A security risk that originates from within an organization — an employee, contractor, or partner with legitimate access who misuses it.
Insider threats are harder to detect than external attacks because the activity often looks like normal, authorized access — behavioral monitoring becomes critical.