Explore the Forscie® Insider Threat Matrix™ with 350+ documented techniques, motivations, and capabilities. Get actionable prevention strategies and detection methods validated by cybersecurity professionals for protecting against real-world insider threats.
Data Source: The Insider Threat Matrix™ is maintained by Forscie® Limited (forscie.com). Copyright 2026 Forscie® Limited. Licensed under Apache License 2.0.
Integration: This assessment platform integrates Matrix techniques with Ponemon Institute cost data and Gartner implementation insights to provide actionable recommendations.
The subject deliberately pushes or tests organizational policies, rules, or controls to assess tolerance levels, detect oversight gaps, or gain a sense of impunity. While initial actions may appear minor or exploratory, boundary testing serves as a psychological and operational precursor to more serious misconduct. CharacteristicsMotivated by curiosity, challenge-seeking, or early-stage dissatisfaction.Actions often start small: minor policy violations, unauthorized accesses, or circumvention of procedures.Rationalizations include beliefs that policies are overly rigid, outdated, or unfair.Boundary testing behavior may escalate if it is unchallenged, normalized, or inadvertently rewarded.Subjects often seek to gauge the likelihood and severity of consequences before considering larger or riskier actions.Testing may be isolated or gradually evolve into opportunism, retaliation, or deliberate harm. Example ScenarioA subject repeatedly circumvents minor IT security controls (e.g., bypassing content filters, using personal devices against policy) without immediate consequences. Encouraged by the lack of enforcement, the subject later undertakes unauthorized data transfers, rationalizing the behavior based on perceived inefficiencies and low risk of detection.
A subject is persuaded against their will to access and exfiltrate or destroy sensitive data, or conduct some other act that harms or undermines the target organization.
A subject’s emotional state is exploited by a malicious third party, particularly during periods of heightened stress, grief, or personal hardship. The third party leverages this vulnerability to manipulate the subject into revealing sensitive information or performing actions that could compromise the organization.
A malicious third party gradually builds a relationship with the subject over an extended period, slowly gaining their trust. This trust is then exploited to access sensitive information or systems, often without the knowledge of the subject.
The subject acts under coercion stemming from threats that target reputation, professional standing, financial stability, or exposure of personal secrets. These threats may be digitally delivered. While these actions stop short of threatening physical harm, they can exert intense psychological pressure, particularly when the subject believes their career, relationships, or public image are at imminent risk. This type of coercion may originate from:Former colleagues, romantic partners, or adversarial insiders with access to sensitive personal or professional material.Political actors, who have a political agenda against the subject's work place.External criminal actors (or hacktivist groups) who have compromised a personal account or acquired compromising data (e.g., via credential leaks or private messages). Unlike ideological motivation or personal gain, this behavior is driven by fear of exposure or ruin, not alignment with the threat actor’s objectives. Subjects may act reluctantly, leave minimal technical traces of coordination, and revert to baseline behavior once the coercive force is removed.
A third party uses deception, exploitation, or other unethical methods to psychologically manipulate a subject over time, with the intent to influence their perceptions, actions, and decisions. This manipulation can lead the subject to, knowingly or unknowingly, act against the organization’s interests.
A malicious third party employs romantic interest or seduction as a manipulation tactic. Through emotional and psychological engagement, the third party persuades the subject to reveal confidential information, grant access to restricted resources, or carry out actions detrimental to the organization.
A subject is extorted by a third party threatening to expose sexual or indecent images connected to them, a tactic commonly referred to as sextortion. These images may be real, obtained by a third party, AI-generated ‘deep fake’ images resembling the subject, or entirely fabricated claims. The extortion is typically financially motivated, which can drive the subject to harm the organization for personal gain. Alternatively, the third party may coerce the subject into compromising the organization by revealing sensitive information or granting unauthorized access.
A third party deceptively manipulates and/or persuades a subject to divulge information, or gain access to devices or systems, or to otherwise cause harm or undermine a target organization.
