Industry research (Ponemon, Verizon, IBM) consistently divides insider incidents into three buckets:
- Negligent — well-intentioned employees who click the wrong link, misconfigure a bucket, or email data to the wrong address. ~60% of incidents.
- Compromised — legitimate accounts taken over by external attackers. ~25%.
- Malicious — employees deliberately stealing or sabotaging. ~15%.
Most public coverage focuses on the malicious category. Most actual damage comes from the negligent category. Your controls need to address all three.