Skip to content
MarketScale
‹ Back to IndustriesBusiness Services

Deterring Insider Threats Takes More Than Technology. It Demands Proper Processes and Culture.

Advanced security tools prove ineffective without the organizational foundation of trained teams, clear protocols, and genuine workplace trust

This story was produced through MarketScale. See how Business Services teams put it to work with Executive Thought Leadership.

By John Petrozzelli · CybersecurityGlobal Security ExchangeGsx 2023Insider Threats
Share

Key takeaways

01

Advanced security tools prove ineffective without the organizational foundation of trained teams, clear protocols, and genuine workplace trust

Get featured

Want to get featured in MarketScale Business Services?

Create a free MarketScale workspace and get your company's expertise featured across our Business Services coverage. No credit card, no demo required.

Start free

There are many sophisticated technology packages and solutions available to help bolster insider threat programs. Still, without the proper training, processes, and a culture of trust built into the system, technology alone won't stop the threats.

Without the proper training, processes, and a culture of trust built into the system, technology alone won't stop the threats.

At the recent Global Security Exchange GSX 2023, a pivotal session titled "Subduing Insider Threats: Transferring Knowledge to CISOs Using Past Successes and Lessons Learned" occurred. The session, led by John Petrozzelli, Director of the MassCyberCenter, broke down the challenges posed by insidious employees with legitimate access. Highlighting that such insiders could be driven by various motivations, from personal gain to allegiance to another country, Petrozzelli emphasized the importance of robust insider threat programs. The session also underscored the value of an acceptable use policy as a potent tool to deter and disrupt such insider threats. With a focus on compliance, operations, and hiring strategies, this session offered invaluable insights into safeguarding organizations from internal vulnerabilities.

Petrozzelli expanded on the lessons, learning, and insights he brought during his session.

John's Thoughts

"It's really a combination of approaches. People, processes, and technology gotta have the people educated and trained; you gotta have the processes in place in policy, like acceptable use policies or mobile device policies. And then you have to have the technology monitor.

We're a quasi-public organization, a dot org versus dot gov. What we do is work on cybersecurity resiliency for the ecosystem in Massachusetts, with a priority on workforce development, specifically resilience on municipalities as well.

What I wanted people to do was to come into the class and learn from some of my successes and mistakes in the past. So, I talked in-depth about some situations where I've dealt with insider threats. The key takeaways would be that they should have some idea of what they would want to do in their receptible use policy so they could deter insider threats and that they should always maintain a relationship with people when they don't need anything with them to set, basically, with trust with people who are going to be people that they'd work with so that they can establish that trust before they need to work with them to mitigate inside reps.

Building Trust in a Hybrid Work Environment

There are two things I'd say; one is this hybrid or commuting environment post-COVID is probably here to stay. How does that change the conflict? Part of my issue was explaining to people that the issues are much more difficult now because you can't establish trust as easily when you're not in person.

Right? So you can't go in and say hi to someone in the office without needing anything. For them because now you've gotta do it via Zoom or Teams. So what I had recommended to them was get on a call early.

So, when you have a two o'clock meeting, get on at one fifty-five. Then, use that five minutes to BS with people to establish trust and rapport. So that's one way that, you know, the evolving cyber security, hybrid, or just even remote work experience changes the insider threat program to make it more difficult. The other side of it is, you know, the negligence of people contributing to insider threats has grown as well.

The issues are much more difficult now because you can't establish trust as easily when you're not in person.

And that's become more of a user negligence where they're not trying to hurt the company, but they're doing so with their inactivity or their lack of negligence, essentially their lack of awareness to what they're doing. That's a security threat.

Addressing the Human Element in Insider Threats

Part one of that is a human issue. It's a huge human element. From that human side of things, you've gotta deal with that's why I talked about in my class, like identifying partners that you wanna work with stakeholders that you have the shared mission with, like HR, like, like security, like, compliance and legal, and then working with them. And then, on the technical side, you know, use the resources available to you.

And that could be a software component. There's some really good insider threat software tools out there that will allow you to do some of the work; it goes back to the human side because through human interaction and teaching your employees about reporting something that they see as suspicious, that's really how gonna identify insiders. You might get lucky and catch them in log activity or exfiltrations with some log activity, but really trying to get humans to identify and then, or report them to somebody, even if it's just one incident, is really how we're gonna help to stem the tide of that.

