Insider threats persist in finance organizations

Insider threats pose a significant and ongoing risk to finance organizations, with the potential for increased severity due to advancements in technology, particularly artificial intelligence. As these companies are bound by regulations demanding long data retention periods, they often find themselves managing vast amounts of unstructured and outdated data. This scenario creates challenges that can be exploited by employees who may inadvertently expose sensitive information due to poor cyber hygiene practices. In this text, we will examine the persistent issue of insider threats within financial institutions and discuss proactive measures organizations can implement to enhance their cybersecurity posture.
The Vulnerability of Finance Organizations
Finance organizations are particularly vulnerable to insider threats for several reasons. One primary factor is the legal requirement to retain data for extended periods, typically ranging from 10 to 15 years. During this time, companies can lose track of significant amounts of unstructured data that may contain sensitive information. Thales’ “Data Threat Report” highlights human error as a major concern, ranking third among threat actors following hacktivists and nation-state actors in 2025. This reality creates opportunities for employees with inadequate cyber hygiene practices to unintentionally compromise an organization’s data security.
Todd Moore, a global vice president of data security at Thales, explains that many employees focus solely on their tasks without considering the cybersecurity implications: “As an employee trying to do my job, I might share information with colleagues through cloud storage or email attachments without realizing the risks involved.” This negligence underscores the necessity for robust monitoring and management strategies within finance organizations.
The Impact of Cloud Storage
Thales identified cloud storage platforms and Software as a Service (SaaS) applications as prime targets following insider exploitation incidents. Adversaries seek access to valuable organizational data stored across various private clouds or on-premises systems. To mitigate these risks effectively, finance organizations must prioritize identifying critical data assets and securing them using tokenization and encryption technologies alongside continuous monitoring tools.
Moore emphasizes that visibility into what data is being accessed is crucial: “You need visibility before you can start really protecting your data.” With artificial intelligence amplifying attack vectors—such as exploiting weak passwords—having transparent oversight becomes even more essential.
The Threat of Agentic AI
The emergence of agentic AI introduces new dimensions of risk for finance organizations. These AI systems can adopt user profiles and access permissions while executing tasks on behalf of individuals. If a malicious actor compromises one such AI agent, they could rapidly locate sensitive financial information hidden within unstructured datasets.
Moore warns that “agentic AI will expose vulnerabilities faster than ever,” highlighting the urgent need for continuous monitoring mechanisms capable of tracking which datasets these agents access and why such access occurs.
Enhancing Cyber Hygiene Practices
While quantifying insider threats in finance remains challenging, it is clear they exist with increasing frequency. Organizations must prioritize educating employees about strong password creation techniques and implementing multifactor authentication wherever possible. Moore stresses the importance of training staff adequately: “We have to train everyone up so we don’t get exploited even faster whenever AI is available.”
A proactive approach includes ensuring timely deletion of unnecessary data once its retention period has expired. Moore asserts: “If my data is in the bank, I’d want it deleted after holding time ends so it cannot be affected by future breaches.” Managing the entire lifecycle of sensitive information has become indispensable in guarding against insider threats.
Conclusion
The threat landscape posed by insiders within finance organizations will not dissipate anytime soon; instead, technological advancements like agentic AI may exacerbate these risks further. By adopting strong security measures—including continuous monitoring tools—and fostering a culture focused on cyber hygiene among employees, financial institutions can better defend against potential breaches caused by both malice and negligence alike.
For effective protection against insider threats, it’s essential that finance organizations take strategic steps now—investing in education around cybersecurity best practices while enhancing their overall infrastructure—to safeguard valuable assets into the future.