Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Insider Threat Awareness Training for CMMC
External hackers get the headlines, but insider threats cause some of the most damaging security incidents. CMMC recognizes this reality with a specific requirement for insider threat awareness training. Every employee must learn to recognize potential insider threats and know how to report concerns.
Insider threat means the risk that someone within your organization—an employee, contractor, or business partner—will use their authorized access to harm your organization, intentionally or accidentally.
This is not about creating a culture of suspicion. It is about helping employees understand that protecting CUI is everyone’s responsibility, and that reporting concerns early can prevent serious damage.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection.
The CMMC Insider Threat Requirement
Requirement AT.L2-3.2.3 states:
“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”
This requirement ensures employees can:
- Recognize behaviors that may indicate an insider threat
- Understand why insider threats matter
- Know how and where to report concerns
- Feel comfortable reporting without fear of retaliation
Types of Insider Threats
Training should cover the different ways insider threats manifest:
Malicious Insiders
People who intentionally misuse access for personal gain, revenge, or ideology:
- Stealing data to sell to competitors or foreign governments
- Sabotaging systems after termination notice
- Leaking information to unauthorized parties
- Fraud or theft using system access
Negligent Insiders
People who accidentally cause harm through carelessness:
- Falling for phishing attacks
- Losing devices containing CUI
- Sharing credentials inappropriately
- Ignoring security policies out of convenience
Compromised Insiders
People whose credentials or access have been stolen by external attackers:
- Credentials stolen through phishing
- Accounts compromised through malware
- Access was exploited after the device theft
Coerced Insiders
People forced to act against the organization:
- Blackmail or extortion
- Threats to family members
- Foreign intelligence recruitment
Warning Signs to Train Employees to Recognize
Insider threat training should teach employees to notice concerning behaviors:
Access and Information Behaviors
- Accessing information outside job responsibilities
- Requesting access to systems or data not needed for work
- Working unusual hours without a clear business need
- Taking work home unnecessarily
- Excessive copying or downloading of files
- Interest in projects or information unrelated to job duties
Behavioral Changes
- Sudden changes in financial situation (unexplained wealth or sudden debt)
- Expressed dissatisfaction with the organization
- Discussing resignation while continuing to access sensitive information
- Changes in work habits or attendance
- Defensive reactions to routine questions about work
Security Policy Violations
- Attempting to bypass security controls
- Disabling or circumventing security software
- Using unauthorized devices or storage media
- Sharing credentials with others
- Tailgating or badge sharing
Communication Red Flags
- Unusual contact with competitors or foreign entities
- Secretive communications
- Reluctance to take a vacation (wanting continuous access)
- Discussing sensitive information in inappropriate settings
What Training Should Emphasize
It Is Not About Spying on Coworkers
Frame insider threat awareness as:
- Protecting the organization and coworkers
- Helping colleagues who may be struggling
- Fulfilling contractual obligations to protect CUI
- Being part of a security-conscious team
Avoid creating an atmosphere of paranoia or distrust.
Context Matters
Not every behavior is suspicious. Training should help employees:
- Consider context before jumping to conclusions
- Look for patterns rather than isolated incidents
- Distinguish between unusual and actually concerning
- Report concerns rather than accusations
Reporting Is Not Accusing
Emphasize that:
- Reporting a concern is not the same as accusing someone
- It is better to report and be wrong than ignore a real threat
- Investigations will determine whether concern is warranted
- Most reports do not lead to negative actions against the subject
Protection from Retaliation
Assure employees that:
- Good-faith reports are protected
- Retaliation for reporting is prohibited
- Reports can be made confidentially
- The organization takes reporting seriously
Reporting Procedures
Training must include clear reporting instructions:
Who to Report To
Identify specific contacts:
- Security officer or team
- Manager or supervisor
- Human resources
- Anonymous hotline (if available)
- Alternative contacts if the primary is the concern
What to Report
Guidance on what information to include:
- What behavior was observed
- When and where it occurred
- Who was involved
- Why does it seem concerning
- Any supporting details
How to Report
Provide multiple channels:
- In-person conversation
- Email to security team
- Phone hotline
- Anonymous reporting system
- Written report form
Building Training Content
Effective insider threat training includes:
Real-World Examples
Use case studies (anonymized or from public sources) showing:
- How insider incidents unfolded
- Warning signs that were missed
- Consequences of the incident
- How early reporting could have helped
Scenario Exercises
Present situations for employees to evaluate:
“You notice a coworker copying large amounts of files to a USB drive the week before their last day. They mention they want to keep samples of their work. What should you do?”
Walking through scenarios builds judgment and confidence in reporting.
Interactive Discussion
For in-person training, discuss:
- Why people become insider threats
- Barriers to reporting concerns
- How to support struggling colleagues
- Balance between awareness and trust
Frequency and Reinforcement
Initial Training
Cover insider threat awareness as part of new hire orientation. Do not delay until annual training.
Annual Refresher
Include insider threat content in annual security awareness training. Review indicators, update with new examples, and reinforce reporting procedures.
Ongoing Awareness
Reinforce between formal training:
- Periodic reminders about reporting procedures
- Case studies in newsletters or meetings
- Posters highlighting key points
- Manager discussions with teams
Documenting Insider Threat Training
Assessors need evidence of insider threat training:
Training Content
- Slides, videos, or materials covering insider threat topics
- Scenario exercises and discussion guides
- Reporting procedure documentation
Completion Records
- Attendance or completion tracking
- Assessment scores on insider threat questions
- Acknowledgment of reporting procedures
Program Evidence
- Training calendar showing insider threat coverage
- Policy requiring insider threat training
- Evidence of reporting channel communication
Common Mistakes in Insider Threat Training
Mistake 1: Creating Paranoia
Overly aggressive training creates a toxic culture. Balance awareness with trust and context.
Mistake 2: Vague Reporting Instructions
“Report concerns to management” is too vague. Provide specific names, contacts, and methods.
Mistake 3: No Protection Discussion
If employees fear retaliation, they will not report. Explicitly address protection and confidentiality.
Mistake 4: Forgetting Remote Workers
Remote employees may observe concerning behavior in virtual interactions. Include remote-relevant examples.
Mistake 5: Once and Done
Annual training alone is insufficient. Reinforce throughout the year.
Key Takeaways
CMMC requires specific training on recognizing and reporting insider threat indicators. Train employees on warning signs across access patterns, behavioral changes, policy violations, and communications.
Emphasize that reporting is about protection, not accusation. Provide clear, multiple reporting channels and assure employees that good-faith reports are protected from retaliation.
Build a security-conscious culture where employees feel responsible for protecting CUI and are comfortable raising concerns early.
Related Articles:
- CMMC Security Awareness Training Requirements
- How to Create a CMMC Training Program
- What is SPRS?
- How to Budget for CMMC Compliance
- CMMC Level 2 Self-Assessment Requirements
- DoD CMMC Level 2 Assessment Guide
Official Sources: This article is based on NIST SP 800-171 Revision 2 requirement 3.2.3, the DoD CMMC Level 2 Assessment Guide, and resources from the National Counterintelligence and Security Center.
Need help developing insider threat training for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.