Insider threat
Insider risk comes in three shapes and only one of them is malicious.
Somebody deliberately causing harm, somebody being careless, and somebody whose account has been taken by an outsider. The third is by far the most common and is frequently counted as an external attack, which distorts how organisations think about the problem. Controls that assume malice are unpopular; controls that assume mistakes are the same controls, framed better.
Checked against the primary source.
