Audit, risk and internal control  |  Cyber

Insider risk: What non-executive directors should know and ask

Picture of Martin Schwarz, author of a thought leadership article on insider risk for NEDonBoard
SHARE
LinkedIn
Twitter
Facebook
Email

Insider risk is not about bad people; it is about understanding how good organisations become vulnerable.

For many boards, insider risk still sounds like a specialist concern but that is too narrow. Insider risk management is a lens on the human thread running through risk vectors including cybersecurity, data loss prevention, internal fraud, corporate criminal offences, culture, AI, operational resilience and institutional trust. It’s where people, access, incentives, culture and organisational pressure interact with other risk vectors.

The right board question is therefore not:

“Do we have an insider risk programme?”.

It is:

“Do we understand how people, access, incentives and culture could cause our principal risks to materialise, or help us manage them better?”


  • Insider risk is not confined to malicious employees. It includes error, coercion, poor judgement, weak controls, unmanaged pressure and misaligned incentives.
  • Many organisational incidents begin with a human failure point and end-up becoming full-scale enterprise crises.
  • AI has expanded the insider risk perimeter through unauthorised use, inappropriate data sharing and poorly governed agents.
  • Corporate criminal offences raise the stakes for boards by linking culture, controls and third-party oversight to corporate and individual liability.
  • Good insider risk governance is not just about preventing harm. It can also improve trust, engagement and productivity.
  • Insider risk is dynamic. New technologies and incentives, including prediction markets, are creating exposures that many boards were not considering a year ago.

Boards have learned, often painfully, that cybersecurity is not simply a technical issue that can be delegated to the CIO or CISO. Insider risk is following the same path.

The M&S cybersecurity incident is instructive because it shows how quickly a problem with human and third-party dimensions can become an enterprise-wide event.

Imagine the boardroom as that situation unfolded. A major consumer brand. Systems disrupted. Online sales affected. Customers concerned about their data. The media demanding answers. Regulators watching. Investors asking about impact. Management trying to understand what had happened, whether the threat had been contained and how long recovery might take.

At that point, the incident is no longer ‘a cybersecurity problem’. It becomes a customer problem, a supplier problem, a resilience problem, a communications problem, a financial problem and, ultimately, a board problem.

The lesson is not simply that people can be manipulated. It is that insider events rarely begin as dramatic acts of betrayal. They often begin with ordinary organisational weaknesses: access that has not been reviewed, a helpdesk process that can be exploited, pressure that has gone unnoticed, controls that people routinely work around, or a third party whose security arrangements have not been tested adequately. That is where board oversight matters.


The attack on Jaguar Land Rover reinforces the point. The disruption went beyond internal systems and production. It affected suppliers, employment and wider economic confidence, leading to government-backed support for the company’s supply chain. Again, that is not merely a cybersecurity story. It is operational resilience, third-party dependency, economic continuity of national significance and board stewardship.

Boards should therefore move beyond asking:

“Are we adequately protected?”.

A more useful question is:

“Where are the human and organisational conditions that could allow a cybersecurity, fraud or conduct event to escalate faster than management expects?”

That shift matters because major incidents rarely remain within the boundaries of the function that first identifies them.


The same logic now applies to AI. Many boards are considering AI through the lenses of strategy, model governance, ethics and procurement. Those are important, but some of the most immediate risks are more prosaic.

Employees may use tools that have not been approved. They may upload commercially sensitive, personal or regulated information into public systems. They may rely on outputs they do not understand or cannot explain. They may create workarounds because authorised tools are too slow or restrictive.

AI agents introduce an additional layer of risk. An agent with excessive permissions may be able to access, combine or act on information at a speed and scale that no individual employee could replicate. That makes the design of access, authority and oversight critical.

AI is therefore an insider risk vector, not because the technology is inherently hostile, but because people may use it in ways that expose information, distort decisions or widen access faster than governance can respond.

The board should not only ask what AI systems the organisation has approved. It should also ask what staff are already using, what data is being shared and what autonomous actions agents are permitted to take.


