# Insider Threat

A security risk that comes from someone within an organization, such as an employee or contractor, rather than an outside attacker.

An **insider threat[↗](/insider-threat)** is a security risk that originates from someone with legitimate access to an organization's systems, an employee, contractor, or business partner, rather than an outside attacker. The threat can be malicious, such as a disgruntled employee stealing data, or unintentional, such as someone falling for a phishing[↗](/phishing) email or misconfiguring a system.

Insider threats are harder to detect than external attacks because the person already has valid credentials and access. Organizations reduce this risk through least-privilege access, activity monitoring, and offboarding processes that promptly revoke access when someone leaves.
