Insider Threat Training

Employee using an access card at a secure office door, insider threat training

Most insider incidents show warning signs that someone noticed and did not act on. This insider threat training gives your managers, human resources and security teams the confidence to recognise those signs, respond early and fairly, and build a counter insider threat program that meets PSPF and SOCI Act expectations. It is delivered by practitioners who have designed and run these programs for government and critical infrastructure.

What your organisation gains

  • Managers who recognise concerning behaviour early and know exactly what to do with it.
  • Personnel security controls that work across the whole employment lifecycle, from recruitment to separation.
  • A clear path to a counter insider threat program that satisfies PSPF Release 2026 and CIRMP personnel hazard rules.
  • Training built around your own procedures and scenarios, which can then be rolled out to the wider workforce.
DeliveryIn-house for your organisation, at your premises or live online via Microsoft Teams
DurationAgreed with you, from a two-hour briefing to a two-day program
LevelsExecutive briefing, manager or practitioner workshop, and train-the-trainer
ApproachPractitioner-led, with case studies, active learning and practical exercises
Suited toExecutives, managers, HR and security teams
Course codeAGILPERSEC001

Why train with Agilient

Taught by practitioners

Every Agilient consultant has at least 20 years of experience, typically as security managers within large organisations, and has dealt first hand with the issues the course covers.

Built for your organisation

Content, examples and scenarios are shaped around your sites, policies and incident history, not an off-the-shelf syllabus that dates quickly.

Active learning

Participants work through case studies and carry out the activities themselves, so the skills stick after the day.

Designed for you to own

Train-the-trainer options and a strategy for moving the course into your own online learning mean the capability stays in-house.

Why insider threat is a priority now

ASIO defines insiders as current and former employees or contractors who use their access, intentionally or unintentionally, to cause harm. In its 2026 Annual Threat Assessment it described espionage and foreign interference as being at extreme levels, and it continues to warn that foreign intelligence services use professional networking sites to identify and cultivate Australians with access to sensitive information. ASIO’s July 2025 cost of espionage report estimated that espionage cost the Australian economy $12.5 billion in 2023-24.

Not every insider incident is malicious. In the Office of the Australian Information Commissioner’s January to June 2025 statistics, human error caused 37 per cent of notifiable data breaches. The 2026 Cost of Insider Risks Global Report from the Ponemon Institute, sponsored by DTEX, put the average annual cost of insider incidents at US$19.5 million per organisation, with negligent or careless insiders accounting for more than half of that figure.

Regulation now expects a structured response. PSPF Release 2026 requires an insider threat program for entities that manage security cleared staff, active assessment of ongoing suitability and a managed separation process, and a policy that stops personnel publicising clearance details online. The SOCI Act CIRMP Rules require critical infrastructure owners to identify critical workers and minimise risks from malicious or negligent employees and contractors, and the enhanced CIRMP Rules, which commenced on 10/06/2026 for nine asset classes, phase in suitability checks and periodic re-checks for critical workers from 2027 and 2028.

What the course covers

  1. Defining the insider threat Malicious, negligent and compromised insiders, and the harm each can cause.
  2. The current threat environment Espionage, foreign interference, online approaches, social engineering and criminal recruitment of staff.
  3. Recognising concerning behaviour Behavioural and workplace indicators, and how to separate genuine concern from normal workplace issues.
  4. Personnel security across the employment lifecycle Pre-employment screening, ongoing suitability, changes in circumstances and managed separation.
  5. Access and privileged access Limiting and monitoring access to critical information, systems and sites.
  6. Reporting and responding Building a reporting culture, handling reports fairly, protecting privacy and knowing when to escalate.
  7. Building a counter insider threat program Governance, the roles of human resources, security, IT and managers, and alignment with the PSPF and CIRMP Rules.
  8. Scenario workshop Working through realistic insider scenarios drawn from your own operating environment.

