A new Mimecast study has found that malicious insider incidents are now rising at the same rate as negligence-based incidents, with 42% of organizations reporting an increase in each over the past year. It is the first time the two figures have been level, marking a significant shift in how enterprise security threats are evolving.
“The data shows both careless mistakes and deliberate actions driving incidents in equal measure,”
said Mimecast CISO Leslie Nielsen.
The findings are alarming not only because insider threats are inherently more dangerous than incidents of negligence, but also because they come at a time when the broader threat landscape is intensifying. AI-powered attacks, expanding collaboration surfaces, and fragmented security controls are all adding pressure.
By the Numbers: What the Data Actually Shows
The headline figure is striking enough, but the details behind it make for even more sobering reading. The share of organizations reporting an increase in malicious insider concerns has jumped nearly ten percentage points in just two years, rising from 33% in 2024 to 42% in 2026.
Organizations experiencing insider-driven incidents report an average of six such events per month, at an estimated cost of $13.1 million per incident. This increase adds substantial cost to their security posture. With 66% of respondents expecting insider-related data loss to rise over the next 12 months, the numbers are only expected to worsen.
The report also highlights how AI is accelerating the problem. Attackers are using AI to recruit insiders, automate reconnaissance, and craft highly convincing social engineering campaigns that can turn an otherwise loyal employee into an unwitting or willing threat actor. Sixty-nine percent of security leaders say AI-powered attacks against their organization are inevitable within the next 12 months, yet 60% admit they are not fully prepared.
Compounding this is a visibility problem. Ninety-one percent of organizations face challenges maintaining governance and compliance over communications data, while 59% lack confidence in their ability to quickly locate data when faced with a regulatory or legal request. This lack of governance not only exposes them to potential fines but also limits their ability to detect, investigate, and respond to insider incidents effectively.
Why Insider Threats Hit Differently
Understanding the scale of the problem is one thing. Understanding why it is so damaging is another.
Unlike external attackers who must first breach a perimeter, malicious insiders already have what every attacker wants: authorized access. They know the systems, where sensitive data resides, and how to move through an organization without triggering immediate suspicion. That authorized access makes them extremely difficult to detect and costly to remediate.




