Skip to content

Malicious Insider Threat

Risk Overview

Malicious insider threats are presented in trusted employees, contractors, or vendors with knowledge and access to systems and the capability of bypassing security controls to cause harm to the bulk power system. A malicious insider could be manipulated by a threat actor external to an organization or may act on their own. The malicious insider often has underlying motivating factors such as unmanaged workplace dissatisfaction, ideology, or financial motivation. Impacts can be physical or cyber. This risk does not include unintentional insiders because they lack motivation. The risk caused by the unintentional insider should be considered with other cyber risks, such as Phishing/Ransomware/Malware.

Trends

Recommended Actions

Mitigating Activities

A suite of NERC CIP standards provides limited controls for this risk.

MRO staff and the Security Advisory Council created an Insider Threat Program Checklist to help MRO entities develop or enhance their existing insider threat policies and procedures. Submit a request to receive a copy of

Related Resources

Related Documents

MRO 2024 Regional Risk Assessment

MRO publishes a Regional Risk Assessment (RRA or assessment) each year to identify and prioritize risks to the reliable and secure operations of the regional bulk power system.

RRA Placemat

This two-sided document highlights the key findings and recommendations from MRO’s 2024 Regional Risk Assessment.

Related News

Understanding Insider Threats

Tools and resources for mitigating what has been identified as a high risk MRO’s mission is to identify, prioritize and assure effective and efficient mitigation of risks to the reliability…

Read More

Insider Threats Remain a High Priority

MRO develops new tools and resources to mitigate risk This article is an update to Understanding Insider Threats – Midwest Reliability Organization (mro.net), which was published on May…

Read More

Related Events