Insider risk now costs the average organization $19.5 million a year, up from $17.4 million just two years ago. You already know insider threats are a problem, but maybe you didn’t know just how quickly the threat is intensifying, how much of the damage is self-inflicted through negligence rather than sabotage, and how AI tools are becoming the newest exfiltration channel.
The headline numbers

These are the figures worth noting before you read anything else.
- Insider risk costs organizations $19.5 million annually on average in 2026, up from $17.4 million in the 2024 study period.
- 83% of organizations experienced at least one insider-related security incident in the past year.
- 68% of organizations now experience between 21 and more than 40 insider incidents per year, up from 57% in 2024.
- Malicious insider breaches cost $4.92 million per incident, higher than phishing, ransomware, and business email compromise.
- Employee use of generative AI tools on corporate devices jumped from 15% to 45% in a single year, and 67% of those employees log in with personal accounts that bypass enterprise controls.
- Organizations running a mature insider risk program avoid an average of seven incidents a year and save $8.2 million doing it.
That last stat is worth focusing on. Simply getting this right could save you from a board-level incident.
How often this actually happens
- Negligent insiders generate an average of 13.8 incidents per organization per year.
- Malicious insiders generate an average of 6.3 incidents per organization per year, a smaller number but a costlier one per event.
- 53% of insider incidents result from plain employee negligence, not malice.
- In a 2026 study, 8,750 IT and security practitioners surveyed across 354 organizations experienced at least one material insider event.
- 77% of organizations experienced insider-related data loss in the past 18 months, and 21% of those logged more than 20 separate incidents in that window.
- 62% of insider incidents stem from human error or a compromised account rather than deliberate misconduct.
You’re not primarily fighting saboteurs. You’re fighting fatigue, misconfiguration, and people who click the wrong link at 4:45 PM on a Friday. Build your defenses for that reality, not the Hollywood version.
What it actually costs, broken down by cause
- Negligent incidents cost an average of $10.3 million a year to remediate across an organization.
- Malicious or criminal insider incidents cost an average of $4.7 million per incident.
- Credential theft costs an average of $4.5 million per incident, the costliest category on a per-event basis despite being the least frequent.
- Incidents contained in more than 90 days cost organizations roughly $18.7 million on average, compared with $10.6 million for incidents contained inside 30 days.
- It now takes an average of 67 days to contain an insider incident, down from 86 days in 2023.
The containment-time curve is the clearest ROI argument you’ll find in this article. Every day you shave off detection and response is money back in the budget. Sixty-seven days is progress. It’s still nine and a half weeks of someone inside your systems doing damage before you notice.
Why detection keeps failing you
- 93% of security leaders say insider threats are as hard, or harder, to detect than external attacks.
- Only 23% of security leaders express strong confidence in stopping an insider threat before serious damage occurs.
- Just 21% of organizations extensively integrate behavioral signals, including HR and financial-stress indicators, into their detection programs.
- 49% of security leaders report discovering insider-related data, credentials, or sensitive information exposed on the dark web.
- Only 44% of organizations currently use user and entity behavior analytics (UEBA), despite it being one of the few tools purpose-built to catch this kind of activity.
- 54% of organizations have started using AI or machine learning to spot insider risk, and 51% of those call the tooling essential or very important to their program.
- Machine learning anomaly detection cuts false positives by up to 60% compared with the rule-based systems most SOCs still run.
You can buy every detection tool on the market and still fail here if the tools don’t talk to each other. Fragmentation, not budget, is the honest reason most insider programs underperform.
The high-risk roles you already trust
- 83% of security leaders flag IT administrators as elevated insider risk, ahead of every other role category.
- 77% flag third-party vendors and contractors as elevated risk.
- 64% flag executives themselves as elevated risk, a category most programs still under-monitor.
- 68% of organizations report employees having access to data they have no legitimate reason to view.
- Roughly 19% of non-administrator business users hold some form of privileged access to enterprise data, apps, or servers.
- 80% of breaches involve a compromised privileged credential of some kind, whether it belongs to a domain admin, a service account, or an application.
- Privileged accounts make up only 8% of an organization’s total digital identities, yet they’re implicated in more than 74% of serious attacks.
- Only 27% of organizations can unify privileged access management policies across every IT service they run
- Organizations that do have unified privileged access management policies across all their IT services are 72% less likely to discover a still-active account belonging to a terminated employee.
Access review is not a compliance checkbox. It’s the single control that would have stopped a meaningful share of the incidents in this list.
The departing employee problem
- 83% of former employees admit they still had access to at least one account from a previous employer after leaving.
