The Cybersecurity and Infrastructure Security Agency released an updated Insider Threat Mitigation Guide on September 9, 2026, providing organizations with revised guidance for managing physical and cyber risks. The streamlined edition addresses hybrid and remote work, advances in artificial intelligence, access control, visitor screening and risks associated with adverse employee separations.

CISA said the guidance provides security support consistent with its statutory mission and offers practical steps for developing or improving an insider threat program. First published in 2020, the guide is intended for security and human resource professionals who manage such programs, as well as organizational leaders at every level.

The update reflects what CISA described as the growing impact of insider threats on critical infrastructure and a changing operational environment. According to the agency, organizations can use the guide regardless of the maturity of their existing security programs, while employees can use it to understand behavioral indicators that may signal a risk.

The revised guide includes new case studies and statistics, along with consolidated sections intended to improve the delivery and continued relevance of the original material. It also provides access to newly released CISA resources supporting organizational preparedness and early risk detection.

Acting Executive Assistant Director for Infrastructure Security Scott Breor said insider threats continue to change as technology becomes more advanced. He urged organizations to establish mitigation programs intended to protect key assets, prevent violence, reduce losses, safeguard sensitive data and save lives, and said feedback from government and industry partners informed the update.

CISA encouraged organizations to review the revised guide, assess their existing programs and consider recommended steps to strengthen threat mitigation. The agency serves as the national coordinator for critical infrastructure security and leads federal efforts to manage, identify and reduce risks to digital and physical infrastructure.