Key Takeaways
- In 2023, insider threats accounted for 19% of all data breaches according to the Verizon DBIR
- 74% of organizations experienced an insider threat incident in the past 12 months per Ponemon Institute 2022 study
- Insider actors were responsible for 20% of breaches in healthcare sector in 2022 DBIR
- The average cost of an insider threat incident is $16.2 million per IBM 2023 Cost of a Data Breach Report
- Insider breaches cost 20% more than external ones at $4.9M average per Ponemon 2022
- Malicious insider attacks average $4.88 million in losses per 2023 IBM
- 68% of insider threats are motivated by financial gain per 2023 Ponemon
- 22% of insiders act due to revenge per Proofpoint 2023 Human Factor
- Negligence accounts for 60% of insider incidents per Verizon DBIR 2023
- 65% of insider threats involve privilege misuse per 2023 DBIR
- Credential theft by insiders in 34% of breaches per IBM 2023
- Email as vector in 52% negligent insider cases per Proofpoint 2023
- 31% of insider threats occur in healthcare per IBM 2023 Cost Report
- Financial services see 28% insider breach rate per Verizon DBIR 2023
- Retail: 25% of incidents from insiders per Ponemon 2022 retail study
Insider threats are a costly and widespread risk across all industries.
Costs
Costs Interpretation
Detection
Detection Interpretation
Industries
Industries Interpretation
Methods
Methods Interpretation
Mitigation
Mitigation Interpretation
Motivations
Motivations Interpretation
Prevalence
Prevalence Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2PONEMONponemon.orgVisit source
- Reference 3IBMibm.comVisit source
- Reference 4PROOFPOINTproofpoint.comVisit source
- Reference 5CROWDSTRIKEcrowdstrike.comVisit source
- Reference 6SANSsans.orgVisit source
- Reference 7GAOgao.govVisit source
- Reference 8DELOITTEwww2.deloitte.comVisit source
- Reference 9BITSIGHTbitsight.comVisit source
- Reference 10KEEPERSECURITYkeepersecurity.comVisit source
- Reference 11SPLUNKsplunk.comVisit source
- Reference 12ENISAenisa.europa.euVisit source
- Reference 13MICROSOFTmicrosoft.comVisit source
- Reference 14SOPHOSsophos.comVisit source
- Reference 15NVLPUBSnvlpubs.nist.govVisit source
- Reference 16CISCOcisco.comVisit source
- Reference 17MANDIANTmandiant.comVisit source
- Reference 18GARTNERgartner.comVisit source
- Reference 19CYBEREASONcybereason.comVisit source
- Reference 20PALOALTONETWORKSpaloaltonetworks.comVisit source
- Reference 21FORTINETfortinet.comVisit source
- Reference 22NCSCncsc.gov.ukVisit source
- Reference 23FBIfbi.govVisit source
- Reference 24VARONISvaronis.comVisit source
- Reference 25KNOWBE4knowbe4.comVisit source
- Reference 26EYey.comVisit source
- Reference 27CSIScsis.orgVisit source
- Reference 28ATTACKattack.mitre.orgVisit source
- Reference 29GITGUARDIANgitguardian.comVisit source
- Reference 30ZSCALERzscaler.comVisit source
- Reference 31RAPID7rapid7.comVisit source
- Reference 32EDUCAUSEeducause.eduVisit source
- Reference 33REUTERSreuters.comVisit source
- Reference 34MAERSKmaersk.comVisit source
- Reference 35MEDIAmedia.defense.govVisit source
- Reference 36DRAGOSdragos.comVisit source
- Reference 37OIGoig.nasa.govVisit source
- Reference 38AMERICANCHEMISTRYamericanchemistry.comVisit source
- Reference 39DEEREdeere.comVisit source
- Reference 40CHARITYWATCHcharitywatch.orgVisit source
- Reference 41FORRESTERforrester.comVisit source
- Reference 42DARKTRACEdarktrace.comVisit source
- Reference 43CYBERARKcyberark.comVisit source
- Reference 44NETSKOPEnetskope.comVisit source
- Reference 45BROADCOMbroadcom.comVisit source
- Reference 46IDCidc.comVisit source
- Reference 47ACTIVTRAKactivtrak.comVisit source
- Reference 48HIRERIGHThireright.comVisit source
- Reference 49CPLcpl.thalesgroup.comVisit source
- Reference 50OKTAokta.comVisit source
- Reference 51EXABEAMexabeam.comVisit source
- Reference 52LOGRHYTHMlogrhythm.comVisit source
- Reference 53ONETRUSTonetrust.comVisit source
- Reference 54SAILPOINTsailpoint.comVisit source






