In this Three Perspectives: Governance at Every Level series, we explore how one governance topic affects each level of an organization—and why all three perspectives are essential for long-term success.
Perspective 2 – The Manager or Supervisor
“My Job Is to Protect My Team While Protecting the Business.”
Mike starts every morning by checking on his team. He isn’t just thinking about today’s customer orders or project deadlines. He’s making sure everyone has what they need to succeed.
Has the new employee completed onboarding?
Does everyone have access to the systems they need?
Has anyone taken on responsibilities that require additional permissions?
Has anyone left the company whose accounts still need to be disabled?
Most managers don’t think of these questions as “insider threat management.” They simply think of them as good management.
But these everyday decisions form one of the strongest defenses a business has against insider threats.
Unlike front-line employees, managers have a broader responsibility. They don’t just follow procedures—they ensure procedures are being followed consistently across the team. They help create an environment where employees feel comfortable asking questions, admitting mistakes, and reporting concerns before they become serious incidents.
Consider a common situation. One of Mike’s employees transfers from Marketing to Accounting. She’s no longer responsible for maintaining the company’s social media accounts, but she now needs access to financial software.
Without governance, her old permissions remain active while new permissions are added. Months later, she unknowingly still has access to customer marketing databases, social media credentials, financial systems, and shared executive folders.
This is called privilege creep, and it is one of the most common insider risks in growing organizations. A good manager catches this before it becomes a problem.
They review access permissions, confirm they still match current job responsibilities, and remove unnecessary access. Employees aren’t offended—in fact, most appreciate knowing the business takes security seriously and protects everyone equally.
Managers also become skilled observers. They notice changes that technology may never detect. Perhaps an employee who normally collaborates with everyone suddenly becomes withdrawn. Another begins downloading unusually large numbers of files after business hours. A contractor repeatedly requests access to systems outside the agreed scope of work.
None of these observations automatically indicate malicious intent. But together, they may justify a conversation, an access review, or additional oversight.
Good governance teaches managers to recognize these situations early—not to accuse employees, but to ask questions and understand whether additional support or investigation is needed.
Managers also play a crucial role in reinforcing the organization’s culture. Policies don’t build trust. People do.
When managers consistently explain why security procedures exist, treat employees fairly, follow the same rules themselves, and encourage open communication, employees are far more likely to report mistakes or suspicious behavior before significant damage occurs.
Perhaps the most important responsibility of a manager is balancing productivity with protection. Employees need enough system access to perform their jobs efficiently.
They should never have so much access that a simple mistake—or intentional misuse—could unnecessarily expose the business. Finding that balance is where good governance truly becomes good leadership.
Controls That Matter Most for Managers and Supervisors
Managers and supervisors play the central operational role in insider threat governance. Their most important controls include:
- Performing periodic insider threat assessments to identify changing risks, review previous incidents, evaluate contractors and vendors, and monitor potential vulnerabilities before problems occur.
- Implementing and maintaining Role-Based Access Control (RBAC) so employees receive access appropriate to their responsibilities—and nothing more.
- Applying the Principle of Least Privilege, ensuring employees receive only the minimum permissions necessary to perform their work effectively.
- Conducting regular access reviews to eliminate privilege creep and confirm that system permissions remain aligned with current job responsibilities.
- Enforcing Segregation of Duties (SOD) by preventing one individual from controlling an entire sensitive process and requiring independent oversight or dual approvals where appropriate.
- Coordinating background checks for sensitive positions and ensuring hiring decisions consider security responsibilities where legally appropriate.
- Ensuring prompt employee offboarding, including immediate removal of system access, collection of company devices, and documentation of completed access revocation.
- Consistently applying disciplinary procedures when policy violations occur, while ensuring investigations are fair, documented, and proportional to the circumstances.
- Encouraging employees to use confidential reporting channels and demonstrating through their own actions that concerns raised in good faith are taken seriously and handled professionally.
Closing Transition
Managers turn governance into everyday practice, but they cannot build an effective insider threat program on their own.
Someone must establish the organization’s ethical culture, allocate resources, approve security policies, determine acceptable risk, and ensure that governance becomes part of the company’s long-term strategy—not simply another compliance exercise.
In the final perspective, we’ll step into the role of the business owner or executive to see how leadership creates the culture, direction, and accountability that enable managers and employees to succeed together.
