GSA Global provides insider risk management services to organisations that need to understand, reduce and respond to the risks created by trusted access. We help clients assess their exposure, build and govern insider risk programmes, strengthen personnel security and detection, investigate suspected insider incidents, and prepare people at every level to recognise and report concerns.

The service is led by Bill Trent and draws on GSA specialists in counterintelligence, security vetting, cyber security, investigations and organisational culture.

What Is Insider Risk?

Insider risk is the potential for harm arising from people who have legitimate access to an organisation’s systems, information, assets or facilities. That includes employees, but also contractors, suppliers and other trusted third parties.

The harm is not always deliberate. Insider incidents arise from:

  • malicious activity, such as theft of data or sabotage;
  • negligent or inadvertent behaviour, which accounts for a large share of incidents;
  • individuals who have been compromised, coerced or recruited by an external party, including hostile states and organised criminal groups.

“Insider risk” is deliberately broader than “insider threat”. A threat usually refers to a specific individual or activity; insider risk describes the wider exposure an organisation carries through trusted access, and it is the exposure, not just the individual, that a programme has to manage.

Why Insider Risk Requires a Coordinated Approach

Insider risk cuts across functions that rarely share a complete picture. HR sees behavioural and employment signals. IT and cyber teams see access and activity data. Security holds physical controls. Legal and privacy govern what data can be collected and used. Procurement manages the third parties who increasingly hold privileged access from outside the organisational perimeter.

In many organisations, responsibility is fragmented across these functions: cyber teams tend to treat insider risk as a technology problem, HR as a vetting or employee-care issue, and leadership as an operational matter to delegate. This can create gaps in how concerns are identified, shared and managed. Behavioural indicators may be visible to managers, colleagues or HR before related activity becomes apparent through technical monitoring, and where functions do not share information, those early indicators can be missed.

Effective insider risk management therefore starts with governance and coordination, not with tools. That principle runs through every GSA engagement.

Our Insider Risk Capabilities

Insider Risk Assessment and Diagnostics

Most client relationships start with an assessment. GSA provides:

  • insider threat reviews: a structured evaluation of the threat environment specific to the client’s sector, workforce, access model and third-party dependencies;
  • insider risk maturity assessments: an evaluation of the current programme against recognised frameworks, with a prioritised path to improvement;
  • pre-incident diagnostics: targeted assessments for periods of elevated risk such as restructuring, redundancy or M&A.

Contact us

Insider Risk Programme and Governance

An insider risk programme is a set of deliberate decisions about ownership, policy, escalation and coordination, made before any technology is deployed. GSA designs and improves programmes from the governance level down: executive sponsorship, roles and responsibilities, cross-functional working arrangements between HR, legal, security and IT, the handling of privacy and behavioural data, and integration with board and enterprise risk reporting.

Contact us

Personnel Security and Vetting

Vetting is a foundational control within insider risk management, not a complete programme in itself. Pre-employment screening establishes who is being given trusted access; higher-tier vetting for sensitive and executive roles, contractor and third-party screening, and periodic or continuous re-screening keep that picture current as roles, access and personal circumstances change.
GSA’s Security Vetting capability is led by Michael Handley, and is designed to feed into the wider insider risk programme rather than sit apart from it.

Contact us

Insider Risk Monitoring and Detection

Monitoring technology matters, but it is one component of insider risk management, not a substitute for it. GSA helps clients define what their detection capability needs to find, the risk scenarios and use cases, before any platform choice, and provides independent advice on DLP, SIEM and user behaviour analytics, including reviews of technology already in place.

Contact us

Insider Threat Investigations and Response

Some concerns need to become investigations. Suspicious access, misuse of information, suspected data theft, fraud, undeclared conflicts or indications that an individual may have been compromised all call for careful, independent fact-finding, conducted with proper regard for the individual, since many alerts turn out to reflect innocent or inadvertent behaviour.

Where an insider concern requires formal investigation, GSA can draw on its wider Investigation Services capability, subject to the scope and requirements of the matter.

