If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Insider Threat Awareness Training for CMMC
External hackers get the headlines, but insider threats cause some of the most damaging security incidents. CMMC recognizes this reality with a specific requirement for insider threat awareness training. Every employee must learn to recognize potential insider threats and know how to report concerns.
Insider threat means the risk that someone within your organization—an employee, contractor, or business partner—will use their authorized access to harm your organization, intentionally or accidentally.
This is not about creating a culture of suspicion. It is about helping employees understand that protecting CUI is everyone’s responsibility, and that reporting concerns early can prevent serious damage.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection.
The CMMC Insider Threat Requirement
Requirement AT.L2-3.2.3 states:
“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”
This requirement ensures employees can:
- Recognize behaviors that may indicate an insider threat
- Understand why insider threats matter
- Know how and where to report concerns
- Feel comfortable reporting without fear of retaliation
Types of Insider Threats
Training should cover the different ways insider threats manifest:
Malicious Insiders
People who intentionally misuse access for personal gain, revenge, or ideology:
- Stealing data to sell to competitors or foreign governments
- Sabotaging systems after termination notice
- Leaking information to unauthorized parties
- Fraud or theft using system access
Negligent Insiders
People who accidentally cause harm through carelessness:
- Falling for phishing attacks
- Losing devices containing CUI
- Sharing credentials inappropriately
- Ignoring security policies out of convenience
Compromised Insiders
People whose credentials or access have been stolen by external attackers:
- Credentials stolen through phishing
- Accounts compromised through malware
- Access was exploited after the device theft
Coerced Insiders
People forced to act against the organization:
- Blackmail or extortion
- Threats to family members
- Foreign intelligence recruitment
Warning Signs to Train Employees to Recognize
Insider threat training should teach employees to notice concerning behaviors:
Access and Information Behaviors
- Accessing information outside job responsibilities
- Requesting access to systems or data not needed for work
- Working unusual hours without a clear business need
- Taking work home unnecessarily
- Excessive copying or downloading of files
- Interest in projects or information unrelated to job duties
Behavioral Changes
- Sudden changes in financial situation (unexplained wealth or sudden debt)
- Expressed dissatisfaction with the organization
- Discussing resignation while continuing to access sensitive information
- Changes in work habits or attendance
- Defensive reactions to routine questions about work
Security Policy Violations
- Attempting to bypass security controls
- Disabling or circumventing security software
- Using unauthorized devices or storage media
- Sharing credentials with others
- Tailgating or badge sharing
Communication Red Flags
- Unusual contact with competitors or foreign entities
- Secretive communications
- Reluctance to take a vacation (wanting continuous access)
- Discussing sensitive information in inappropriate settings
What Training Should Emphasize
It Is Not About Spying on Coworkers
Frame insider threat awareness as:
- Protecting the organization and coworkers
- Helping colleagues who may be struggling
- Fulfilling contractual obligations to protect CUI
- Being part of a security-conscious team
Avoid creating an atmosphere of paranoia or distrust.
Context Matters
Not every behavior is suspicious. Training should help employees:
- Consider context before jumping to conclusions
- Look for patterns rather than isolated incidents
- Distinguish between unusual and actually concerning
- Report concerns rather than accusations
Reporting Is Not Accusing
Emphasize that:
- Reporting a concern is not the same as accusing someone
- It is better to report and be wrong than ignore a real threat
- Investigations will determine whether concern is warranted
- Most reports do not lead to negative actions against the subject
Protection from Retaliation
Assure employees that:
- Good-faith reports are protected
- Retaliation for reporting is prohibited
- Reports can be made confidentially
- The organization takes reporting seriously
Reporting Procedures
Training must include clear reporting instructions:
Who to Report To
Identify specific contacts:
- Security officer or team
- Manager or supervisor
- Human resources
- Anonymous hotline (if available)
- Alternative contacts if the primary is the concern
What to Report
Guidance on what information to include:
- What behavior was observed
- When and where it occurred
- Who was involved
- Why does it seem concerning
- Any supporting details
How to Report
Provide multiple channels:
- In-person conversation
- Email to security team
- Phone hotline
- Anonymous reporting system
- Written report form
Building Training Content
Effective insider threat training includes:
Real-World Examples
Use case studies (anonymized or from public sources) showing:
- How insider incidents unfolded
- Warning signs that were missed
- Consequences of the incident
- How early reporting could have helped
Scenario Exercises
Present situations for employees to evaluate:
“You notice a coworker copying large amounts of files to a USB drive the week before their last day. They mention they want to keep samples of their work. What should you do?”
Walking through scenarios builds judgment and confidence in reporting.
Interactive Discussion
For in-person training, discuss:
- Why people become insider threats
- Barriers to reporting concerns
- How to support struggling colleagues
- Balance between awareness and trust
Frequency and Reinforcement
Initial Training
Cover insider threat awareness as part of new hire orientation. Do not delay until annual training.
Annual Refresher
Include insider threat content in annual security awareness training. Review indicators, update with new examples, and reinforce reporting procedures.
Ongoing Awareness
Reinforce between formal training:
- Periodic reminders about reporting procedures
- Case studies in newsletters or meetings
- Posters highlighting key points
- Manager discussions with teams
Documenting Insider Threat Training
Assessors need evidence of insider threat training:
Training Content
- Slides, videos, or materials covering insider threat topics
- Scenario exercises and discussion guides
- Reporting procedure documentation
Completion Records
- Attendance or completion tracking
- Assessment scores on insider threat questions
- Acknowledgment of reporting procedures
Program Evidence
- Training calendar showing insider threat coverage
- Policy requiring insider threat training
- Evidence of reporting channel communication
Common Mistakes in Insider Threat Training
Mistake 1: Creating Paranoia
Overly aggressive training creates a toxic culture. Balance awareness with trust and context.
Mistake 2: Vague Reporting Instructions
“Report concerns to management” is too vague. Provide specific names, contacts, and methods.
Mistake 3: No Protection Discussion
If employees fear retaliation, they will not report. Explicitly address protection and confidentiality.
Mistake 4: Forgetting Remote Workers
Remote employees may observe concerning behavior in virtual interactions. Include remote-relevant examples.
Mistake 5: Once and Done
Annual training alone is insufficient. Reinforce throughout the year.
Key Takeaways
CMMC requires specific training on recognizing and reporting insider threat indicators. Train employees on warning signs across access patterns, behavioral changes, policy violations, and communications.
Emphasize that reporting is about protection, not accusation. Provide clear, multiple reporting channels and assure employees that good-faith reports are protected from retaliation.
Build a security-conscious culture where employees feel responsible for protecting CUI and are comfortable raising concerns early.
Keep reading
More in CMMC Training & Awareness
- CMMC Security Awareness Training Requirements →
- CMMC Training Documentation and Evidence →
- How to Create a CMMC Training Program →
- Role-Based Training for CMMC Compliance →
- What is SPRS? →
- How to Budget for CMMC Compliance →
- CMMC Level 2 Self-Assessment Requirements →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5