CISA Updates Insider Threat Guide to Address AI and Hybrid Work Risks
Share
The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated Insider Threat Mitigation Guide, incorporating new advice to address the risks posed by artificial intelligence (AI), hybrid work environments, and employee departures.
The revised guidance, published on 9 September, expands upon the original 2020 version to reflect a more dynamic and evolving operational landscape. The update is designed to assist security and human resources professionals, as well as organisational leaders, in identifying and mitigating risks from within their own workforces.
New Risks in AI and Remote Work
A central component of the update focuses on emerging workplace trends. CISA noted that the rise in hybrid and remote work has fundamentally altered how organisations maintain control over both physical and digital access. The guide provides specific advice on managing these shifting perimeters to prevent unauthorised access to sensitive systems.
Regarding artificial intelligence, the agency’s new material focuses on the potential for AI to be used as a tool for manipulation or deception. This addresses the growing concern that malicious actors or insiders could leverage AI to bypass traditional security controls or deceive colleagues through sophisticated social engineering.
Broadening the Scope to Physical Security
The updated framework moves beyond traditional data loss prevention to include physical security measures. The guidance covers access control, visitor screening, and the mitigation of risks associated with adverse employee separations—the period during which an employee leaves an organisation under difficult circumstances.
Scott Breor, CISA’s acting executive assistant director for infrastructure security, stated that insider threats continue to evolve alongside advancing technology. He urged organisations to implement programmes capable of protecting key assets, preventing violence, reducing losses, and safeguarding sensitive data.
The agency stated that the guide is intended for use by organisations regardless of their current security maturity. It also includes information on behavioural indicators that may signal an emerging risk, alongside resources intended to help organisations establish early detection capabilities through CISA‘s preparedness materials.




Leave a Reply