Security1 publisher2 min readPublished
CISA adds AI deception and adverse separations to the insider threat guide it wrote in 2020
The September 9 revision updates CISA's 2020 text on its own timeline, with no deadline attached and no incident behind it, and the topics CISA chose to add read as a checklist of the assumptions most insider threat programs have not revisited.
The Watch · Security desk

What happened
- CISA published a revised Insider Threat Mitigation Guide on September 9, replacing the version it first issued in 2020.
- The revision adds case studies, statistics and new guidance on hybrid and remote work, artificial intelligence and adverse employee separations.
- The workplace material addresses the rise in hybrid and remote work and how each arrangement changes an organization's control over physical and digital access.
- Scott Breor, CISA's acting executive assistant director for infrastructure security, said partner feedback informed the update and encouraged organizations to assess their own programs against it.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision The added topics set the order of a re-audit: access control for staff who are rarely on site, deception aimed at employees, and offboarding when the exit is not the employee's choice.
- constraint A program scoped to data-loss alerting no longer matches the federal reference, which is filed under physical security and treats violence prevention as an insider threat outcome.
- cost The bill is analyst and HR reading time plus re-pointing internal policy at a reorganized document, not change windows or downtime.
- precedent With no revision schedule published and the 2020 edition having stood until now, programs should expect to be measured against this text for years rather than months.
The guide revision changed the baseline a program gets audited against on September 9, not the technical exposure of any organization [2]. CISA names the audience as the security and human resources staff who run insider threat programs plus leaders at any level, and says any organization can use the guide regardless of the maturity of its security [11].
The AI material is narrower than the label suggests. CISA describes it as covering AI used to manipulate or deceive, and the account is explicit that this is not a broader assessment of the technology's role in insider incidents [5]. Insider misuse of AI tools by employees is outside the scope described [16]. The agency says the update acknowledges the growing impact of insider threats on critical infrastructure and adds use cases to match how operations are changing [12], but none of the added statistics appear in the public account, so there is no figure here to benchmark a program against [15].
Where the guide sits carries as much weight as the new sections. It is filed in CISA's physical security section, next to the added access control and visitor screening content [8][6], and Scott Breor, CISA's acting executive assistant director for infrastructure security, put the purpose of a program as protecting key assets, preventing violence, reducing losses, safeguarding sensitive data and saving lives [7]. That is a wider remit than data loss. It decides who has to be in the room for the re-audit.
One mechanical detail matters for anyone mapping controls. The revision arrives in a streamlined format with sections consolidated [3], so internal policy that cites the 2020 guide by section will no longer land on the same text [14]. Organizations with no program at all are pointed first at newly released CISA resources on preparedness and early risk detection, which the agency frames as the practical route into the material [13]. CISA gave no timetable for further revisions [10]. The 2020 edition held until this one replaced it [2].
What to watch
- Whether CISA publishes the statistics behind its critical infrastructure claim in a form programs can benchmark against.
- Whether the AI section is later extended past manipulation and deception to insider use of AI tools.
- Any published timetable for the next revision, which CISA has not given.