The subject is coerced by a third party into harmful or otherwise policy-violating activity through explicit or credible threats of violence, either directed at themselves or at others (e.g., family members, colleagues). This type of coercion often includes real-world intimidation, such as direct verbal or written threats, or more ambiguous references that imply the actor possesses the means or knowledge to inflict physical harm. Examples may include:Stated intent to harm the subject’s family unless a system is accessed or data is provided.Demonstrations of knowledge of personal routines or addresses.Implied physical threat (“We know where you work.” / “Think about your daughter.”) intended to coerce compliance. In some cases, the coercive actor may belong to or adopt the tactics and posture of organized crime groups or hybrid cyber-physical groups, lending credibility to the threat. The subject’s response may be reluctant, sudden, and inconsistent with previous behavior, reflecting actions taken under acute psychological and physical duress. This motive reflects extreme coercion and requires careful investigative sensitivity. It may also intersect with criminal law, necessitating immediate coordination with internal legal teams, law enforcement, and/or protective services. In almost all such cases, the organization has a duty to treat the subject as a victim of crime.
A subject may be motivated by personal, financial, or professional interests that directly conflict with their duties and obligations to the organization. This inherent conflict of interest can lead the subject to engage in actions that compromise the organization’s values, objectives, or legal standing. For instance, a subject who serves as a senior procurement officer at a company may have a financial stake in a vendor company that is bidding for a contract. Despite knowing that the vendor's offer is subpar or overpriced, the subject might influence the decision-making process to favor that vendor, as it directly benefits their personal financial interests. This conflict of interest could lead to awarding the contract in a way that harms the organization, such as incurring higher costs, receiving lower-quality goods or services, or violating anti-corruption regulations. The presence of a conflict of interest can create a situation where the subject makes decisions that intentionally or unintentionally harm the organization, such as promoting anti-competitive actions, distorting market outcomes, or violating regulatory frameworks. While the subject’s actions may be hidden behind professional duties, the conflict itself acts as the driving force behind unethical or illegal behavior. These infringements can have far-reaching consequences, including legal ramifications, financial penalties, and damage to the organization’s reputation.
A subject holds an undisclosed financial interest in an organization, individual, transaction, investment, asset, or commercial outcome affected by their organizational responsibilities. The interest may include company ownership, shares, debt, commission, referral payments, profit-sharing arrangements, creditor relationships, beneficial ownership, or another financial position through which the subject may gain or avoid loss. The interest may be held directly or indirectly through a family member, associate, trust, company, or other intermediary. The conflict becomes operationally significant where the subject can influence procurement, supplier selection, pricing, investment decisions, contract awards, customer treatment, regulatory review, access permissions, or the handling of confidential information. The subject may favor a connected entity, suppress unfavorable information, disclose commercially useful material, or manipulate a decision while presenting their actions as ordinary professional judgment. Investigators should identify the financial relationship, determine when it began, establish whether disclosure was required, and compare the subject’s decisions with objective organizational criteria. Evidence may include corporate ownership records, declared-interest registers, procurement records, payment data, communications, approval history, and repeated decisions benefiting the same external entity.
A subject is influenced by a personal, familial, romantic, or close social relationship with an individual whose interests are affected by the subject’s organizational responsibilities. The relationship may involve a colleague, applicant, customer, supplier representative, contractor, investigation subject, complainant, or another person connected to an organizational decision. The conflict may arise where the subject can approve access, influence recruitment, award work, alter a case outcome, disclose information, suppress scrutiny, or provide another form of preferential treatment. The existence of a personal relationship does not itself establish harmful intent. The investigative concern arises where the relationship creates a material conflict with the subject’s duties and is not disclosed through the organization’s required process. Relevant indicators may include repeated favorable decisions, unusual access to information concerning the connected person, involvement in matters from which the subject should have recused themselves, or communications inconsistent with the stated professional relationship. Investigators should establish the nature and timing of the relationship, the subject’s disclosure obligations, the decisions or access affected by it, and whether the subject took steps to conceal the connection. The resulting infringement may separately involve abuse of decision-making authority, unauthorized data access, data disclosure, fraud, or interference with an investigation.
