Skip to content
MarketScale
‹ Back to IndustriesBusiness Services

Deterring Insider Threats Takes More Than Technology. It Demands Proper Processes and Culture.

Advanced security tools prove ineffective without the organizational foundation of trained teams, clear protocols, and genuine workplace trust

This story was produced through MarketScale. See how Business Services teams put it to work with Executive Thought Leadership.

By John Petrozzelli · CybersecurityGlobal Security ExchangeGsx 2023Insider Threats
Share

Key takeaways

01

Advanced security tools prove ineffective without the organizational foundation of trained teams, clear protocols, and genuine workplace trust

Get featured

Want to get featured in MarketScale Business Services?

Create a free MarketScale workspace and get your company's expertise featured across our Business Services coverage. No credit card, no demo required.

Request an invite

There are many sophisticated technology packages and solutions available to help bolster insider threat programs. Still, without the proper training, processes, and a culture of trust built into the system, technology alone won't stop the threats.

Without the proper training, processes, and a culture of trust built into the system, technology alone won't stop the threats.

At the recent Global Security Exchange GSX 2023, a pivotal session titled "Subduing Insider Threats: Transferring Knowledge to CISOs Using Past Successes and Lessons Learned" occurred. The session, led by John Petrozzelli, Director of the MassCyberCenter, broke down the challenges posed by insidious employees with legitimate access. Highlighting that such insiders could be driven by various motivations, from personal gain to allegiance to another country, Petrozzelli emphasized the importance of robust insider threat programs. The session also underscored the value of an acceptable use policy as a potent tool to deter and disrupt such insider threats. With a focus on compliance, operations, and hiring strategies, this session offered invaluable insights into safeguarding organizations from internal vulnerabilities.

Petrozzelli expanded on the lessons, learning, and insights he brought during his session.

John's Thoughts

"It's really a combination of approaches. People, processes, and technology gotta have the people educated and trained; you gotta have the processes in place in policy, like acceptable use policies or mobile device policies. And then you have to have the technology monitor.

We're a quasi-public organization, a dot org versus dot gov. What we do is work on cybersecurity resiliency for the ecosystem in Massachusetts, with a priority on workforce development, specifically resilience on municipalities as well.

What I wanted people to do was to come into the class and learn from some of my successes and mistakes in the past. So, I talked in-depth about some situations where I've dealt with insider threats. The key takeaways would be that they should have some idea of what they would want to do in their receptible use policy so they could deter insider threats and that they should always maintain a relationship with people when they don't need anything with them to set, basically, with trust with people who are going to be people that they'd work with so that they can establish that trust before they need to work with them to mitigate inside reps.

Building Trust in a Hybrid Work Environment

There are two things I'd say; one is this hybrid or commuting environment post-COVID is probably here to stay. How does that change the conflict? Part of my issue was explaining to people that the issues are much more difficult now because you can't establish trust as easily when you're not in person.

Right? So you can't go in and say hi to someone in the office without needing anything. For them because now you've gotta do it via Zoom or Teams. So what I had recommended to them was get on a call early.

So, when you have a two o'clock meeting, get on at one fifty-five. Then, use that five minutes to BS with people to establish trust and rapport. So that's one way that, you know, the evolving cyber security, hybrid, or just even remote work experience changes the insider threat program to make it more difficult. The other side of it is, you know, the negligence of people contributing to insider threats has grown as well.

The issues are much more difficult now because you can't establish trust as easily when you're not in person.

And that's become more of a user negligence where they're not trying to hurt the company, but they're doing so with their inactivity or their lack of negligence, essentially their lack of awareness to what they're doing. That's a security threat.

Addressing the Human Element in Insider Threats

Part one of that is a human issue. It's a huge human element. From that human side of things, you've gotta deal with that's why I talked about in my class, like identifying partners that you wanna work with stakeholders that you have the shared mission with, like HR, like, like security, like, compliance and legal, and then working with them. And then, on the technical side, you know, use the resources available to you.

And that could be a software component. There's some really good insider threat software tools out there that will allow you to do some of the work; it goes back to the human side because through human interaction and teaching your employees about reporting something that they see as suspicious, that's really how gonna identify insiders. You might get lucky and catch them in log activity or exfiltrations with some log activity, but really trying to get humans to identify and then, or report them to somebody, even if it's just one incident, is really how we're gonna help to stem the tide of that.

Utilizing Advanced Tools While Maintaining Company Culture

I had mentioned using all the resources available to you, and that's really like the tools. Some really good insider threat tools out there can do screen capturing, live recording, and monitoring. It goes to your initial part of this with respect to company culture. People might not wanna work for a company that has those things running.

The other thing is unless a company has the prospect of them serving employees in some kind of acceptable use policy or something, it might not work legally for them to be able to do that. It's really a combination of approaches—people, processes, and technology. You have to have the people educated and trained.

You gotta have the processes in place, like acceptable use policies or mobile device policies, and then you have to have the technology to monitor it."