Contact us

Insider Risk Awareness, Culture and Training

Colleagues, line managers and HR are often well placed to notice a developing problem early. GSA delivers staff awareness, manager and HR training, executive and board briefings, and tabletop exercises that test how an organisation would handle an insider incident. We also review culture and whistleblowing arrangements, because a trusted speak-up route can surface a concern before technical monitoring does.

Contact us

Foreign State Targeting and Counter-Compromise

Hostile states and sophisticated criminal groups deliberately target individuals: recruiting, coercing or compromising people with valuable access, and in some cases placing operatives inside organisations as hired employees or contractors. High-risk personnel, and people travelling to higher-risk jurisdictions, face particular exposure.

GSA’s counter-compromise capability, led by Howard Nichol, formerly the British Army’s Head of Counterintelligence and Security, is designed to address this threat through foreign state recruitment awareness, travel-related compromise briefings, confidential support for individuals who receive suspicious approaches, and the design of trusted reporting channels. Awareness for high-risk populations is covered under Insider Threat Awareness and Training.

Contact us

If you want to understand your organisation’s current insider risk exposure, review an existing programme, or discuss a specific concern, contact GSA to discuss your requirements in confidence.

Speak to GSA about Insider Risk Management

When Organisations Review Insider Risk

Insider risk usually comes under scrutiny when something changes. Common triggers include:

  • restructuring, redundancy programmes or divestitures, which create stressed employees and changing access models;
  • mergers and acquisitions, particularly the months immediately after completion;
  • holding sensitive intellectual property or client information that others want;
  • heightened geopolitical exposure in the sectors hostile states target;
  • growing reliance on contractors, outsourced providers and other third parties with privileged access;
  • an insider incident, at the organisation or at a peer;
  • regulatory scrutiny of governance and controls;
  • deployment of new monitoring technology that raises privacy, works-council or employee-trust questions;
  • a recognition that existing arrangements are fragmented across HR, security, cyber and legal, with no single owner.

None of these automatically means an organisation has a problem. Each is a sensible reason to test whether current arrangements match the threat as it now stands.

How GSA Approaches Insider Risk

GSA’s approach is integrated in a specific, practical sense: the disciplines that insider risk spans sit inside one firm and work as one programme.

  • Programme leadership and governance: Bill Trent leads insider risk strategy, programme design and board-level advisory.
  • Counterintelligence: Howard Nichol brings direct operational experience against hostile state intelligence services and insiders.
  • Personnel security: Michael Handley’s vetting operation feeds screening and re-screening outputs into the wider programme.
  • Cyber: GSA’s Cyber Security and Resilience team supports technical monitoring, access controls and cyber-enabled insider activity.
  • Investigations: where a concern becomes a case, independent fact-finding can be drawn from GSA Investigation Services, with scope agreed for each matter.
  • Culture and whistleblowing: Dr Brian Moore QPM advises on the organisational conditions that determine whether people speak up.
  • Physical security context: where insider activity has consequences for premises or people, GSA’s protective services capability is available.

The starting point depends on the client. An organisation with no formal programme usually begins with an assessment; one with an established programme may need a technical review, a specific investigation or a maturity benchmark. GSA does not assume every engagement leads to a programme build.

Our Insider Risk Team

Bill Trent, Managing Director, Insider Risk lead. Bill leads GSA’s insider risk service. He advises organisations on insider risk management, cyber security, resilience and major incidents, drawing on extensive experience supporting global organisations and government agencies. He is also leading the Insider Risk UK collaboration, an initiative working towards a UK Insider Risk Management Collaboration Centre and closer links with established insider risk centres in the US, Canada and Australia.

Howard Nichol, Director of Operations. Howard served for 30 years in the British Army, concluding as the Army’s Head of Counterintelligence and Security. He specialised in human intelligence and counterintelligence operations against hostile state intelligence services, insiders, terrorist and extremist groups and organised crime, and now advises organisations on insider risk and tailored security programmes.

Michael Handley, Managing Director, Security Vetting. Michael brings more than two decades of senior British policing experience across major crime, fraud investigation, protection and intelligence-led operations, followed by extensive corporate security work. He leads GSA’s Security Vetting capability and specialises in personnel risk across employees, contractors and other trusted individuals.

