An insider threat assessment establishes what an organisation is actually exposed to; a maturity review establishes how well current arrangements address that exposure and what to prioritise. Unless the real threats are understood, neither the risk nor the appropriate response can be judged properly, which is why assessment is the natural starting point for most insider risk work and the most common first engagement with GSA Global.
Understanding Your Insider Risk Exposure
Insider risk is specific to each organisation. It depends on the sector, the value of the information and systems held, the workforce and contractor profile, the access model, third-party dependencies, and the current threat environment, including whether the organisation operates in a sector that hostile states actively target. A generic checklist cannot capture that, so GSA Global assessments are built around the client’s actual circumstances rather than a standard template.
What an Insider Risk Assessment Examines
Depending on scope, an assessment looks across the dimensions that together determine insider risk exposure:
- governance, ownership and cross-functional coordination;
- workforce profile, including contractors and other trusted third parties;
- access management, including privileged access and joiners-movers-leavers processes;
- technical monitoring and detection arrangements;
- personnel security, vetting and re-screening;
- physical security integration;
- culture, whistleblowing and reporting arrangements;
- investigation and response capability.
Not every assessment needs all of these. Scope is agreed at the outset against what the client needs to know.
What You Receive
Assessment outputs are written for decision-makers. Depending on the engagement, they include:
- a current-state assessment of exposure and capability;
- identified gaps against the relevant frameworks;
- a maturity position and benchmark;
- threat scenarios and priority risk themes;
- prioritised recommendations and, where appropriate, a roadmap and the basis of a business case for change.
Who Leads the Work
Assessments are led by Bill Trent, who heads GSA’s insider risk service. Where the engagement includes hostile-state and recruitment threat, Howard Nichol brings counterintelligence experience from a 30-year Army career that concluded as Head of Counterintelligence and Security. Vetting and personnel security dimensions draw on Michael Handley’s team, and technical monitoring dimensions on GSA Global’s Cyber Security and Resilience specialists.
What Happens Next
An assessment leads wherever the findings point. That may be programme improvement and governance work, a technical review of monitoring and controls, changes to vetting and re-screening, targeted training, or, occasionally, an investigation of a specific concern the assessment surfaces. It may equally conclude that current arrangements are broadly appropriate and need only modest adjustment.
Our Insider Risk Assessment and Diagnostics Capabilities