- 56% of those former employees admit they used that lingering access with the specific intent of harming their previous employer.
- 74% of managers and business leaders say their company has been negatively affected by a former employee breaching their security.
- Most insiders who steal intellectual property do so within roughly 30 days of resigning.
- In 2025, roughly 245,953 tech employees were laid off across 783 companies, creating offboarding pressure your IT team has to get right in a timely manner.
- Security researchers consistently find that attackers monitor public layoff announcements and use the resulting confusion to time phishing and social engineering campaigns against a company’s remaining staff.
Offboarding is the least glamorous item on any security roadmap but the most important to get right.
Where DevOps teams are bleeding secrets
- GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits in 2025, a 34% increase over 2024 and the largest single-year jump the company has ever recorded.
- 64% of secrets leaked back in 2022 are still valid today, meaning they have remained exposed and unrotated for roughly four years.
- Internal repositories are roughly six times more likely to contain a hardcoded secret than public ones, and 32% of internal repositories contain at least one.
- Secrets found in self-hosted GitLab and Docker environments are three to four times more likely to be live, exploitable credentials than secrets found elsewhere.
- 28% of 2025’s secret-leak incidents originated entirely outside source code, in tools like Slack, Jira, and Confluence, and 56.7% of the secrets found only in collaboration tools were rated critical severity.
- AI-assisted commits leak secrets at roughly double the GitHub-wide baseline rate, about 3.2% versus the platform average.
- Leaked credentials tied specifically to AI services rose 81% year over year to 1.27 million in 2025.
Every one of these is a self-inflicted wound. Nobody broke in. Someone on your own team committed a credential, and it sat there long enough for an attacker to find it. The fix isn’t a bigger firewall. It’s scanning your own repositories with the same rigor you’d expect from an external auditor.
Shadow AI is the newest insider vector
- Source code is the single most common data type submitted to external generative AI models.
- Shadow AI usage (when employees use unsanctioned artificial intelligence tools or unauthorized personal accounts to process corporate data) is now the third most common non-malicious insider action, a fourfold increase in share from the year before.
- Roughly 60% of organizations have experienced at least one data exposure event tied to an employee’s use of a public generative AI tool.
- Breaches involving shadow AI cost organizations $4.63 million on average, $670,000 more than the cost of a standard breach.
- 20% of organizations IBM studied had experienced a breach linked specifically to shadow AI, unsanctioned tools employees adopted without security’s knowledge.
- 97% of organizations that suffered an AI-related breach admitted they lacked proper access controls around their AI systems.
- 63% of breached organizations either have no AI governance policy or are still building one.
Your developers were never going to wait for a policy document before trying ChatGPT on a production bug. But whereas AI may be boosting developer velocity, their increased productivity is putting pressure on your governance, creating an AI governance paradox.
Programs that actually work
- Insider risk management now consumes 19% of the average organization’s IT security budget, up from 8.2% in 2023, more than doubling in three years.
- 65% of organizations with a dedicated insider risk program say it was the only security strategy that let them pre-empt a breach through early detection.
- Organizations at the highest maturity level detect and contain incidents in under 31 days and spend roughly $10.6 million annually on insider risk overall, well below the $19.5 million global average.
- 72% of organizations report their insider risk budgets are increasing.
- 66% of security leaders name real-time behavioral analytics as the top priority for their next round of insider risk tooling.
- Worldwide information security spending is forecast to reach $240 billion in 2026, a 12.5% increase over 2025, with insider risk management named among the fastest-growing categories inside that number.
What this means for your team
None of these figures suggest a single tool you can buy to resolve the problem of insider risk. The most effective measures to address the issue are closing the gap on offboarding and access revocation, scanning your own repositories and collaboration tools for the credentials your team already leaked, and writing an AI usage policy before your engineers write one for you by default. This is not glamorous work, but doing it consistently will help you to avoid what has become the costliest category of breaches.
Solve your infrastructure challenges
Spacelift is an infrastructure orchestration platform built for IaC. It brings collaboration, automation, and governance into a single workflow, so your team can provision cloud infrastructure faster without losing control.
DTEX Systems. 2026 Cost of Insider Risks Global Report. Accessed: 5 August 2026.
Ponemon Sullivan Privacy Report. 2026 Cost of Insider Risks: Global. Accessed: 5 August 2026.
DTEX Systems. Ponemon Cost of Insider Risks: Key Findings 2026. Accessed: 5 August 2026.
Infosecurity Magazine. Cost of Insider Incidents Surges 20% to Nearly $20m. Accessed: 5 August 2026.
