# Insider Threat **Entity class:** National-security and cybersecurity concept ## Definition An **insider threat** is the danger that a person with authorized access or placement will use that access, intentionally or unintentionally, to harm an organization or the security of the United States. National-security doctrine expressly includes harm through espionage, terrorism, unauthorized disclosure, or degradation of resources and capabilities. ## Relevance to this collection It is the literal doctrinal bridge to [[wiki/Human CVE|Human CVE]]: the human is part of the protected system, and authorized placement can become the condition that makes an [[wiki/Attack Path|attack path]] possible. ## Relationships - **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. - **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]]. ## Sources / Provenance - [Defense Counterintelligence and Security Agency, *Exploitation of Insider Access*](https://www.dcsa.mil/Portals/128/Documents/CI/DCSA_CI_Best_Practices_booklet.pdf) (accessed 2026-09-23). **As of:** 2026-09-23