When we think about security threats, we default to the external attacker — ransomware, phishing, brute-force bots. But according to the Verizon 2025 DBIR, insider threats account for 34% of breaches in small and medium businesses. And the top attack vector? Abused or mismanaged passwords.
The good news: you don't need a SOC to defend against this. You need sane password policies and a few controls wired into your credential workflow.
The three kinds of insider
Not every insider is malicious. Knowing the category tells you which control to reach for:
Malicious — departing staff or contractors intentionally misusing access (exfiltrating a customer DB before resignation). IBM pegs the average cost at ~£210k per incident.








