By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: The rise of insider cyber threats – UKTN
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > The rise of insider cyber threats – UKTN
News

The rise of insider cyber threats – UKTN

News Room
Last updated: 2026/03/05 at 11:44 AM
News Room Published 5 March 2026
Share
The rise of insider cyber threats – UKTN
SHARE

Cyber threats have become a daily reality for businesses in 2026, with a common reason suggested being surging geopolitical tensions driving rates of state-sponsored attacks.

But while international threat actors in hostile states are legitimate concerns, recent research suggests a far greater risk faced by businesses comes from the inside.

In its latest annual State of Human Risk report, network security company Mimecast examined the human-led cyber threats that are most plaguing British businesses.

Its survey of 2,500 IT security and decision makers has revealed that the scale to which insider incidents cost businesses.

Negligence, malice and the cost of insider incidents

Mimecast’s research found that between direct threats from insiders, credential misuse and user-driven error, the majority of security incidents come in some way from inside a company.

Between both negligent and malicious insider activity, the risk report revealed a 45% rise among UK businesses over the past 12 months.

According to the research, these incidents cost on average £9.6m, with organisations experiencing six insider incidents per month.

Part of the problem, as suggested by Mimecast’s chief marketing officer Nikki Cosgrove, is that insider risk concentrates across a workforce.

The group’s research found that 8% of employees are responsible for 80% of an organisation’s security risk.

“The organisations that understand that stop applying identical controls to everyone and start building programmes that can distinguish between the careless, the compromised, and the malicious,” Cosgrove said.

While neither form of insider security risk is desirable, it is also concerning that Mimecast has found that malicious incidents are rising to the same rate as negligent ones.

“For a long time, security teams told themselves insider risk was mostly accidental. A careless click. A misdirected file. Someone who didn’t know better. That story no longer holds.”

What are businesses doing wrong?

Part of the problem is simple preparedness. Mimecast research found that only 22% of organisations train their employees to spot cyber-attacks on an ongoing basis, and only 33% combine regular security awareness training with continuous monitoring for policy violations.

Beyond this, Cosgrove pointed out a common fault in a typical business’s approach to tackling these kinds of threats.

“They treat insider risk as a solely technical problem. It isn’t. It’s a people problem that happens to have technical symptoms,” she said.

“What changes the trajectory of an insider risk programme isn’t the technology. It’s whether the organisation is willing to ask why someone became a risk in the first place.”

This could be down to financial pressure, disengagement or even coercion and Cosgrove claimed these real drivers of risk leave behavioural signals long before anything can be seen in a threat alert.

The organisations building genuine capability here are treating those signals as early warning intelligence, not background noise.

The role of regulation

Interestingly, Mimecast noted that the existing regulatory architecture needed to meet these challenges is already for the most part in place.

Between GDPR, the Data Protection Act and the incoming Cyber Resilience Bill, there is already a framework with real authority.

“The problem isn’t that we lack regulation. It’s that the guidance was written for a threat model that no longer reflects how incidents actually unfold,” said Cosgrove.

“What policymakers need to grapple with is how fundamentally the threat has changed.”

Today, data loss can happen across email, collaboration tools, cloud platforms and even via AI systems and agents and it happens at a speed that manual processes are not fit for.

“Regulation that only contemplates the human insider is already outdated,” Cosgrove said.

“What’s needed are governance standards that cover both, with clear requirements for automated detection when sensitive data moves inappropriately, and real-time controls that don’t depend on someone being in the loop.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Netflix buys Ben Affleck’s AI filmmaking company InterPositive |  News Netflix buys Ben Affleck’s AI filmmaking company InterPositive | News
Next Article Building a SaaS With Zero Human Code | HackerNoon Building a SaaS With Zero Human Code | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Really, you made this without AI? Prove it
Really, you made this without AI? Prove it
News
Lenovo’s Legion Go 2 Is the Latest Console to Raise Prices
Lenovo’s Legion Go 2 Is the Latest Console to Raise Prices
News
Shanghai launches traffic safety code for delivery riders · TechNode
Shanghai launches traffic safety code for delivery riders · TechNode
Computing
Oracle’s massive layoffs affected 158 employees in the Bay Area
Oracle’s massive layoffs affected 158 employees in the Bay Area
News

You Might also Like

Really, you made this without AI? Prove it
News

Really, you made this without AI? Prove it

13 Min Read
Lenovo’s Legion Go 2 Is the Latest Console to Raise Prices
News

Lenovo’s Legion Go 2 Is the Latest Console to Raise Prices

5 Min Read
Oracle’s massive layoffs affected 158 employees in the Bay Area
News

Oracle’s massive layoffs affected 158 employees in the Bay Area

2 Min Read
iFixit AirPods Max 2 Teardown: Same Design, Same Repairability Issues
News

iFixit AirPods Max 2 Teardown: Same Design, Same Repairability Issues

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?