ABSTRACT

Insider threat is a human–computer threat that is often highly misunderstood because of the well-publicized and documented classic cases of insider threat by malicious insiders. The distinction between a virtuous employee and a wicked employee in the context of insider cybersecurity threat was not found in the literature. Insider cybersecurity threats to organizations also include organizational supporting mechanisms. Organizational understanding must focus not just on the technological factors, but also on the human factors including behaviour. Finance and logistic challenges and concerns are fairly consistent themes along with challenges in information mismanagement and policing for information assurance especially where growth in technology continues. Access to organizations is created by humans and exploited through technology. Creating an easily accessible document library or having a standardized policy area will be important that documents be shared organizationally to minimize policy gaps. Organizations should establish a warning system up to a zero tolerance for particular incidents that occur.