Help Net Security. The $19.5 Million Insider Risk Problem. Accessed: 5 August 2026.
DTEX Systems. 2025 Ponemon Cost of Insider Threats Global Report: Takeaways. Accessed: 5 August 2026.
Ponemon Institute. The Security Risk Organizations Should Not Ignore: Careless, Negligent and Malicious Insiders. Accessed: 5 August 2026.
Kiteworks. Insider Threats Cost $2.7M: 2025 Ponemon Report Reveals 45% of Data Breaches Come From Within. Accessed: 5 August 2026.
IBM. Cost of a Data Breach Report 2025. Accessed: 5 August 2026.
IBM. 2025 Cost of a Data Breach Report: Navigating the AI Rush Without Sidelining Security. Accessed: 5 August 2026.
IBM. IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications, 97% of Which Reported Lacking Proper AI Access Controls. Accessed: 5 August 2026.
Kiteworks. How Shadow AI Costs Companies $670K Extra: IBM’s 2025 Breach Report. Accessed: 5 August 2026.
Nudge Security. Shadow AI in IBM’s 2025 Cost of a Data Breach Report. Accessed: 5 August 2026.
Verizon. 2026 Data Breach Investigations Report. Accessed: 5 August 2026.
Verizon. 2026 Data Breach Investigations Report (PDF). Accessed: 5 August 2026.
Verizon. Executive Summary, 2026 Data Breach Investigations Report. Accessed: 5 August 2026.
Verizon. 2025 Data Breach Investigations Report (PDF). Accessed: 5 August 2026.
Kiteworks. Verizon DBIR 2026: Shadow AI Now a Top Insider Threat. Accessed: 5 August 2026.
Cybersecurity Insiders. 2025 Insider Risk Report: The Shift to Predictive Whole-Person Insider Risk Management. Accessed: 5 August 2026.
Cybersecurity Insiders. 2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks. Accessed: 5 August 2026.
Fortinet. 2025 Insider Risk Report: The Hidden Cost of Everyday Actions. Accessed: 5 August 2026.
Fortinet. 2025 Insider Risk Report (PDF). Accessed: 5 August 2026.
Fortinet. 2025 Insider Risk Report: Peer Insights to Inform Your Insider Risk Strategy. Accessed: 5 August 2026.
GitGuardian. State of Secrets Sprawl Report 2025. Accessed: 5 August 2026.
GitGuardian. AI Is Fueling Secrets Sprawl: The State of Secrets Sprawl 2026. Accessed: 5 August 2026.
GitGuardian. The State of Secrets Sprawl 2025. Accessed: 5 August 2026.
The Hacker News. The State of Secrets Sprawl 2026: 9 Takeaways for CISOs. Accessed: 5 August 2026.
Snyk. Why 28 Million Credentials Leaked on GitHub in 2025, and What to Do About It. Accessed: 5 August 2026.
Help Net Security. AI Frenzy Feeds Credential Chaos, Secrets Leak Through Code, Tools, and Infrastructure. Accessed: 5 August 2026.
Expert Insights. PAM Market Overview: Key Stats & Insights. Accessed: 5 August 2026.
LLCBuddy. Privileged Access Management Software Statistics 2025. Accessed: 5 August 2026.
Forbes. Overprivileged Access Vulnerabilities: What Leaders Need to Know. Accessed: 5 August 2026.
Beyond Identity. Beyond Identity Study Shows Former Employees Are Likely to Continue Accessing Old Employer Information. Accessed: 5 August 2026.
Beyond Identity. Former Employees Admit to Using Continued Account Access to Harm Previous Employers. Accessed: 5 August 2026.
Help Net Security. 83% of Employees Continue Accessing Old Employer’s Accounts. Accessed: 5 August 2026.
Carnegie Mellon University Software Engineering Institute. Insider Threat Deep Dive: Theft of Intellectual Property. Accessed: 5 August 2026.
InformIT. The CERT Guide to Insider Threats: Insider Theft of Intellectual Property. Accessed: 5 August 2026.
TechCrunch. A Comprehensive List of 2025 Tech Layoffs. Accessed: 5 August 2026.
Exabeam. 46 Insider Threat Statistics You Must Know. Accessed: 5 August 2026.
Exabeam. UEBA (User and Entity Behavior Analytics): Complete Guide. Accessed: 5 August 2026.
Gartner. Gartner Forecasts Worldwide End-User Spending on Information Security to Total $213 Billion in 2025. Accessed: 5 August 2026.
Gartner Projects $244 Billion in Security Spending for 2026. Accessed: 5 August 2026.
