An insider threat assessment establishes what an organisation is actually exposed to; a maturity review establishes how well current arrangements address that exposure and what to prioritise. Unless the real threats are understood, neither the risk nor the appropriate response can be judged properly, which is why assessment is the natural starting point for most insider risk work and the most common first engagement with GSA Global.

Understanding Your Insider Risk Exposure

Insider risk is specific to each organisation. It depends on the sector, the value of the information and systems held, the workforce and contractor profile, the access model, third-party dependencies, and the current threat environment, including whether the organisation operates in a sector that hostile states actively target. A generic checklist cannot capture that, so GSA Global assessments are built around the client’s actual circumstances rather than a standard template.

What an Insider Risk Assessment Examines

Depending on scope, an assessment looks across the dimensions that together determine insider risk exposure:

  • governance, ownership and cross-functional coordination;
  • workforce profile, including contractors and other trusted third parties;
  • access management, including privileged access and joiners-movers-leavers processes;
  • technical monitoring and detection arrangements;
  • personnel security, vetting and re-screening;
  • physical security integration;
  • culture, whistleblowing and reporting arrangements;
  • investigation and response capability.

Not every assessment needs all of these. Scope is agreed at the outset against what the client needs to know.

What You Receive

Assessment outputs are written for decision-makers. Depending on the engagement, they include:

  • a current-state assessment of exposure and capability;
  • identified gaps against the relevant frameworks;
  • a maturity position and benchmark;
  • threat scenarios and priority risk themes;
  • prioritised recommendations and, where appropriate, a roadmap and the basis of a business case for change.

Who Leads the Work

Assessments are led by Bill Trent, who heads GSA’s insider risk service. Where the engagement includes hostile-state and recruitment threat, Howard Nichol brings counterintelligence experience from a 30-year Army career that concluded as Head of Counterintelligence and Security. Vetting and personnel security dimensions draw on Michael Handley’s team, and technical monitoring dimensions on GSA Global’s Cyber Security and Resilience specialists.

What Happens Next

An assessment leads wherever the findings point. That may be programme improvement and governance work, a technical review of monitoring and controls, changes to vetting and re-screening, targeted training, or, occasionally, an investigation of a specific concern the assessment surfaces. It may equally conclude that current arrangements are broadly appropriate and need only modest adjustment. 

Our Insider Risk Assessment and Diagnostics Capabilities

Insider Threat Review

The threat review is the outward-looking assessment: a structured evaluation of the threat environment specific to the client, covering sector, workforce profile, access model and third-party dependencies. It draws on open-source intelligence and GSA Global’s own insight, and includes an assessment of geopolitically motivated insider risk and the relative likelihood of state-sponsored recruitment activity against the client’s workforce.

The output is a set of plausible but severe scenarios that give leadership a concrete understanding of the insider challenges the organisation needs to address.

Contact us about a Insider Threat Review

Insider Risk Maturity Assessment

The maturity assessment is the inward-looking counterpart: a collaborative evaluation of the current programme across governance and ownership, HR and cultural controls, technical monitoring and detection, physical security, vetting and access management, and third-party risk. It is benchmarked against recognised UK and international frameworks and standards, including NPSA guidance, CISA’s insider risk programme evaluation and relevant ISO standards.

The report sets out whether insider-related exposures sit within the organisation’s risk tolerance and, where they do not, provides the basis of a business case for capability development and investment decisions.

Contact us about a Insider Risk Maturity Assessment

Pre-Incident Diagnostics

Some circumstances raise insider risk sharply and temporarily. A pre-incident diagnostic is a targeted, time-bounded assessment for those windows:

  • planned restructuring or redundancy programmes;
  • mergers, acquisitions and divestitures, especially the integration period;
  • a material change in business or geopolitical exposure.

The diagnostic identifies the specific exposures created by the transition, such as stressed employees, transitional accounts, accumulating access and distracted management, and recommends proportionate, time-bound mitigations.

Contact us about a Pre-Incident Diagnostics

Understand your organisation’s exposure to insider threats, identify gaps in current controls and prioritise the actions that matter most. Contact one of our team for a confidential discussion about an insider risk assessment.

Speak to GSA about Insider Risk Management

Frequently Asked Questions (FAQs)

What is an insider risk assessment?

An insider risk assessment evaluates where an organisation may be exposed to threats from employees, contractors, trusted third parties or others with legitimate access to systems, information or facilities. It considers both the threat environment and the effectiveness of existing controls.

What does an insider risk assessment include?

Depending on scope, an assessment may examine governance, personnel security, vetting, access management, technical monitoring, physical security, third-party risk, organisational culture, whistleblowing arrangements and investigation capability.

When should an organisation carry out an insider risk assessment?

An assessment can be useful when reviewing existing security arrangements, following changes in threat exposure or when preparing for significant organisational change. This can include restructuring, redundancies, mergers, acquisitions, divestitures or changes in geopolitical risk.

What happens after an insider risk assessment?

The findings may lead to changes in governance, vetting, monitoring, access controls, training or investigation procedures. Recommendations are prioritised so organisations can focus investment and resources on the areas of greatest risk.

Subscribe to our newsletter to keep up to date with all the latest news

Areas of interest

Marketing permissions

Please select all the ways you would like to hear from GSA Global:

You can unsubscribe at any time by clicking the link in the footer of our emails. For information about our privacy practices, please see our privacy policy.

We use Mailchimp as our marketing platform. By subscribing, you acknowledge that your information will be transferred to Mailchimp for processing. Learn more about Mailchimp's privacy practices.

GSA Global