The Insider Threat Problem Was Never Really About Disgruntled Employees
Most organisations that have an insider threat program built it around the same archetype: the resentful employee who downloads client data on their way out the door, or the careless contractor who clicks the wrong link. That framing shaped the investment, the controls, and — critically — who owned the problem. It became an HR issue with a thin IT veneer. Boards were comfortable deprioritising it because it felt manageable, human, and relatively rare.
That framing is now dangerously obsolete. Recent reporting from iTnews confirms that the North Korean IT worker scheme — where state-sponsored operatives pose as legitimate remote contractors to gain employment and access — is expanding beyond technology firms in Australia into sectors including healthcare. These are not disgruntled employees. They are adversaries who entered through your front door, passed your hiring process, received legitimate credentials, and are operating inside your access controls with full cover.
That is insider threat. The disgruntled employee just had better PR.
Why the Old Framing Survived This Long
The “rogue employee” narrative was always more comfortable than the alternative. It implied the problem was an exception — someone behaving badly — rather than a structural failure in how organisations govern privileged access and verify identity over time. It also gave boards and executives a familiar lens: people problems have people solutions. Culture, HR policy, exit procedures. None of that requires a serious conversation about whether your identity governance architecture is fit for purpose.
Insider threat programs built on that foundation inherit its shape. They watch for behavioural anomalies suggesting someone is about to leave or has already checked out mentally, which makes them retrospective by design, and they rest on one assumption that used to be safe: that the person in the role is who they said they were at interview.
Infiltration Is the New Baseline
The fake IT worker scheme is not a novel attack vector so much as a patient application of something sophisticated actors have understood for a long time. The most durable access is legitimate access — credentials issued by your own IT team, rights scoped to a genuine job function, a plausible work history, and the organisational invisibility that comes free with being a contractor in a large enterprise. There is no malware to detect and no phishing to block, and nothing triggers the lateral movement rules, because the operator started where they needed to be.
The expansion into Australian healthcare says less about that sector than about how targets are being chosen. Healthcare organisations hold extraordinarily sensitive personal data, run complicated vendor ecosystems and, bluntly, have underinvested in identity governance relative to the data they carry. The attraction is not technical weakness. It is the distance between how sensitive the data is and how mature the access controls around it are, and that distance is the attack surface.
What Privileged Access Governance Buys You Here
The investment conversation is where this goes wrong. Privileged access governance usually reaches a board dressed as compliance — something done to satisfy CPS 234 or to close an audit finding — and the security value disappears inside that framing.
What it actually prevents is this exact scenario: someone with no legitimate claim to your environment working inside it indefinitely, because nobody is asking whether the access is still warranted, whether the identity behind the credentials is real, or whether the work being done matches the rights granted.
Access reviews, contractor identity verification, separation of duties, real visibility into what privileged accounts do all day. None of that is theatre once the threat model includes deliberate infiltration. Those are the controls that catch an adversary who never had to break in.
Australian organisations operating under the Security of Critical Infrastructure Act have some regulatory pressure here, but enforcement focus has largely been on the infrastructure layer rather than identity governance depth. The Privacy Act reforms under way increase the consequence of a data exposure but do not, by themselves, change the access controls that would prevent one. OAIC has the power to investigate and fine, but the fine comes after the breach. The control has to come before it.
The Governance Conversation Boards Are Not Having
Boards that receive cyber security reporting typically see metrics oriented around technical controls: vulnerability counts, patching cadence, phishing simulation results. Almost none of that is relevant to detecting a fake IT worker. What is relevant — and almost never reported — is the quality and frequency of access reviews, the rigour of contractor onboarding identity verification, and whether anyone is correlating access rights against actual work output.
The gap is in governance rather than tooling. Whether the CISO has bought the right platform is beside the point; what matters is whether the organisation can answer three questions cleanly. Who holds privileged access right now? Should each of them still have it? And is there any assurance that the identity behind each account belongs to the person you employed?
Most organisations cannot answer all three. A fair number cannot answer any of them without a week’s notice.
What Should Change
Insider threat has to stop being an HR-adjacent problem that security monitors on the side. Deliberate infiltration by sophisticated actors, some of them state-affiliated, is now a realistic scenario for Australian organisations well outside defence and critical infrastructure. Healthcare, professional services, anyone holding valuable data and leaning on contractors or remote IT staff: all plausible.
A program designed to catch the disgruntled employee will not catch any of that, so the investment has to move. Identity verification at hire and again periodically. Least privilege actually enforced rather than aspired to. Access reviews run as a security control instead of an audit formality. Somebody looking at what privileged accounts do.
The disgruntled employee was never the worst case. It just felt like it, because it was the case we were comfortable imagining.