5 Questions with Insider Risk Expert Shibu Thomas  

Insider risk has always been difficult to manage because it starts with something every organization needs to operate: trust. 

Today, that trust extends beyond employees. Privileged users, contractors, third parties, compromised identities and increasingly AI-enabled systems can all interact with sensitive data and critical environments. 

For Shibu Thomas, that makes insider risk one of cybersecurity’s most consequential, and least understood, challenges. 

With more than 25 years of experience helping government agencies and national security organizations strengthen cybersecurity and insider threat programs, Shibu works with customers to build resilient insider risk capabilities that protect mission-critical environments. He also serves as an Industry Chair with Advanced Technology Academic Research Center (ATARC) and collaborates with Insider Risk Practitioners Alliance (IRPA) to help advance best practices for insider risk management. 

Ahead of our virtual strategic session: Insider Risk – When Trust Becomes the Attack Surface, we asked Shibu five questions about what’s changing, where organizations are struggling and what a mature insider risk program looks like today.

1. Why is insider risk becoming harder to manage? 

Shibu: Insider risk has become one of the most consequential, and least understood, challenges in cybersecurity. 

It can be a compromised credential weaponized within minutes. A well-meaning user pasting sensitive information into a public generative AI tool. A trusted vendor whose access becomes the breach vector. Increasingly, we also have to consider agentic AI systems acting autonomously inside environments and blurring the line between human intent and machine behavior. 

And this isn’t theoretical. We’re seeing insider risk incidents around the world involving individuals with legitimate or trusted access. 

The technology is evolving, but technology alone doesn’t solve insider risk. Culture, process and people matter just as much. 

2. What do you mean when you say, “trust is becoming the attack surface”? 

Shibu: That’s what makes insider risk so difficult. 

Organizations put significant effort into establishing trust. Employees go through interviews, vetting and, in national security environments, potentially extensive background checks before being granted security clearances and access to sensitive systems. 

But trusted access doesn’t eliminate risk. 

A legitimate user might intentionally exfiltrate sensitive data through webmail or cloud storage. They could inadvertently share information with a public generative AI tool. Someone could be socially engineered or financially motivated to provide access or exfiltrate data. We now also need to consider people using AI agents to perform actions on their behalf. 

So, we can’t stop at asking whether someone is trusted. We need to understand what they’re doing with that trust. 

3. Where are insider risk programs falling short today? 

Shibu: One area I keep coming back to is what I’d call investigative paralysis. 

Organizations invest in monitoring. They identify an incident of concern. And then they freeze. 

At that point, you’re no longer dealing with only a technology problem. You’re dealing with a people and process problem. HR wants to be involved. Legal wants to be involved. Managers may struggle to believe it’s one of their people. By the time everyone agrees on what to do, the damage may already be done. 

The second challenge is ownership ambiguity. 

Insider risk sits at the intersection of IT, security, HR, legal and sometimes physical security. When everyone owns it, nobody owns it. There are still organizations debating which team should lead the response or whose budget an insider risk program should come from. 

The third challenge is visibility. 

Organizations may believe they’re monitoring their environment, but they’re really monitoring what their existing tools allow them to see. When activity moves outside that visibility perimeter, risk can go with it. 

That is also why simply checking the box with tools an organization already owns isn’t enough. Insider risk requires the right technology, but it also requires dedicated people and processes that can operate at scale. 

4. How are Zero Trust and compliance changing insider risk management? 

Shibu: Zero Trust changed the conversation from “Who should we trust?” to “How do we continuously validate trust?” 

Identity alone isn’t enough. A legitimate, authenticated user can still misuse legitimate access. 

It also exposes an important gap between access and behavior. Zero Trust can help determine whether someone should have access. Insider risk management helps determine whether they’re using that access appropriately. 

That distinction is pushing behavioral analytics and continuous monitoring closer to the center of modern security strategies. 

At the same time, compliance frameworks are acting as a forcing function. 

Organizations can no longer treat insider risk as an informal practice or a “nice to have.” There are growing expectations around governance, monitoring and accountability that organizations need to document and demonstrate. 

The conversation is moving from “Should we invest in insider risk?” to “How do we build the capability, and how do we prove that it works?” 

5. What does a mature insider risk program actually look like? 

Shibu: If I walked into a government agency or system integrator tomorrow, the first question I’d ask would be simple: 

Do you have a dedicated insider risk program with people specifically assigned to it? 

Not security generalists who handle insider risk when they have time. People whose job it is. 

That answer alone tells me a lot. 

From there, I’d look at three things. 

First, is there a defined process for what happens when activity is flagged? Monitoring and alerting are only the beginning. The organization needs a clear human workflow for what happens next. 

Second, are the different stakeholders, security, HR, legal and others, actually working together, or are they operating in separate lanes? 

Third, has the organization ever tested the program through an insider risk tabletop exercise or simulation? 

If a program has never been stress-tested against a realistic insider scenario, it may exist on paper without being ready for what happens in the real world. 

The Definition of an Insider Is Expanding 

So, what happens next? 

Shibu doesn’t believe the rise of AI means the traditional insider threat disappears. Quite the opposite. 

Malicious, negligent, compromised and departing employees will continue to present risk. Organizations can’t become so focused on AI agents, synthetic identities and emerging technologies that they lose sight of the human behaviors they’ve been managing for years. 

What is changing is the scope of the challenge. 

The next phase of insider risk won’t just be about monitoring what trusted people do. Organizations will increasingly need to understand what humans, identities and autonomous systems can do on each other’s behalf. 

The definition of an insider is expanding. Insider risk programs need to evolve with it. 

Continue the Conversation  

Join Shibu Thomas for Insider Risk: When Trust Becomes the Attack Surface as he explores how insider risk is evolving, why traditional approaches can fall short and what government, defense and system integrator organizations can do to build more proactive and resilient insider risk programs.