A subject owns, operates, advises, supports, or materially benefits from an external business whose activities or interests conflict with their responsibilities to the organization. The external interest may include a private company, consultancy, partnership, directorship, freelance operation, side business, or commercial activity conducted through another person. The business does not need to be a direct competitor. A conflict may also arise where it supplies similar services, seeks access to the same customers, depends on organizational resources, or could benefit from information available through the subject’s role. The subject may use organizational working time, information, equipment, personnel, customer relationships, intellectual property, or decision-making authority to support the external business. They may also direct opportunities away from the organization, influence supplier or customer decisions, or conceal the extent of their involvement. Investigators should establish the subject’s ownership, management, advisory, or beneficial relationship with the external business and determine whether it was disclosed. Relevant evidence may include corporate records, professional profiles, business websites, invoices, communications, device activity, customer contact, use of organizational resources, and work performed during contracted hours. This Sub-section should be distinguished from IF038 – Undisclosed Concurrent Employment. Undisclosed Concurrent Employment captures the infringement of maintaining or performing undisclosed external work where disclosure is required. External Business Interest describes the conflict acting as a motive that may influence a wider range of harmful conduct.
A subject, motivated solely by personal curiosity, may take actions that unintentionally cause or risk harm to an organization. For example, they might install unauthorized software to experiment with its features or explore a network-attached storage (NAS) device without proper authorization.
A subject believes they have a personal right to organizational information, intellectual property, systems, resources, access, or work product that exceeds the rights granted to them by the organization. The belief may arise because the subject created, developed, maintained, managed, discovered, or materially contributed to the asset, or because prolonged access has caused the subject to regard it as personally theirs to retain or use. Entitlement may cause a subject to disregard ownership, confidentiality, access, or retention requirements because they do not perceive their actions as taking something to which they have no legitimate claim. The subject may retain source code, customer information, research, documents, credentials, equipment, or other organizational assets for personal reference, future employment, a subsequent business venture, or another purpose while rationalizing the infringement on the basis of contribution or perceived ownership.
A subject carries out covert actions, such as the collection of confidential or classified information, for the strategic advantage of a nation-state.
The subject is a current or former asset of a nation-state intelligence service, operating inside the organization with pre-existing loyalty to, or direct affiliation with, a foreign government. Unlike insiders who develop espionage motives post-employment, this subject is often inserted, recruited prior to hiring, or cultivated externally over time and then encouraged to seek access to a target organization. Their motive is the advancement of strategic objectives on behalf of a foreign nation-state. These objectives may include extracting sensitive information, degrading operational resilience, manipulating internal systems or decisions, weakening public or partner trust, or embedding long-term access for future exploitation. Such subjects may be formal intelligence officers, contract operatives, ideological affiliates, or individuals acting under recruitment, coercion, or influence. Example Scenarios: A subject recruited during university by a foreign security service secures a role in a telecommunications provider and enables covert surveillance access for state-level eavesdropping.A subject hired into a biopharmaceutical firm has pre-existing links to a state-sponsored “talent program” and transfers research data to affiliated institutions abroad via covert cloud channels.
A subject accesses and exfiltrates or destroys sensitive data or otherwise contravenes internal policies in an attempt to prevent professional reprisals against them or other persons.
Hubris refers to excessive self-confidence, often manifesting as a belief that the subject is above rules, policies, or consequences. The subject sees themselves as indispensable, superior, or uniquely capable—and may rationalize policy violations because they “know better.” The core trait of hubris is a sense of arrogance and superiority, where the subject views themselves as fundamentally above their peers in capability or judgment. The key driver behind this motive is the belief that "I am the exception"—that normal rules or controls are for others, not for someone of their perceived caliber. This often leads to behavior such as circumventing controls, overriding governance processes, or acting unilaterally without authorization, because the subject sees compliance as an unnecessary constraint on their effectiveness. Their justification typically rests on the idea that "the rules don’t apply to me because I’m smarter, more important, or more experienced than those who created them."