# Insider Threat
**Entity class:** National-security and cybersecurity concept
## Definition
An **insider threat** is the danger that a person with authorized access or placement will use that access, intentionally or unintentionally, to harm an organization or the security of the United States. National-security doctrine expressly includes harm through espionage, terrorism, unauthorized disclosure, or degradation of resources and capabilities.
## Relevance to this collection
It is the literal doctrinal bridge to [[wiki/Human CVE|Human CVE]]: the human is part of the protected system, and authorized placement can become the condition that makes an [[wiki/Attack Path|attack path]] possible.
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]].
## Sources / Provenance
- [Defense Counterintelligence and Security Agency, *Exploitation of Insider Access*](https://www.dcsa.mil/Portals/128/Documents/CI/DCSA_CI_Best_Practices_booklet.pdf) (accessed 2026-09-23).
**As of:** 2026-09-23