Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.

Thought Leadership Insider Threat
May 2026  ·  8 min read

Most small businesses invest in perimeter security and assume the threat is outside. The data tells a different story. The most financially damaging cyber incidents don't break through your defenses — they walk past them, using legitimate access your own employees already have.


In May 2025, Coinbase discovered that cyber attackers had recruited a group of their own customer support agents — employees with legitimate system access — and bribed them to hand over customer data. The attackers then used that data to impersonate Coinbase representatives, manipulating customers into sending them cryptocurrency. When the attackers contacted Coinbase demanding a $20 million ransom, the company refused to pay. The total cost — including customer reimbursements, security upgrades, and regulatory response — ran significantly higher.

Coinbase isn't a naive startup. They're one of the most security-conscious companies in the world. Their firewall didn't fail. Their perimeter didn't fail. Their people did — not through malice, but through human vulnerability to financial pressure.

This is the cyber risk most small businesses never see coming. Not because it's new — it's been the dominant threat vector for years. But because the entire security industry has spent decades selling perimeter protection, and the conversation about what happens inside the perimeter has never caught up.

88% of all cyber incidents are caused by human error — not external attackers breaking through defenses VikingCloud / Stanford Research, 2025
45% of data breaches stem directly from insider threats — employees and contractors with legitimate access Ponemon Institute, 2025
81 days average time to detect and contain an insider threat — by which point the damage is already done Ponemon Cost of Insider Risks, 2025

The three employees who are costing you the most

The outdated picture of the insider threat is a disgruntled employee deliberately stealing files on their way out the door. That person exists — but they represent only a fraction of the real risk. The Ponemon Institute's 2025 research identified three distinct insider threat profiles, and the most expensive one is the one nobody is talking about.

The Negligent Employee

55% of incidents — Ponemon 2025
The majority of insider incidents aren't malicious at all. They're caused by well-meaning employees making costly mistakes — clicking a phishing link, using a personal cloud account for work files, pasting client data into an unsanctioned AI tool, reusing a password across work and personal accounts, or misconfiguring a cloud storage bucket to be publicly accessible. These employees aren't trying to harm the company. They're trying to get their job done, and the gap between "useful" and "secure" is where the damage happens.
Real cost The average negligent insider incident costs $8.8 million annually per organization to remediate — more than many malicious attacks — because negligent incidents are frequent, often go undetected for weeks, and multiply across an entire workforce. (Ponemon 2025)

The Compromised Insider

20% of incidents — Ponemon 2025
This is the most technically sophisticated threat: an employee whose credentials have been stolen — through phishing, credential stuffing from a breached third-party service, or malware — and whose account is now being operated by an external attacker. From your security systems' perspective, everything looks legitimate. The login is from a recognized device at a normal time. The access patterns are familiar. The attacker is invisible behind a trusted identity, moving through your systems with full authorized access.
Real cost Credential theft incidents cost an average of $779,000 each — and 78% now involve cloud or SaaS platforms rather than on-premises systems, meaning traditional perimeter defenses are almost entirely irrelevant. (Ponemon 2025 / CrowdStrike)

The Malicious Insider

25% of incidents — Ponemon 2025
The classic threat — and the least common. A disgruntled employee exfiltrating client lists before leaving for a competitor. A contractor exceeding their authorized access. An employee recruited by a ransomware group — as the Medusa ransomware gang was documented doing in 2023–2024, offering employees 15% of any ransom payment in exchange for network access. The malicious insider is the hardest to catch because they know your systems, know your monitoring, and know exactly where the data is.
Real cost Malicious insider breaches were the costliest initial attack vector per incident at $4.99 million per breach — the highest of any attack category tracked by IBM's 2024 Cost of a Data Breach Report.
The most important thing to understand about the insider threat is that 75% of it is not malicious. Your employees are not your enemy — but they are your most significant financial vulnerability. The average organization experiences 13.5 negligent insider incidents per year. Not per decade. Per year. Most SMBs have no mechanism to detect any of them.

Why your firewall can't help you here

The firewall was designed to stop unauthorized access. It does that job reasonably well. But the insider threat — in all three of its forms — operates entirely within authorized access. The negligent employee who pastes client data into an AI tool is using their authorized credentials on their authorized device. The attacker operating through a compromised account has a valid username and password. The malicious insider is accessing files they have every right to access.

What your firewall stops
External attackers trying to brute-force their way in through unauthorized access attempts, known malicious IP addresses and domains, unencrypted traffic from outside the network, and automated scanning tools probing your perimeter.
What your firewall can't stop
An employee emailing sensitive files to a personal account. A compromised credential logging in from a familiar location. An employee uploading client data to an unauthorized AI tool. A departing employee downloading client lists before their last day. Any action taken by someone with legitimate access.