What participants will be able to do

  • Define insider threat and explain how malicious, negligent and compromised insiders differ.
  • Recognise behavioural indicators and respond early, fairly and in line with policy.
  • Apply personnel security controls from recruitment through to separation.
  • Explain PSPF Release 2026 and SOCI Act CIRMP expectations for personnel security.
  • Contribute to a counter insider threat program suited to the organisation.

Who should attend

  • Executives and senior managers
  • Security managers and advisers
  • Human resources and people and culture teams
  • Managers and supervisors of critical or privileged roles
  • CIRMP and PSPF personnel security owners

Choose the level and format that suits you

The course can be run at more than one level, so governance and day-to-day practice are covered together.

  • Executive briefing. A short session for executives and boards on accountability, obligations, risk appetite and what good looks like.
  • Manager and practitioner workshop. The full course, with case studies and practical exercises for the people who manage the risk day to day.
  • Train-the-trainer. Preparing your own trainers to deliver the course inside your organisation, with the materials and guidance to do it well.
  • In person or online. Delivered at your premises, at a venue you choose, or live online through Microsoft Teams and other platforms.

Bringing the capability in-house, with Agilient as your partner

More organisations want to build and keep this capability within their own teams. Agilient supports that. After delivering the course, Agilient can train your trainers, help your learning and development team plan the conversion of the course into an online module, and stay involved as an adviser, so your people deliver it with the benefit of Agilient’s hands-on experience.

How it works

  1. Get in touch. Tell us which course you are interested in, roughly how many people, where and when.
  2. Scoping conversation. An Agilient consultant discusses your people, sites, policies and recent incidents, and agrees the level, format and duration with you.
  3. Tailored content. Case studies, scenarios and exercises are built around your own environment and procedures.
  4. Delivery and handover. The course is delivered in person or online. Agilient can then train your trainers, support an online version, or review related procedures, controls or risk assessments.

Related Agilient services and resources

Frequently asked questions

What is an insider threat?

An insider threat is the risk that a current or former employee, contractor or other trusted person uses their access to harm the organisation, whether deliberately, carelessly or because someone else has exploited them. Harm can include theft, fraud, sabotage, espionage, data breaches and violence.

Who should attend insider threat training?

Managers and supervisors, human resources and security staff, and anyone who manages people in critical or privileged roles. These are the people best placed to notice concerning behaviour and act on it early.

Does the course help with PSPF and SOCI Act obligations?

Yes. The course explains the PSPF Release 2026 personnel security and insider threat requirements and the SOCI Act CIRMP personnel hazard rules, including the enhanced rules that commenced on 10/06/2026, and shows how training fits into a wider counter insider threat program.

Can the training be extended to the wider workforce?

Yes. Agilient typically starts with facilitated sessions for managers and can then adapt the content for the wider workforce, including for the organisation’s own online learning system.

How long is the course?

Duration is agreed with you. Courses range from a two-hour briefing to a one, one and a half or two-day program, depending on your audience, risks and how much practical work you want included.

Can the course be delivered online?

Yes. Agilient delivers courses in person at your premises and live online through Microsoft Teams and other platforms, and can combine the two for teams spread across several locations.

Can our own team deliver this training in future?

Yes. Agilient runs train-the-trainer sessions so your people can deliver the course themselves, and can work with your learning and development team on a strategy for converting the course into an online module for induction and refreshers.

Can individuals book a place on this course?

No. Agilient runs its training in-house for organisations rather than as public courses, so individual places are not available. Group size, timing and content are agreed with each organisation.

Is this an accredited course?

No, and that is deliberate. It is not a nationally recognised qualification that follows a fixed syllabus, which can date quickly. It is designed and delivered by practitioners who have dealt with these issues first hand, tailored to your organisation, and built on case studies, active learning and practical exercises.

Ready to build this capability in your organisation?

Tell us what you need. Agilient will recommend the right level, format and duration, and tailor the course to your organisation.

Other in-house security training courses

Sources

Last updated 29/09/2026.