Insider Threat
The single greatest risk to any security program isn't the adversary at the fence line — it's the person already inside it.
Every layer of a physical protection system — detection, delay, and response — is designed against an adversary who starts outside the fence, without access, without keys, and without knowledge of how the facility actually operates. The insider threat is different in kind, not just degree: it is posed by someone who already holds some or all of what every other layer exists to deny an outsider.
This is why national regulators and international bodies alike treat the insider threat as the most significant risk a nuclear or critical infrastructure security program has to address — and why GTS treats in-depth insider threat analysis as a distinct, dedicated service rather than a subsection of a broader assessment.
The IAEA's guidance defines an insider simply as anyone with authorised access to a facility, its material, or its sensitive information — an employee at any level, or a periodic visitor such as a contractor or inspector. What makes this population uniquely dangerous is capability: an insider can use legitimate access and knowledge to understand, bypass, or defeat protective measures that would stop an outsider cold.
An insider already holds keys, credentials, or knowledge that every other layer of defence assumes an outsider lacks.
IAEA guidance defines unwitting, passive, and active insiders — each demanding a different mitigation approach.
Fitness-for-duty, access authorization, cybersecurity, and physical protection combine into one complete program.
Even the best program depends on colleagues actually noticing — and reporting — anomalous behaviour.
Why It Ranks First
What We Deliver
An insider threat analysis is not a background-check audit. GTS's methodology examines the full lifecycle of trust an organisation extends to its people and contractors — before employment, during employment, and at termination — and the structural safeguards that limit what any single trusted individual could do alone, regardless of how thoroughly they were vetted going in.
Because insider risk is as much organisational and behavioural as it is technical, our assessments pair access and authority mapping with a candid review of security culture: whether personnel are actually empowered, trained, and willing to report the anomalies most insider programs depend on surfacing early.
Related Services
Concerned About Insider Risk?