Utilizing Advanced Tools While Maintaining Company Culture

I had mentioned using all the resources available to you, and that's really like the tools. Some really good insider threat tools out there can do screen capturing, live recording, and monitoring. It goes to your initial part of this with respect to company culture. People might not wanna work for a company that has those things running.

The other thing is unless a company has the prospect of them serving employees in some kind of acceptable use policy or something, it might not work legally for them to be able to do that. It's really a combination of approaches—people, processes, and technology. You have to have the people educated and trained.

You gotta have the processes in place, like acceptable use policies or mobile device policies, and then you have to have the technology to monitor it."

Video TranscriptExpand ↓

It's really a a combination of approaches. People, processes and technology, gotta have the people, educated and trained, you gotta have the processes in place in in policy, like acceptable use policies or mobile device policies. And then you have to have the technology monitor. So we're a a quasi public organization, we're a dot org versus dot gov. What we do is work on cybersecurity resiliency for the ecosystem in Massachusetts, with a priority on workforce development, specifically resilience on personalities as well. What I wanted people to do is to come into the class, learn from some of my successes and mistakes in the past. So I talked in-depth about some of the situation where I've dealt with insider threats. The key takeaways would be, like, that they should have some idea of what they would wanna do in their receptible use policy so that they could kind of deter insider threats that they should always maintain a a relationship with people when they don't need anything with them to set, basically, with trust with people who are gonna be people that they'd work with so that they can establish that trust before they need to work with them to mitigate inside reps. Two things I'd say. One is this, hybrid or commuting environment post COVID, it's probably here to stay. How does that change the conflict? Part of the issue that I had was explaining to people that the issues are much more difficult now because you can't establish trust as easily when you're not in person. Right? So you can't go in and say hi to someone in the office without needing anything. For them because now you've gotta do it via Zoom or teams. So what I had recommended to them was get on a call early. So, like, when you have a two o'clock meeting, get on at one fifty five. And then use that five minutes to b s with people and establish your trust and report that way. So that's one way that, you know, the olving cyber security, hybrid, or just even remote work experience changes the insider threat program to make it more difficult. The other side of it is, you know, the negligence of people contributing to insider threats has grown as well. And that's become more of a user negligence where they're not trying to hurt the company, but they're doing so with their inactivity or their lack of their negligence, essentially their their lack of awareness to what they're doing. That's security threat. Part, one of that, I guess, would be is a human issue. It's a h a huge human element. From that human side of things, you've gotta deal with that's why I talked about in my class, like identifying partners that you wanna work with stakeholders that you have the shared mission with, like HR, like, like security, like, compliance and legal, and then working with them. And then on technical side, you know, use the resources available to you. And that could be a software component. There's some really good insider threat software tools out there that will allow you to do some of the work, it goes back to the human side because through human interaction and teaching your employees about reporting something that they see as suspicious, that's really how gonna identify insiders. You might get lucky and catch them in log activity or exfiltrations with some log activity, but but really trying to get humans to, identify and then, or report them to somebody, even if it's just one incident is is really how we're gonna help to stem the tide of that. I had mentioned, like, using all the resources available to you, and that's really like the tools. There are some really good insider threat tools out there that can do screen capturing, live recording, monitoring. It goes to your initial part of this with respect to company culture. People might not wanna work for a company that has those things running. The other thing is unless a company has the prospect of them serving employees in some kind of acceptable use policy or something, it it might not work legally for them to be able to do that. It's really a combination of approaches. People processes and technology. You gotta have the people educated and trained. You gotta have the processes in place in in see, like acceptable use policies or mobile device policies and then you have to have the technology to monitor it.

Your experts belong here

Every story in MarketScale Business Services starts with a company putting its consultants, practice leads, and account teams on the record. Buyers are already reading this topic. The only question is whose experts they find.

Clients hire the firm whose thinking they have already read, which means fewer cold conversations for your partners.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

John Petrozzelli
John PetrozzelliDirector, MassCyberCenter

John Petrozzelli is the Director of MassCyberCenter, a Cybersecurity Incident Responder, and an Insider Threat Instructor. Formerly, he directed cybersecurity operations for Magna5’s Boston Region and held senior leadership roles at the FBI, including as a Chief Security Officer overseeing security risk management impacting national security. Petrozzelli is a seasoned communicator, combining his decades of experience with his master's in information security to translate threat awareness to stakeholders. With extensive experience in crisis management, zero-trust models, and computer forensics, he has been a featured speaker at prestigious cybersecurity conferences worldwide. Petrozzelli's expertise spans cybersecurity advisory, crisis management, and insider threat training, with a track record of successfully implementing enterprise-wide security initiatives across various industries.

