Framework // Insider Threat Program Maturity
Insider Threat Capability Maturity Model
A five-domain assessment that scores your organization's ability to detect, investigate, and neutralize insider threats — grounded in NITTF guidance, ICD 732, and NIST 800-53 personnel security controls. The output is a scored gap analysis and a 90-day remediation roadmap your CISO can present to the board.
Insider Threats Already Have Credentials
Perimeter defenses assume the adversary is outside. Insider threats — employees, contractors, partners with legitimate access — bypass every firewall, every endpoint agent, and every SOC alert that was designed to catch external intrusion. They access the same VPNs, databases, and Slack channels your analysts use.
The Carnegie Mellon CERT Division has cataloged insider threat incidents across defense, finance, healthcare, and critical infrastructure for over two decades. The consistent finding: organizations that lack a structured insider threat program detect incidents an average of 197 days later than organizations that maintain one. By that point, the damage — IP theft, sabotage, espionage, data destruction — is operational fact, not theoretical risk.
Compliance-driven checkbox programs do not close this gap. A policy binder gathering dust in the CISO's office does not detect a disgruntled engineer exfiltrating source code to a personal cloud account at 2 AM. The Insider Threat CMM was built to measure whether your program actually works under operational pressure — not whether it exists on paper.
Field Observation
"In 23 years of intelligence work across government and Fortune 500 environments, the most damaging breaches I've investigated were not external intrusions. They were trusted employees acting within their authorized access. The attacker didn't break in — they were already inside."
— Jeff Bardin, Chief Intelligence Officer, Treadstone 71
Five Domains of Insider Threat Maturity
Each domain is scored independently against a five-level maturity scale. The composite score reveals where your program is strong and where operational gaps persist.
Detection & Reporting
Technical and behavioral indicators, reporting channels, anonymous tip infrastructure, and cross-system correlation capabilities. Measures whether anomalies are caught — and whether anyone acts on them.
Behavioral Analysis
Integration of psychological and behavioral science into threat assessment. Evaluates whether human factors — financial stress, disgruntlement, ideological shift, foreign contact — are monitored through structured analytic methods, not ad hoc suspicion.
Data Access & Monitoring
Privileged access governance, DLP effectiveness under operational conditions, cloud storage controls, removable media policy enforcement, and network telemetry analysis. Tests whether controls actually prevent exfiltration — not just log it after the fact.
Program Governance
Leadership sponsorship, legal and privacy framework, HR-security integration, budget allocation, and executive reporting cadence. A program without governance is a pilot project waiting to be defunded.
Cross-Functional Coordination
Information sharing between security, HR, legal, IT, counterintelligence, and external partners. Evaluates whether organizational silos block the very information flow the program depends on.
Five Levels — From Reactive to Optimized
What the Assessment Actually Tests
A compliance audit confirms controls exist on paper. The CMM tests whether they work under operational conditions.
| Capability | Standard Compliance Audit | Treadstone 71 Insider Threat CMM |
|---|---|---|
| Policy existence check | ✓ | ✓ |
| Policy effectiveness under pressure | — | ✓ |
| Behavioral indicator integration | — | ✓ |
| Adversarial tabletop exercises | — | ✓ |
| Deception environment testing | — | ✓ |
| Cross-functional coordination scoring | — | ✓ |
| 90-day remediation roadmap | — | ✓ |
| Board-ready executive summary | — | ✓ |
Grounded in National Security Standards
What Your Organization Receives
Domain-by-Domain Scored Report
Each of the five domains scored against the maturity scale with specific findings, evidence, and severity ratings. No boilerplate — every finding is tied to your organizational context.
Gap Prioritization Matrix
Ranked list of deficiencies sorted by risk impact and remediation effort. Distinguishes quick wins from structural changes that require budget and leadership sponsorship.
90-Day Remediation Roadmap
Phased action plan with assigned ownership, milestones, and resource requirements. Designed to be presented directly to agency heads, boards, or executive committees without further translation.
Executive Summary
Two-page board-ready brief summarizing maturity posture, highest-risk gaps, and recommended investment priorities. Written for non-technical decision-makers.
How the Assessment Works
Standard engagement: 10–15 business days. All interviews and reviews can be conducted remotely or on-site.
Scoping & Document Review
NDA execution. Collection of existing policies, procedures, org charts, and prior audit reports. Initial stakeholder identification.
Interviews & Technical Review
Structured interviews with security, HR, legal, IT, and counterintelligence stakeholders. Technical controls validation. DLP and access governance testing.
Tabletop & Deception Testing
Adversarial tabletop exercise simulating insider threat scenarios. Deception environment assessment. Behavioral indicator validation.
Report & Roadmap Delivery
Scored report, gap matrix, 90-day roadmap, and executive summary delivered. Briefing to leadership. Optional: program build engagement begins.
Frequently Asked Questions
What does the Insider Threat CMM assess?
What standards is the Insider Threat CMM grounded in?
Who is the assessment designed for?
How long does the assessment take?
How is this different from a compliance audit?
Can the CMM be combined with other Treadstone 71 services?
Request a Confidential Briefing
Discuss your organization's insider threat posture with a Treadstone 71 intelligence professional. All initial consultations are conducted under NDA.
Office: 424.234.3629