2026-06-23OPINION · INSIDERTHREAT · PRIVILEGEDACCESSMANAGEMENT · IDENTITYGOVERNANCE · CYBERSECURITYSTRATEGY · INFOSECLEADERSHIP5 MIN READ READ
FILED UNDER

Fake Contractors Expose What Access Governance Really Means

When adversaries enter through the front door, the controls that catch them are not the ones most organisations have built.

The Insider Threat Problem Was Never Really About Disgruntled Employees

Most organisations that have an insider threat program built it around the same archetype: the resentful employee who downloads client data on their way out the door, or the careless contractor who clicks the wrong link. That framing shaped the investment, the controls, and — critically — who owned the problem. It became an HR issue with a thin IT veneer. Boards were comfortable deprioritising it because it felt manageable, human, and relatively rare.

That framing is now dangerously obsolete. Recent reporting from iTnews confirms that the North Korean IT worker scheme — where state-sponsored operatives pose as legitimate remote contractors to gain employment and access — is expanding beyond technology firms in Australia into sectors including healthcare. These are not disgruntled employees. They are adversaries who entered through your front door, passed your hiring process, received legitimate credentials, and are operating inside your access controls with full cover.

That is insider threat. The disgruntled employee just had better PR.

Why the Old Framing Survived This Long

The “rogue employee” narrative was always more comfortable than the alternative. It implied the problem was an exception — someone behaving badly — rather than a structural failure in how organisations govern privileged access and verify identity over time. It also gave boards and executives a familiar lens: people problems have people solutions. Culture, HR policy, exit procedures. None of that requires a serious conversation about whether your identity governance architecture is fit for purpose.

Insider threat programs built on this foundation tend to reflect it. They focus on behavioural monitoring for anomalies that suggest someone is about to leave, or has already mentally checked out. They are retrospective. They assume the person sitting in the role is who they say they are.

That assumption is no longer safe.

Infiltration Is the New Baseline

The fake IT worker threat is not a novel attack vector that emerged from nowhere. It is a logical extension of what sophisticated threat actors have always understood: that the most durable access is legitimate access. Credentials issued by your own IT team, access rights scoped to a real job function, a plausible work history, and the organisational invisibility that comes with being a contractor in a large enterprise. No malware required. No phishing. No lateral movement that triggers your detection rules — because they started where they needed to be.

What makes the Australian expansion into healthcare significant is not the sector itself, but what it signals about selection criteria. Healthcare organisations hold extraordinarily sensitive personal data, operate complex third-party and vendor ecosystems, and — bluntly — have historically underinvested in identity governance relative to their data risk. They are attractive not because they are easy targets in a technical sense, but because their access control maturity often lags their data sensitivity.

That gap is the attack surface.

What Privileged Access Governance Actually Means Here

This is where the investment conversation needs to change. Privileged access governance is frequently presented to boards as a compliance exercise — something you do to satisfy APRA CPS 234 or to tick boxes in an audit. The genuine security value gets lost in the compliance framing.

What privileged access governance actually prevents is exactly this scenario: an individual with no legitimate claim to your environment operating inside it indefinitely because no one is asking whether the access remains appropriate, whether the identity behind the credentials is who they claim to be, or whether the work being performed matches the access granted.

Periodic access reviews, robust contractor identity verification, separation of duties, and genuine visibility into what privileged accounts are doing are not compliance theatre when the threat model includes deliberate infiltration. They are the controls that catch an adversary who never had to break in.

Australian organisations operating under the Security of Critical Infrastructure Act have some regulatory pressure here, but enforcement focus has largely been on the infrastructure layer rather than identity governance depth. The Privacy Act reforms under way increase the consequence of a data exposure but do not, by themselves, change the access controls that would prevent one. OAIC has the power to investigate and fine, but the fine comes after the breach. The control has to come before it.

The Governance Conversation Boards Are Not Having

Boards that receive cyber security reporting typically see metrics oriented around technical controls: vulnerability counts, patching cadence, phishing simulation results. Almost none of that is relevant to detecting a fake IT worker. What is relevant — and almost never reported — is the quality and frequency of access reviews, the rigour of contractor onboarding identity verification, and whether anyone is correlating access rights against actual work output.

This is a governance gap, not a technical one. The question for boards is not whether their CISO has deployed the right tool. It is whether the organisation can answer three questions with confidence: Do we know who has privileged access right now? Do we know whether each of those people should still have it? And do we have any assurance that the identity behind each account is the person we employed?

Most organisations cannot answer all three. Many cannot answer any of them cleanly.

What Should Change

Stop treating insider threat as an HR-adjacent problem that security teams monitor on the side. The threat model has changed. Deliberate infiltration by sophisticated actors — including state-affiliated ones — is now a realistic scenario for Australian organisations outside the defence and critical infrastructure sectors. Healthcare, professional services, and any organisation with valuable data and a reliance on contractors or remote IT staff are plausible targets.

The investment conversation needs to shift accordingly. Insider threat programs that are built around detecting the disgruntled employee are not built for this. Identity verification at the point of hire and periodically thereafter, genuine least-privilege enforcement, access reviews that are treated as a security control rather than an audit formality, and visibility into what privileged accounts are actually doing — these are the capabilities that matter.

The disgruntled employee was never the worst case. It just felt like it, because it was the case we were comfortable imagining.

Next dossier
AI Adoption Has a Carbon Liability Boards Haven't Priced →
Engage the author
Paul Healy is currently taking on briefs for FY26.
Brief Paul
Share