B2B Weekly

The week in Business Services, and sixteen other industries, every Monday.

Ten stories, one-line takes, five minutes. Free.

Business Services: are you visible to AI?

Before they reach out, Business Services buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Business Services expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your consultants, practice leads, and account teams into the articles, video, and social content Business Services buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Business Services Insights

The Early Scale: Nvidia Forecasts Doubling Chip Sales Next Year; Supply Constraints Loom: Bloomberg

The Early Scale: Nvidia Forecasts Doubling Chip Sales Next Year; Supply Constraints Loom: Bloomberg

Nvidia forecasts that chip sales will double next year, while supply constraints remain a consideration. Today’s briefing also covers fintech interest in embedded payments and school-account policy questions raised by expanded Gemini access.

  • 01Nvidia forecasts doubling chip sales next year, and supply chain constraints could affect its ability to meet demand.
  • 02Embedded payments are an increasing focus in fintech M&A, according to a PYMNTS report
  • 03Schools are reassessing account controls, privacy and classroom AI guidance after expanded student access to Google’s Gemini

Sep 21, 2026

Embedded Payments Drive Fintech M&A Focus, Says PYMNTS

Embedded Payments Drive Fintech M&A Focus, Says PYMNTS

The integration of embedded technology within various industries is accelerating, as businesses realize the value of having payments and other processes 'baked in' to their existing systems. This trend is not just a tech fad but represents a shift towards creating seamless customer experiences across sectors. Businesses that adapt quickly by leveraging embedded solutions stand to gain a competitive advantage.

  • 01Embedded payments allow transactions within applications without requiring users to leave the platform, enhancing customer experience across e-commerce, property management, and finance sectors.
  • 02Timing media negotiations around major global events could potentially maximize future contract value, as Serie A’s one-year CBS extension suggests.
  • 03Schools are scrambling to adapt to Google’s Gemini rollout, and education service providers should prepare for rising demand for AI infrastructure support and training.

Sep 20, 2026

The Early Scale: Schools scramble as Google unleashes Gemini chatbot on students

The Early Scale: Schools scramble as Google unleashes Gemini chatbot on students

In the rapidly shifting landscape of B2B technology and operations, innovation often requires careful balancing between new trends and existing infrastructure. As businesses embrace cutting-edge solutions such as AI integration and robotics, they face challenges in maintaining seamless operations and maximizing efficiency. Simultaneously, data-driven strategies are reshaping industries, offering new avenues for growth and value creation. In this environment, understanding the potential of new technologies and adapting operations accordingly is not just beneficial, it’s essential.

  • 01Holiday e-commerce sales forecast to grow 7.5–8.4% to as much as $319B in the 2026–2027 season, outpacing overall retail growth of 4–4.8%
  • 02PMMI says the lifetime cost of packaging robots can be lower than manual labor, reshaping manufacturers’ automation ROI calculations
  • 03Educational institutions must adapt curricula and policies as Google's Gemini chatbot becomes available to students

Sep 19, 2026

Explore More Business Services Insights

Read more expert perspectives from across Business Services.

Browse Business Services Hub

About the Expert

John Petrozzelli
John Petrozzelli

Director, MassCyberCenter

John Petrozzelli is the Director of MassCyberCenter, a Cybersecurity Incident Responder, and an Insider Threat Instructor. Formerly, he directed cybersecurity operations for Magna5’s Boston Region and held senior leadership roles at the FBI, including as a Chief Security Officer overseeing security risk management impacting national security. Petrozzelli is a seasoned communicator, combining his decades of experience with his master's in information security to translate threat awareness to stakeholders. With extensive experience in crisis management, zero-trust models, and computer forensics, he has been a featured speaker at prestigious cybersecurity conferences worldwide. Petrozzelli's expertise spans cybersecurity advisory, crisis management, and insider threat training, with a track record of successfully implementing enterprise-wide security initiatives across various industries.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Business Services and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512