← All posts

The Threat Walked In Through HR

Most of what a board hears about cybersecurity involves an outsider getting in. A phishing email. A stolen credential. An unpatched server facing the internet. The mental model is a wall, and the question is whether the wall held.

The first half of this year produced a number that does not fit that model. The Identity Theft Resource Center tracked 21 insider wrongdoing events in the first six months of 2026. In all of 2025, it tracked three. That is a sevenfold increase in six months, and the ITRC attributes it to two forces working at once: tech-sector layoffs and nation-state recruitment schemes.

Neither of those is a security control problem. Both are people problems that arrive through the hiring and separation processes — functions that report, in most companies, to someone who has never been asked a security question by the board.

The Headline Number Is Not the Interesting Number

The rest of the ITRC report is the part that gets the press coverage. There were 1,803 tracked data compromises in H1 2026, against 3,321 for all of 2025 — a pace that would produce roughly 3,600 events this year and set a record. More than 471 million victim notices went out in six months, eclipsing the 297.5 million sent during all twelve months of last year. A single compromise involving Instructure's Canvas education platform accounted for an estimated 275 million of those notices, about 58 percent of the total.

Those are big numbers, and they are the ones that will show up in your next vendor pitch deck. They are also the least actionable numbers in the report, because they describe a handful of very large events that most companies had no ability to influence.

Two other findings deserve more of your attention than the headline.

Publicly traded companies accounted for 10.3 percent of compromises but 83.4 percent of all victim notices. If you sit on a public company board, the base rate that matters to you is not the average across all 1,803 events. Your exposure is concentrated, and it is concentrated in you.

Only 24 percent of H1 2026 breach notices included any information about the attack vector — the lowest share the ITRC has ever recorded. ITRC President James E. Lee calls this "an unprecedented transparency crisis." The practical consequence for executives is that the disclosure regime you are relying on to tell you what is happening in your industry is telling you almost nothing. Three quarters of the notices sent this year said, in effect, something happened. You cannot benchmark against that. You cannot learn from it. And if you are counting on peer disclosure to tell you when a threat has reached your sector, you are counting on a signal that has largely gone dark.

Why Insider Risk Went Up

Two things happened simultaneously.

The first is ordinary and cyclical: layoffs. When a company reduces its technology workforce, it creates a window in which people who still hold access have lost their reason to protect it. Most of them behave honorably. The ones who do not have credentials that no perimeter control was designed to stop, because the credentials are legitimate.

The second is not ordinary at all. On July 31, 2026, the FBI and allied governments issued a joint advisory on North Korean IT workers who obtain remote employment at Western companies using stolen identities, AI-generated resumes, and — increasingly — real-time deepfake video during job interviews. Salaries are remitted to Pyongyang to fund weapons programs; access obtained along the way is used for theft and extortion. U.S. investigators have prosecuted domestic facilitators who ran "laptop farms," hosting company-issued machines in their homes so overseas operatives appeared to be logging in from American addresses.

To be precise about attribution: the ITRC did not name North Korea in its report. It cited "nation-state recruitment schemes" generally. But the two data sets describe the same shape of problem, and the FBI advisory tells you exactly which control failed. It was not a firewall. It was an interview.

The AI Layer Underneath

IBM's 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026, found that one in four malicious breaches were AI-enabled — a 56 percent increase over the prior year — and that those breaches cost an average of $6 million, roughly $1 million more than the $4.99 million global average. The report attributes the AI-enabled category mostly to deepfake impersonation and AI-enabled malware.

Deepfake impersonation is the connective tissue. The same capability that lets an attacker pass a video interview lets one pass a help-desk identity check or approve a wire transfer on a call that sounds exactly like your CFO. Your organization almost certainly has multiple business processes whose only authentication control is I recognized their face and voice. That control has been quietly deprecated, and nobody sent a notice.

One more IBM finding is worth putting in front of your board. Eighty-five percent of organizations said they plan to increase security spending after learning about advanced frontier AI cyber capabilities — compared with just 64 percent who said they would increase spending after actually experiencing a breach. Leaders are, for once, more motivated by the threat ahead than by the one behind them. That is a rare and perishable condition. Use it.

What to Ask Your CISO This Week

This is a governance conversation, not a technology one. Four questions:

  1. Who verified that our last ten remote technical hires are physically who and where they claim to be? Not "did HR run a background check" — who confirmed identity and location, and how? If the answer involves only documents and video calls, you have the exposure the FBI advisory describes.
  2. How long does access survive separation? Ask for the measured median, not the policy target. The gap between the two is your insider risk window.
  3. Which of our business processes still authenticate a human by voice or face alone? Wire approvals, password resets, executive requests to finance. Name them, then decide which need a second channel.
  4. Where would we learn that a peer in our sector was breached? If the answer is "public disclosures," you now know that three quarters of those disclosures say nothing useful. Fund a better source.

None of these require a new platform. All of them require an executive to own an answer.

The wall is not where the action is. The badge reader is.