Framework // Insider Threat Program Maturity

Insider Threat Capability Maturity Model

A five-domain assessment that scores your organization's ability to detect, investigate, and neutralize insider threats — grounded in NITTF guidance, ICD 732, and NIST 800-53 personnel security controls. The output is a scored gap analysis and a 90-day remediation roadmap your CISO can present to the board.

The Problem

Insider Threats Already Have Credentials

Perimeter defenses assume the adversary is outside. Insider threats — employees, contractors, partners with legitimate access — bypass every firewall, every endpoint agent, and every SOC alert that was designed to catch external intrusion. They access the same VPNs, databases, and Slack channels your analysts use.

The Carnegie Mellon CERT Division has cataloged insider threat incidents across defense, finance, healthcare, and critical infrastructure for over two decades. The consistent finding: organizations that lack a structured insider threat program detect incidents an average of 197 days later than organizations that maintain one. By that point, the damage — IP theft, sabotage, espionage, data destruction — is operational fact, not theoretical risk.

Compliance-driven checkbox programs do not close this gap. A policy binder gathering dust in the CISO's office does not detect a disgruntled engineer exfiltrating source code to a personal cloud account at 2 AM. The Insider Threat CMM was built to measure whether your program actually works under operational pressure — not whether it exists on paper.

Field Observation

"In 23 years of intelligence work across government and Fortune 500 environments, the most damaging breaches I've investigated were not external intrusions. They were trusted employees acting within their authorized access. The attacker didn't break in — they were already inside."

— Jeff Bardin, Chief Intelligence Officer, Treadstone 71

Assessment Framework

Five Domains of Insider Threat Maturity

Each domain is scored independently against a five-level maturity scale. The composite score reveals where your program is strong and where operational gaps persist.

01

Detection & Reporting

Technical and behavioral indicators, reporting channels, anonymous tip infrastructure, and cross-system correlation capabilities. Measures whether anomalies are caught — and whether anyone acts on them.

02

Behavioral Analysis

Integration of psychological and behavioral science into threat assessment. Evaluates whether human factors — financial stress, disgruntlement, ideological shift, foreign contact — are monitored through structured analytic methods, not ad hoc suspicion.

03

Data Access & Monitoring

Privileged access governance, DLP effectiveness under operational conditions, cloud storage controls, removable media policy enforcement, and network telemetry analysis. Tests whether controls actually prevent exfiltration — not just log it after the fact.

04

Program Governance

Leadership sponsorship, legal and privacy framework, HR-security integration, budget allocation, and executive reporting cadence. A program without governance is a pilot project waiting to be defunded.

05

Cross-Functional Coordination

Information sharing between security, HR, legal, IT, counterintelligence, and external partners. Evaluates whether organizational silos block the very information flow the program depends on.

Maturity Scale

Five Levels — From Reactive to Optimized

1 Initial No formal program. Insider events handled ad hoc by IT or HR without coordination.
2 Developing Policy drafted. Basic awareness training deployed. Detection relies on manual review or reactive alerts.
3 Defined Program is documented with assigned ownership. Behavioral indicators are incorporated. Reporting channels exist and are tested.
4 Managed Metrics are tracked. Tabletop exercises validate detection. Cross-functional coordination is operational, not aspirational.
5 Optimizing Continuous improvement driven by intelligence feedback loops. Deception environments actively test and deter. Program adapts to emerging threat vectors in real time.
Methodology

What the Assessment Actually Tests

A compliance audit confirms controls exist on paper. The CMM tests whether they work under operational conditions.

Capability Standard Compliance Audit Treadstone 71 Insider Threat CMM
Policy existence check
Policy effectiveness under pressure
Behavioral indicator integration
Adversarial tabletop exercises
Deception environment testing
Cross-functional coordination scoring
90-day remediation roadmap
Board-ready executive summary
Standards & Alignment

Grounded in National Security Standards

📋
NITTF Guidance National Insider Threat Task Force — minimum standards for federal insider threat programs
📜
Executive Order 13587 Structural reforms for insider threat detection across the federal government
🔐
ICD 732 Intelligence Community Directive on personnel security and insider threat management
NIST SP 800-53 Personnel security controls (PS family) — access agreements, screening, termination
🏛
CERT Insider Threat Center Carnegie Mellon SEI — 20+ years of insider threat indicators and pattern research
🛡
CISA Guidance Cybersecurity and Infrastructure Security Agency insider threat mitigation resources
Deliverables

What Your Organization Receives

Domain-by-Domain Scored Report

Each of the five domains scored against the maturity scale with specific findings, evidence, and severity ratings. No boilerplate — every finding is tied to your organizational context.

