Insider Threat

Insider Threat
Analysis

The single greatest risk to any security program isn't the adversary at the fence line — it's the person already inside it.

Every layer of a physical protection system — detection, delay, and response — is designed against an adversary who starts outside the fence, without access, without keys, and without knowledge of how the facility actually operates. The insider threat is different in kind, not just degree: it is posed by someone who already holds some or all of what every other layer exists to deny an outsider.

This is why national regulators and international bodies alike treat the insider threat as the most significant risk a nuclear or critical infrastructure security program has to address — and why GTS treats in-depth insider threat analysis as a distinct, dedicated service rather than a subsection of a broader assessment.

The IAEA's guidance defines an insider simply as anyone with authorised access to a facility, its material, or its sensitive information — an employee at any level, or a periodic visitor such as a contractor or inspector. What makes this population uniquely dangerous is capability: an insider can use legitimate access and knowledge to understand, bypass, or defeat protective measures that would stop an outsider cold.

The One Threat No Perimeter Can Stop

Legitimate Access

An insider already holds keys, credentials, or knowledge that every other layer of defence assumes an outsider lacks.

Three Insider Categories

IAEA guidance defines unwitting, passive, and active insiders — each demanding a different mitigation approach.

Four-Part Mitigation Model

Fitness-for-duty, access authorization, cybersecurity, and physical protection combine into one complete program.

Culture-Dependent

Even the best program depends on colleagues actually noticing — and reporting — anomalous behaviour.

Why It Ranks First

The Risk Every
Other Layer Misses

0+
Years of Combined Experience
0
Insider Mitigation Program Elements
0+
International Programs

What We Deliver

In-Depth
Insider Analysis

An insider threat analysis is not a background-check audit. GTS's methodology examines the full lifecycle of trust an organisation extends to its people and contractors — before employment, during employment, and at termination — and the structural safeguards that limit what any single trusted individual could do alone, regardless of how thoroughly they were vetted going in.

Because insider risk is as much organisational and behavioural as it is technical, our assessments pair access and authority mapping with a candid review of security culture: whether personnel are actually empowered, trained, and willing to report the anomalies most insider programs depend on surfacing early.

Core Deliverables
Insider threat risk analysis. Who has access to what, what that access would allow, and where consequence-weighted insider risk actually sits.
Insider categorisation & capability mapping. Distinguishing unwitting, passive, and active insiders, since each demands a different response.
Access authorization & reliability review. Evaluating background investigation, reassessment, and behavioural observation programs.
Separation-of-duties analysis. Finding where one individual holds enough combined access to defeat a protective function alone.
Mitigation program development. Policies and oversight spanning pre-employment screening through offboarding and access revocation.
Security culture & reporting review. Testing whether personnel would actually recognise and report a colleague's anomalous behaviour.

Our Approach

Trust, Mapped
Across a Lifecycle

National regulatory frameworks reflect exactly this reality. In the US nuclear sector, licensees must maintain a formal Insider Mitigation Program combining fitness-for-duty monitoring, access authorization, cybersecurity controls over privileged access, and physical protection measures informed specifically by insider capability — not external adversary capability alone. Critical infrastructure guidance outside the nuclear sector increasingly reaches the same conclusion.

Every Other Layer Assumes an Outsider. This Is the One That Doesn't.
Insider threat findings are among the most sensitive an organisation holds. GTS handles these engagements under strict confidentiality, with reporting structured to protect the individuals and access details discussed.

Related Services

Explore More

Nuclear Programs Nuclear Security Advisory Physical protection, material control, and security culture advisory for nuclear power and nuclear weapons programs, benchmarked against IAEA Nuclear Security Series guidance. Learn More Critical Infrastructure Physical Security & Vulnerability Assessment Detection–delay–response system design, adversary path analysis, and performance testing for critical infrastructure and high-consequence facilities. Learn More New Build & Construction Critical Asset Protection: Design & Construction Advisory Security-by-design advisory for new nuclear plants and critical infrastructure — embedding physical protection into planning and construction, not retrofitting it afterward. Learn More

Concerned About Insider Risk?

Speak With
an Advisor

Contact GTS