Assembling a Multi-Disciplinary Insider Threat Management Team provides CISA guidance for organizations seeking to establish and operate teams responsible for identifying, assessing, and mitigating insider threats. Designed particularly for critical infrastructure organizations, the guide emphasizes combining expertise from cybersecurity, physical security, human resources, legal counsel, operations, law enforcement, and behavioral or mental health disciplines. CISA outlines the benefits, composition, training, and responsibilities of an effective threat management team and introduces a four-part Plan, Organize, Execute, and Maintain (POEM) framework for building sustainable insider threat capabilities. The guidance also addresses sensitive information handling, employee reporting, legal compliance, data collection, training, and partnerships needed to reduce insider risk while supporting organizational security and workforce trust.

| Format: |
|
| Topics: | |
| Website: | Visit Publisher Website |
| Author(s): |
|
| Publisher: | Cybersecurity and Infrastructure Security Agency (CISA) |
| Published: | January 1, 2026 |
| Tags: | cisacybersecuritydhsInsider Riskinsider threatInsider Threat Management |