Gap Prioritization Matrix

Ranked list of deficiencies sorted by risk impact and remediation effort. Distinguishes quick wins from structural changes that require budget and leadership sponsorship.

90-Day Remediation Roadmap

Phased action plan with assigned ownership, milestones, and resource requirements. Designed to be presented directly to agency heads, boards, or executive committees without further translation.

Executive Summary

Two-page board-ready brief summarizing maturity posture, highest-risk gaps, and recommended investment priorities. Written for non-technical decision-makers.

Engagement

How the Assessment Works

Standard engagement: 10–15 business days. All interviews and reviews can be conducted remotely or on-site.

Week 1

Scoping & Document Review

NDA execution. Collection of existing policies, procedures, org charts, and prior audit reports. Initial stakeholder identification.

Week 2

Interviews & Technical Review

Structured interviews with security, HR, legal, IT, and counterintelligence stakeholders. Technical controls validation. DLP and access governance testing.

Week 3

Tabletop & Deception Testing

Adversarial tabletop exercise simulating insider threat scenarios. Deception environment assessment. Behavioral indicator validation.

Week 4

Report & Roadmap Delivery

Scored report, gap matrix, 90-day roadmap, and executive summary delivered. Briefing to leadership. Optional: program build engagement begins.

Common Questions

Frequently Asked Questions

What does the Insider Threat CMM assess?
The model evaluates five domains: detection and reporting mechanisms, behavioral analysis integration, data access and monitoring controls, program governance and leadership, and cross-functional coordination. Each domain is scored against a five-level maturity scale from Initial through Optimizing.
What standards is the Insider Threat CMM grounded in?
The framework aligns with National Insider Threat Task Force (NITTF) guidance, Executive Order 13587, Intelligence Community Directive 732, NIST SP 800-53 personnel security controls, and the CERT Division's insider threat indicators research at Carnegie Mellon University.
Who is the assessment designed for?
CISOs, insider threat program managers, counterintelligence officers, HR security directors, and compliance leads. The assessment has been deployed in government agencies, defense contractors, financial institutions, energy companies, and critical infrastructure operators.
How long does the assessment take?
A standard engagement runs 10 to 15 business days depending on organizational size. The process includes stakeholder interviews, policy review, technical controls evaluation, tabletop exercises, and delivery of the scored report with the 90-day remediation roadmap.
How is this different from a compliance audit?
A compliance audit confirms whether controls exist on paper. The CMM tests whether those controls actually work under operational conditions. The assessment includes adversarial tabletop exercises, behavioral indicator validation, and deception environment testing — capabilities that a standard compliance audit does not measure.
Can the CMM be combined with other Treadstone 71 services?
Yes. The Insider Threat CMM is frequently paired with the Cyber Intelligence Capability Maturity Model for a comprehensive dual assessment, or with the Intelligence Program Build service to implement remediation recommendations directly. The Fractional Intelligence Officer service can provide ongoing oversight after the initial assessment.
Contact

Request a Confidential Briefing

Discuss your organization's insider threat posture with a Treadstone 71 intelligence professional. All initial consultations are conducted under NDA.

Office: 424.234.3629

Trademarks of Treadstone 71 LLC

Brand
Treadstone 71™
The T71 Standard
The T71 Standard™, The Adversary Index™ (TAI™), Cognitive Warfare Threat Report™ (CWTR™), Public Attribution Series™ (PAS™), Decision Advantage Standard™ (DAS™), Cognitive Warfare Operating System™ (CWOS™), Embedded Cognitive Warfare Officer™ (ECWO™)
Frameworks
STEMPLES Plus™, Cyber Intelligence Capability Maturity Model™ (Cyber Intelligence CMM™), Insider Threat CMM™, Cultural Nexus Framework™, Advanced Analytic Dominance™ (Advanced SATs™)
Decision Engines
ATCRI™, ACS™, CWC™, CWIA™, HTIM™, CARM™
Methods
Integrated Behavioral Threat Analysis™ (IBTA™), The Convergence™, Project Omega™, Decoy's Dilemma™, Pitch Black Tetrad™
Notice on Proprietary Methods and AI Restrictions · Copyright, trade secret, and trademark laws protect all Treadstone 71 LLC frameworks, engines, and analytic tools. We strictly prohibit external entities from ingesting our materials into artificial intelligence systems, large language models, or automated pipelines without a prior written license. Unlicensed scraping, embedding, vector indexing, or generating derivative products constitutes severe intellectual property infringement. Such actions explicitly violate global copyright structures, including the EU Directive 2019/790, Article 4 TDM-Reservation.