents each month. Beyond the immediate operational disruption, these events can carry significant financial and reputational consequences, particularly where sensitive or regulated data is involved.

At the same time, many organisations are grappling with increasingly sophisticated attack methods, including the use of AI to automate or enhance malicious activity. Despite widespread recognition of this risk, preparedness remains inconsistent, with many businesses acknowledging gaps in their ability to detect or respond effectively.

Another key challenge lies in the disconnect between security controls and user behaviour. While organisations continue to invest in technology, fewer are successfully aligning these tools with security awareness and training programmes. This can leave blind spots, particularly across collaboration platforms and cloud-based services where large volumes of sensitive data are shared daily.

The reliance on native security features within these platforms further compounds the issue. Although convenient, these controls are often not designed to address the full spectrum of insider risk, particularly when it comes to identifying intent or unusual behaviour.

Taken together, these trends reinforce a clear message: human risk is now central to cyber resilience. Addressing insider threats requires more than perimeter security, it demands a joined-up approach that combines visibility, user awareness, and proactive monitoring.

As organisations continue to adapt to hybrid working, AI-driven threats, and increasingly complex digital environments, insider risk is set to remain a critical focus area for cybersecurity strategies in the years ahead.

Organisations must ensure their people, processes, and technology work together to reduce risk. Get in touch with our team to discuss how you can better protect your organisation from insider risk

Source: 2026 State of Human Risk Report