The failure to prevent fraud offence, when combined with other corporate criminal offences in the UK such as bribery & corruption and the failure to prevent tax evasion, should sharpen board attention further. Organisations must demonstrate that reasonable prevention procedures are in place. That places familiar governance disciplines at the centre of the discussion:

  • Tone from the top.
  • Proportionate controls.
  • Third-party oversight.
  • Incentives and reward structures.
  • Training and awareness.
  • Escalation pathways.
  • Whether management truly understands how misconduct could occur in practice.

For boards, the practical issue is whether cybersecurity, data loss prevention, internal fraud, conduct, corporate criminal offences and third-party risk are being viewed as separate control programmes, or whether management can see the common human and organisational drivers running across them. In that lies the most frequent blind spot for organisations.


One of the biggest misconceptions is that insider risk management is primarily about identifying malicious actors. That framing is too crude and too late.

Good insider risk governance is about understanding how the organisation really works. It asks:

  • Where do staff experience unreasonable pressure?
  • Where are people bypassing controls to get the job done?
  • Which teams depend too heavily on one individual?
  • Do employees feel able to raise concerns?
  • Are managers trained to recognise changes in staff behaviour or performance?
  • Are third parties subject to the same standards as employees?
  • Do the organisation’s stated values survive when commercial pressure rises?

When organisations understand their people better, they can remove unnecessary friction, design more proportionate controls, improve engagement and reduce the productivity losses caused by poorly designed processes. The best insider risk programmes do not treat employees as suspects. They help create an environment in which people are more likely to act responsibly, raise concerns early and remain engaged with the organisation’s purpose.


There is also a broader societal dimension. Boards are not only responsible for protecting assets and delivering returns. They are stewards of institutions that employees, customers, investors and communities need to trust.

When major organisations suffer repeated failures involving misconduct, data misuse, fraud or weak accountability, the damage does not remain contained within the company. It contributes to a wider erosion of confidence in business, leadership and institutions. For NEDs, this matters because reputation is usually a second-order consequence. It follows a more fundamental failure in culture, behaviour, governance or control.

The productive question is therefore not:

“How do we protect our reputation?”

It is:

“Do we understand the conditions inside this organisation that determine whether people will trust it?”

Insider risk provides one of the clearest lenses through which to answer that question.


Insider risk is not static. It changes with technology, incentives and market structures.

Prediction markets are a good example. Employees with access to privileged information may now have new opportunities to profit from future events, corporate announcements or operational outcomes. That creates insider-trading, conduct and reputational risks in forms that many organisations were not considering a year ago.

The issue is broader than traditional securities markets. It is about whether employees can monetise knowledge gained through their role, even where existing policies were written for a different environment.

Boards should ask whether their conduct frameworks, conflicts policies and monitoring arrangements have kept pace with those changing incentives. That is the discipline insider risk governance requires: not a static control set, but an evolving understanding of how people, access and incentives interact with technology and external markets.


Insider risk does not need to become another silo or another lengthy item on the risk register. It should become a lens through which boards examine the human and organisational dimensions of the risks they already oversee.

The core question is:

“Do we have sufficient visibility of how people, culture, access and incentives could amplify our principal risks, or strengthen our organisation?”

That is where board oversight adds most value.

📌 Questions NEDs should be asking:

  • Where are the human failure points in our most important controls?
  • Which employees and third parties hold access capable of creating disproportionate harm?
  • What are we learning from near misses, speak-up data, conduct indicators and control workarounds?
  • How are we governing unauthorised AI use and the permissions given to AI agents?
  • Are fraud, cybersecurity, data loss prevention conduct and corporate criminal offence risks being governed together where they share common drivers?
  • What emerging technologies or incentives could change employee behaviour faster than our policies and controls can adapt?

This article is written by NEDonBoard member, Martin Schwarz.

Martin Schwarz is a senior governance, risk and national security leader with more than 30 years’ experience strengthening institutional resilience across government, financial services and the private sector. He has held senior roles in the UK and New Zealand, including Director of Investigations at the New Zealand Security Intelligence Service, where he led national security investigations. In financial services, Martin held senior economic crime and regulatory risk roles at the Bank of New Zealand and Nationwide Building Society. He is now the co-founder of SSIR Partners Ltd., a governance technology start-up and consultancy specialising in insider-risk governance, organisational culture and broader human-centric risk. Martin is a member of NEDonBoard and the Security Institute.


If, like Martin, you are interested in writing for the benefits of the NEDonBoard member community, please email [email protected].

loading