This isn't a criticism of firewalls — perimeter security is necessary and important. The problem is when it becomes the primary investment and the conversation stops there. Seventy-two percent of organizations lack full visibility into how employees interact with sensitive data, according to Fortinet's 2025 Insider Risk Report. More than half report they don't have adequate tools to monitor insider risk. The perimeter is defended. The inside is dark.

Fifty-six percent of companies say they lack adequate visibility into employee access to sensitive data. They know their firewall is up. They have no idea what's happening behind it. That gap — between perimeter confidence and internal visibility — is where most insider incidents live, undetected, for an average of 81 days. (Ponemon 2025 / Swif.ai)

The AI multiplier — why this is getting worse, fast

The rise of AI tools has significantly amplified every category of insider threat. The negligent employee now has dozens of powerful AI tools at their fingertips — tools that are useful, free, and actively encouraged for productivity. The problem is that those tools process whatever they're given. Client contracts. Strategy documents. Employee records. Financial projections. The data flows out through an interface that looks like a productivity tool and functions like an unmonitored data transfer.

Verizon's 2025 Data Breach Investigations Report found that 15% of employees were routinely accessing generative AI systems on corporate devices — with 72% of those accounts linked to non-corporate emails, placing them entirely outside company monitoring. This isn't shadow IT in the old sense of an employee using a personal Dropbox. It's an employee feeding your most sensitive business data to an external AI system, under terms of service you've never read, with data retention policies you've never evaluated.

And on the other side of the equation, AI is making it dramatically easier to recruit and manipulate insiders. The Coinbase case involved direct financial recruitment. But AI-powered spear phishing — personalized, convincing, indistinguishable from legitimate communications — is now being used to socially engineer employees into becoming unwitting insiders, handing over credentials or taking actions that open access without ever knowing they've done anything wrong.

What actually catches insider threats

The good news is that insider threats — especially negligent and compromised ones — leave behavioral signals. The bad news is that most SMBs have no system to read them. Here's what actually works:

1

Access control and least privilege — reduce the blast radius

The single most effective structural control. If employees only have access to what they need for their specific role, a compromised or negligent insider can only expose what they can reach. Audit access quarterly. Remove permissions that have accumulated over time. Treat admin access as a privilege that requires active justification, not a default that comes with seniority.

2

Behavioral monitoring — watch for the signals

Large data downloads outside normal hours. Access to files unrelated to an employee's role. Login from an unusual location or device. Emails to personal accounts containing attachments. These behavioral anomalies are visible signals that something is wrong — if anyone is looking. Most SMBs aren't looking.

3

AI tool policy — name the approved tools, retire the rest

Create a short approved list of AI tools with appropriate data protections. Make it easy for employees to use approved tools and clearly communicate the risk of unapproved ones. The goal isn't to ban AI — it's to ensure that when your employees use it, your client data isn't going somewhere you've never evaluated. Most SMBs have no AI tool policy at all.

4

Offboarding as a security event — not an HR formality

Third-party credentials and departed employee accounts remain active long after projects end or employment concludes. Every active account belonging to someone who no longer works for you is an unmonitored access point. Treat every departure as a security event: revoke access on the final day, audit what was accessed in the preceding weeks, recover devices before the person leaves.

5

Training that reflects the actual threat — not 2015's version of it

Employees with consistent, simulation-based security training are 7 times less likely to fall for phishing, according to Cofense research. But training that focuses only on spotting typos in emails is obsolete. Modern security training needs to cover AI tool risk, social engineering, credential hygiene, and clear reporting channels — including a culture where employees feel safe reporting mistakes without fear of punishment.

Platforms like Veriti Spottr give SMBs the external visibility piece — continuous scanning of your attack surface, identification of exposed credentials, and a CyberScore that tells you where your perimeter gaps are. That visibility is the starting point. Because you can't build internal controls until you know what your external exposure looks like — and the two threats feed each other. An attacker who finds your exposed admin page doesn't break in. They use it to steal a credential. And then the insider threat begins.

The reframe every SMB owner needs

The question "are we secure?" almost always gets answered by pointing at the firewall, the antivirus, and the password policy. Those things matter. But they answer the wrong question. The right question is: "If one of our employees made a mistake — or had their credentials stolen — right now, what could an attacker reach, and how quickly would we know?"

For most small businesses, the honest answer is: almost everything, and not for 81 days.

That's not a technology failure. It's a visibility failure. The organizations that handle insider threats well aren't necessarily the most technically sophisticated — they're the ones with the clearest picture of who has access to what, the earliest signal when something looks wrong, and the fastest response when it does.

Your firewall is working exactly as designed. The question is what's happening on the other side of it — on your payroll, on your devices, behind your trusted login screens. That's where the real risk lives. And that's where the real investment needs to go.

See what's exposed on your perimeter — before an attacker uses it to get inside. Veriti Spottr's beta is free.

Join the free beta →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

Your Password Policy Isn't Protecting You. Your Employees' Habits Are.

What Attackers Do With Your Data in the First 60 Minutes