Skip to main content
Welcome to Deloitte
If we have selected the wrong experience for you, please change it above.

Insider risk management is your first line of defense

Four key actions to safeguard assets and ensure security

Key findings include2:

Negligence remains the most common form of insider threat, with 92% of organizations that track underlying intent reporting at least one negligence-related incident.

For deliberate, malicious insider threats, the most reported incident categories were:

  • Workplace harassment and violence (50%)3 is now the most commonly reported insider threat category. [VM1] [IF2]
  • Fraud (44%) and personal information theft (PII) (41%) remain among the most prevalent insider threats
  • Although less frequent, incidents involving IT sabotage (13%), foreign interference (9%), and violent extremism (9%) continue to be reported, highlighting the broad spectrum of insider risks organizations must be prepared to address.

Despite growing awareness, only 5% of organizations report having robust insider risk policies and frameworks in place.

Insider risks are an escalating threat to Canadian organizations. They jeopardize mission-critical systems, intellectual property, and employee safety. The financial and reputational costs can be significant, with organizations spending an average of US$19.5 million annually on containment and response.1 This figure represents an average cost, with the figure generally being higher for larger organizations in North America, particularly in the healthcare and IT sectors.

To address these risks, you need to implement organization-wide insider risk management: proactive and comprehensive strategies designed to detect and mitigate potential threats from within. Insider risk management strengthens detection and response controls, reducing risks from both malicious intent and accidental misuse of privileged access.

Insider risk management is no longer an emerging capability. It is rapidly becoming a cornerstone of organizational resilience strategies. Is your organization ready?

In this article, we outline four key actions to implement effective insider risk management in your organization.

Insider risk management is no longer an emerging discipline. It is increasingly recognized as an enterprise-wide risk that affects people, information, operations, reputation, and trust. The 2025–2026 Deloitte survey reveals that insider threats remain pervasive across Canadian organizations, while program maturity continues to lag behind organizational awareness.

To strengthen organizational resilience, insider risk management must evolve beyond traditional controls and reactive response measures. Organizations need integrated governance, proactive monitoring, and a people-centered approach to effectively manage insider risks.

 

Here’s how to get started.

The survey results highlight a persistent governance gap. While 51% of organizations report having a dedicated insider risk working group, only 5% have robust insider risk policies and frameworks in place. More than one-third of organizations still operate without a formal insider risk framework.

Effective insider risk management requires coordination across human resources, security, cyber, legal, compliance, physical security, fraud, and business leaders. Organizations should establish formal governance structures, define ownership and accountability, and enable ongoing information sharing across functions. Without an integrated governance model, detection efforts often remain fragmented and reactive.

By creating cross-functional working groups and executive sponsorship structures, organizations can better align risk priorities, improve decision-making, and build a sustainable insider risk capability.

Many organizations continue to manage insider risks through disconnected policies, controls, and processes. Yet the survey demonstrates that formalization remains one of the least mature areas of insider risk management. Only a small percentage of organizations report robust policies and governance frameworks capable of supporting enterprise-wide risk management.

Organizations should develop a dedicated insider risk management framework that establishes a common language, defines risk categories and behavioural indicators, and clarifies prevention, detection, response, and escalation responsibilities. The framework should integrate cyber, fraud, workplace misconduct, physical security, and broader organizational risks within a single governance model.

A structured framework enables organizations to move beyond isolated control activities toward a coordinated and repeatable program that supports long-term maturity.

The survey reveals a significant maturity gap between preventive controls and proactive detection capabilities. Access management remains one of the most mature capabilities across sectors, while behavioural monitoring and continuous detection capabilities continue to lag. UEBA adoption is improving, but only half of organizations have reached an operational level of maturity.

Organizations should complement traditional preventive measures with risk-based monitoring capabilities capable of identifying concerning behavioural patterns before incidents occur. This includes monitoring high-risk activities, strengthening escalation processes, and integrating behavioural indicators into detection workflows.

The objective is to transition from a reactive posture focused on incidents that have already occurred to a proactive posture focused on emerging indicators of risk. Notably, the survey shows that no sector has yet achieved a mature proactive posture, highlighting a significant opportunity for improvement. 

The data reinforces a recurring theme: insider risk remains fundamentally a people issue. Negligence continues to be the most common underlying driver of insider incidents, while workplace harassment and violence emerged as one of the fastest-growing incident categories in this year's survey.

As a result, organizations should expand their focus beyond technology controls and invest in awareness, education, and behavioural risk management. Training programs, reporting mechanisms, and leadership engagement remain relatively immature across many organizations and represent critical opportunities to strengthen organizational resilience.

Creating a culture in which employees understand insider risk, recognize concerning behaviours, and feel empowered to raise concerns is essential for long-term program success. Organizations that successfully combine people-focused initiatives with strong governance and modern detection capabilities will be best positioned to manage the evolving insider risk landscape.

Take the first steps now

An effective insider risk management approach not only protects critical assets and aligns with national security imperatives, but also strengthens organizational resilience and reinforces internal trust.

Deloitte can help your organization unlock insider risk management ROI with a sourcing-first strategy to secure talent, trust, and transformation.

Read the Insider risk management in Canada - findings from Deloitte 2024-2025

Connect with us to get started.

  1. Ponemon Institute and DTEX, 2025 Ponemon Cost of Insider Threats Global Report, 2025.
  2. The results highlight several trends; however, they should be interpreted in the context of a larger sample size, changes in industry representation, and the fact that maturity levels are based on respondents’ self-assessments of their organizations’ capabilities. As a result, observed differences in maturity may reflect both changes in the composition of survey participants and differences in how organizations perceive and evaluate their own capabilities. Any extrapolation between industry sectors should be undertaken with caution.
  3. Workplace harassment and violence emerged as the most frequently reported insider threat category in the 2025-2026 survey. This result should be interpreted with caution, as it appears to be influenced by broader government-sector reporting trends. In Canada's federal public service, reported cases of workplace harassment and violence increased by 13% in 2023, reaching 2,129 cases. See: https://www.cbc.ca/news/politics/workplace-harassment-violence-federal-public-service-1.7178188.

Did you find this useful?

Thanks for your feedback