Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Insider Threat Awareness Training for CMMC

External hackers get the headlines, but insider threats cause some of the most damaging security incidents. CMMC recognizes this reality with a specific requirement for insider threat awareness training. Every employee must learn to recognize potential insider threats and know how to report concerns.

Insider threat means the risk that someone within your organization—an employee, contractor, or business partner—will use their authorized access to harm your organization, intentionally or accidentally.

This is not about creating a culture of suspicion. It is about helping employees understand that protecting CUI is everyone’s responsibility, and that reporting concerns early can prevent serious damage.

CUI stands for Controlled Unclassified Information—sensitive government data requiring protection.

The CMMC Insider Threat Requirement

Requirement AT.L2-3.2.3 states:

“Provide security awareness training on recognizing and reporting potential indicators of insider threat.”

This requirement ensures employees can:

  • Recognize behaviors that may indicate an insider threat
  • Understand why insider threats matter
  • Know how and where to report concerns
  • Feel comfortable reporting without fear of retaliation

Types of Insider Threats

Training should cover the different ways insider threats manifest:

Malicious Insiders

People who intentionally misuse access for personal gain, revenge, or ideology:

  • Stealing data to sell to competitors or foreign governments
  • Sabotaging systems after termination notice
  • Leaking information to unauthorized parties
  • Fraud or theft using system access

Negligent Insiders

People who accidentally cause harm through carelessness:

  • Falling for phishing attacks
  • Losing devices containing CUI
  • Sharing credentials inappropriately
  • Ignoring security policies out of convenience

Compromised Insiders

People whose credentials or access have been stolen by external attackers:

  • Credentials stolen through phishing
  • Accounts compromised through malware
  • Access was exploited after the device theft

Coerced Insiders

People forced to act against the organization:

  • Blackmail or extortion
  • Threats to family members
  • Foreign intelligence recruitment

Warning Signs to Train Employees to Recognize

Insider threat training should teach employees to notice concerning behaviors:

Access and Information Behaviors

  • Accessing information outside job responsibilities
  • Requesting access to systems or data not needed for work
  • Working unusual hours without a clear business need
  • Taking work home unnecessarily
  • Excessive copying or downloading of files
  • Interest in projects or information unrelated to job duties

Behavioral Changes

  • Sudden changes in financial situation (unexplained wealth or sudden debt)
  • Expressed dissatisfaction with the organization
  • Discussing resignation while continuing to access sensitive information
  • Changes in work habits or attendance
  • Defensive reactions to routine questions about work

Security Policy Violations

  • Attempting to bypass security controls
  • Disabling or circumventing security software
  • Using unauthorized devices or storage media
  • Sharing credentials with others
  • Tailgating or badge sharing

Communication Red Flags

  • Unusual contact with competitors or foreign entities
  • Secretive communications
  • Reluctance to take a vacation (wanting continuous access)
  • Discussing sensitive information in inappropriate settings

What Training Should Emphasize

It Is Not About Spying on Coworkers

Frame insider threat awareness as:

  • Protecting the organization and coworkers
  • Helping colleagues who may be struggling
  • Fulfilling contractual obligations to protect CUI
  • Being part of a security-conscious team

Avoid creating an atmosphere of paranoia or distrust.

Context Matters

Not every behavior is suspicious. Training should help employees:

  • Consider context before jumping to conclusions
  • Look for patterns rather than isolated incidents
  • Distinguish between unusual and actually concerning
  • Report concerns rather than accusations

Reporting Is Not Accusing

Emphasize that:

  • Reporting a concern is not the same as accusing someone
  • It is better to report and be wrong than ignore a real threat
  • Investigations will determine whether concern is warranted
  • Most reports do not lead to negative actions against the subject

Protection from Retaliation

Assure employees that:

  • Good-faith reports are protected
  • Retaliation for reporting is prohibited
  • Reports can be made confidentially
  • The organization takes reporting seriously

Reporting Procedures

Training must include clear reporting instructions:

Who to Report To

Identify specific contacts:

  • Security officer or team
  • Manager or supervisor
  • Human resources
  • Anonymous hotline (if available)
  • Alternative contacts if the primary is the concern

What to Report

Guidance on what information to include:

  • What behavior was observed
  • When and where it occurred
  • Who was involved
  • Why does it seem concerning
  • Any supporting details

How to Report

Provide multiple channels:

  • In-person conversation
  • Email to security team
  • Phone hotline
  • Anonymous reporting system
  • Written report form

Building Training Content

Effective insider threat training includes:

Real-World Examples

Use case studies (anonymized or from public sources) showing:

  • How insider incidents unfolded
  • Warning signs that were missed
  • Consequences of the incident
  • How early reporting could have helped

Scenario Exercises

Present situations for employees to evaluate:

“You notice a coworker copying large amounts of files to a USB drive the week before their last day. They mention they want to keep samples of their work. What should you do?”

Walking through scenarios builds judgment and confidence in reporting.

Interactive Discussion

For in-person training, discuss:

  • Why people become insider threats
  • Barriers to reporting concerns
  • How to support struggling colleagues
  • Balance between awareness and trust

Frequency and Reinforcement

Initial Training

Cover insider threat awareness as part of new hire orientation. Do not delay until annual training.

Annual Refresher

Include insider threat content in annual security awareness training. Review indicators, update with new examples, and reinforce reporting procedures.

Ongoing Awareness

Reinforce between formal training:

  • Periodic reminders about reporting procedures
  • Case studies in newsletters or meetings
  • Posters highlighting key points
  • Manager discussions with teams

Documenting Insider Threat Training

Assessors need evidence of insider threat training:

Training Content

  • Slides, videos, or materials covering insider threat topics
  • Scenario exercises and discussion guides
  • Reporting procedure documentation

Completion Records

  • Attendance or completion tracking
  • Assessment scores on insider threat questions
  • Acknowledgment of reporting procedures

Program Evidence

  • Training calendar showing insider threat coverage
  • Policy requiring insider threat training
  • Evidence of reporting channel communication

Common Mistakes in Insider Threat Training

Mistake 1: Creating Paranoia

Overly aggressive training creates a toxic culture. Balance awareness with trust and context.

Mistake 2: Vague Reporting Instructions

“Report concerns to management” is too vague. Provide specific names, contacts, and methods.

Mistake 3: No Protection Discussion

If employees fear retaliation, they will not report. Explicitly address protection and confidentiality.

Mistake 4: Forgetting Remote Workers

Remote employees may observe concerning behavior in virtual interactions. Include remote-relevant examples.

Mistake 5: Once and Done

Annual training alone is insufficient. Reinforce throughout the year.

Key Takeaways

CMMC requires specific training on recognizing and reporting insider threat indicators. Train employees on warning signs across access patterns, behavioral changes, policy violations, and communications.

Emphasize that reporting is about protection, not accusation. Provide clear, multiple reporting channels and assure employees that good-faith reports are protected from retaliation.

Build a security-conscious culture where employees feel responsible for protecting CUI and are comfortable raising concerns early.

Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2 requirement 3.2.3, the DoD CMMC Level 2 Assessment Guide, and resources from the National Counterintelligence and Security Center.

Need help developing insider threat training for CMMC compliance? Contact Greypike for expert guidance on Level 1 and Level 2 certification, or get started with Obolix to streamline your compliance journey.

Table of Contents