CISA released an updated edition of its Insider Threat Mitigation Guide on September 9, replacing the 2020 version with a shorter, more current document built around hybrid work, AI misuse and the risks that surface when an employee is on the way out the door. The agency said the update reflects “evolving considerations such as the rise in hybrid and remote work, and advances in artificial intelligence,” and added new case studies and expanded guidance on access control, visitor screening, and mitigating risk during adverse employee separations.

Why it matters: most insider-threat programs were built around an office-based, single-employer workforce and have not been rewritten since. A remote or hybrid employee’s access footprint, personal-device usage and the timing of an offboarding process all look different than they did in 2020, and CISA’s own case-study update suggests the agency has seen enough incidents fitting that newer profile to warrant a rewrite rather than a patch. The AI addition is notable on its own terms: CISA is now treating AI-assisted manipulation and deception of insiders, not just insiders misusing AI tools, as part of the threat surface a program needs to cover.

The original insight here is about sequencing, not content: CISA’s own guide update explicitly connects offboarding risk to access control failures, which is the same failure mode driving the shift toward continuous access review that this week’s non-human-identity coverage and the Shai-Hulud credential-hunting worm both point to. A program built to catch a departing employee’s badge and laptop, but not their still-live API tokens and AI agent sessions, is reviewing half the exit.

Source: CISA