Dr Brian Moore QPM. Brian advises on organisational culture, whistleblowing and insider behaviour, and on the leadership and governance conditions that shape organisational risk. His doctorate is in whistleblowing.

Cyber and investigations specialists. Mark Raeburn supports engagements requiring senior cyber security and resilience experience, and Anthony Dickinson supports technical delivery, security controls and technical assurance. Where an insider matter becomes an investigation, GSA’s Investigation Services team leads the investigative work.

Insider Risk Across the Organisation

Insider risk connects naturally to several other GSA services. The connections below exist because the problems genuinely overlap.

  • Cyber Security and Resilience: technical monitoring, access control, compromised accounts and cyber-enabled insider activity sit at the intersection of the two disciplines.
  • Investigation Services: independent fact-finding, including OSINT, when a concern or alert becomes an investigation.
  • Security Vetting: pre-employment and ongoing personnel security controls that feed the insider risk picture.
  • Whistleblowing: trusted reporting arrangements can identify behavioural concerns before technical monitoring does.
  • Crisis Management: a serious insider event can develop into a wider organisational incident requiring coordinated leadership, legal, technical and communications response.
  • Close Protection and Protective Services: an insider can expose information about executives, residences, routines or protective arrangements.
  • Travel Risk Management: high-risk travel increases opportunities for targeting, coercion and recruitment.

Frequently Asked Questions (FAQs)

What is insider risk management?

A structured approach to identifying, assessing and reducing the risks posed by people with legitimate access to an organisation’s systems, information, assets or facilities. It combines governance, personnel security, monitoring, investigation capability, training and culture.

What is the difference between insider risk and insider threat?

Insider risk is the broader exposure created by trusted access. An insider threat is a specific individual or activity presenting potential harm. Managing the risk well reduces the chance that a threat develops into an incident. The discipline is described both as insider risk management and insider threat management; in practice the two terms are used largely interchangeably.

What causes insider risk?

Three broad drivers: deliberate malicious action; negligence or inadvertent behaviour; and compromise, where individuals are recruited, coerced or otherwise influenced by an external party. Each requires a different programme response.

How can an organisation identify insider threats?

By combining indicators rather than relying on one source: personnel security and vetting data, access and technical monitoring, behavioural signals visible to managers and colleagues, and trusted reporting channels.

What should an insider risk management programme include?

Clear governance and ownership, risk assessment, personnel security and vetting, proportionate monitoring and detection, investigation and response arrangements, training and awareness, and a working agreement between HR, legal, security and IT on how behavioural data is handled.

Is insider risk just a cyber-security issue?

No. Technical detection matters, but insider incidents are often preceded by human signals that do not appear in system logs. Governance, culture, personnel security and HR involvement are equally important.

What role does HR play in insider risk management?

HR holds much of the earliest signal, including performance, grievance, conduct and wellbeing information, and manages the employment processes through which concerns are handled fairly. An effective programme gives HR a defined role alongside security, legal and IT.

How does employee vetting support insider risk management?

Screening establishes and refreshes confidence in the people given trusted access. It is one control within the programme; on its own it does not manage insider risk, because insiders often act on opportunities or pressures that arise after joining.

Can GSA investigate a suspected insider threat?

GSA can support the independent investigation of suspected insider incidents, drawing on its Investigation Services capability, with the scope of each matter agreed at the outset.

How can GSA assess our existing insider risk capability?

Through an insider threat review, a maturity assessment or a pre-incident diagnostic, depending on what has prompted the question.

Contact us

Complete the form here and we will get in touch with you to discuss your requirements.






    Subscribe to our newsletter to keep up to date with all the latest news

    Areas of interest

    Marketing permissions

    Please select all the ways you would like to hear from GSA Global:

    You can unsubscribe at any time by clicking the link in the footer of our emails. For information about our privacy practices, please see our privacy policy.

    We use Mailchimp as our marketing platform. By subscribing, you acknowledge that your information will be transferred to Mailchimp for processing. Learn more about Mailchimp's privacy practices.

    GSA Global