Video TranscriptExpand ↓

It's really a a combination of approaches. People, processes and technology, gotta have the people, educated and trained, you gotta have the processes in place in in policy, like acceptable use policies or mobile device policies. And then you have to have the technology monitor. So we're a a quasi public organization, we're a dot org versus dot gov. What we do is work on cybersecurity resiliency for the ecosystem in Massachusetts, with a priority on workforce development, specifically resilience on personalities as well. What I wanted people to do is to come into the class, learn from some of my successes and mistakes in the past. So I talked in-depth about some of the situation where I've dealt with insider threats. The key takeaways would be, like, that they should have some idea of what they would wanna do in their receptible use policy so that they could kind of deter insider threats that they should always maintain a a relationship with people when they don't need anything with them to set, basically, with trust with people who are gonna be people that they'd work with so that they can establish that trust before they need to work with them to mitigate inside reps. Two things I'd say. One is this, hybrid or commuting environment post COVID, it's probably here to stay. How does that change the conflict? Part of the issue that I had was explaining to people that the issues are much more difficult now because you can't establish trust as easily when you're not in person. Right? So you can't go in and say hi to someone in the office without needing anything. For them because now you've gotta do it via Zoom or teams. So what I had recommended to them was get on a call early. So, like, when you have a two o'clock meeting, get on at one fifty five. And then use that five minutes to b s with people and establish your trust and report that way. So that's one way that, you know, the olving cyber security, hybrid, or just even remote work experience changes the insider threat program to make it more difficult. The other side of it is, you know, the negligence of people contributing to insider threats has grown as well. And that's become more of a user negligence where they're not trying to hurt the company, but they're doing so with their inactivity or their lack of their negligence, essentially their their lack of awareness to what they're doing. That's security threat. Part, one of that, I guess, would be is a human issue. It's a h a huge human element. From that human side of things, you've gotta deal with that's why I talked about in my class, like identifying partners that you wanna work with stakeholders that you have the shared mission with, like HR, like, like security, like, compliance and legal, and then working with them. And then on technical side, you know, use the resources available to you. And that could be a software component. There's some really good insider threat software tools out there that will allow you to do some of the work, it goes back to the human side because through human interaction and teaching your employees about reporting something that they see as suspicious, that's really how gonna identify insiders. You might get lucky and catch them in log activity or exfiltrations with some log activity, but but really trying to get humans to, identify and then, or report them to somebody, even if it's just one incident is is really how we're gonna help to stem the tide of that. I had mentioned, like, using all the resources available to you, and that's really like the tools. There are some really good insider threat tools out there that can do screen capturing, live recording, monitoring. It goes to your initial part of this with respect to company culture. People might not wanna work for a company that has those things running. The other thing is unless a company has the prospect of them serving employees in some kind of acceptable use policy or something, it it might not work legally for them to be able to do that. It's really a combination of approaches. People processes and technology. You gotta have the people educated and trained. You gotta have the processes in place in in see, like acceptable use policies or mobile device policies and then you have to have the technology to monitor it.

Your experts belong here

Every story in MarketScale Business Services starts with a company putting its consultants, practice leads, and account teams on the record. Buyers are already reading this topic. The only question is whose experts they find.

Clients hire the firm whose thinking they have already read, which means fewer cold conversations for your partners.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

John Petrozzelli
John PetrozzelliDirector, MassCyberCenter

John Petrozzelli is the Director of MassCyberCenter, a Cybersecurity Incident Responder, and an Insider Threat Instructor. Formerly, he directed cybersecurity operations for Magna5’s Boston Region and held senior leadership roles at the FBI, including as a Chief Security Officer overseeing security risk management impacting national security. Petrozzelli is a seasoned communicator, combining his decades of experience with his master's in information security to translate threat awareness to stakeholders. With extensive experience in crisis management, zero-trust models, and computer forensics, he has been a featured speaker at prestigious cybersecurity conferences worldwide. Petrozzelli's expertise spans cybersecurity advisory, crisis management, and insider threat training, with a track record of successfully implementing enterprise-wide security initiatives across various industries.

Follow Business Services Insights

Get new expert content in your inbox.

Business Services: are you visible to AI?

Before they reach out, Business Services buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Business Services expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your consultants, practice leads, and account teams into the articles, video, and social content Business Services buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Business Services Insights

Gartner says 58% of finance teams now use AI

Gartner says 58% of finance teams now use AI

Gartner puts finance AI adoption at 58% in 2024, up 21 points from 2023. Now finance teams need ROI and cost benchmarks. That lands on governance, vendor selection, and measuring AI value without breaking controls.

  • 0158% adoption is a useful internal benchmark: if finance is still piloting, peers may already be scaling workflow-level use cases.
  • 02The Gartner survey found 66% of finance leaders are more optimistic about AI than last year, according to CFO Dive.
  • 03Gartner’s pitch for CFO-facing tools, from AI use-case libraries to budget and efficiency benchmarks, indicates procurement cycles are shifting toward packaged evaluation and governance artifacts.

Sep 13, 2026

Microsoft’s supply chain AI agents now factor carbon into routing

Microsoft’s supply chain AI agents now factor carbon into routing

SupplyChainBrain says Microsoft is deploying AI agents to recommend routes based on cost, speed, and carbon impact. Routing and allocation become continuous, model-driven decisions. Data latency and forecast governance become hard costs.

  • 01Carbon-weighted route recommendations only help if carriers provide lane-level emissions data your TMS can actually consume.
  • 02The “latency tax” benchmark of 5 cents per dollar is a useful internal cost-of-delay test for disconnected planning workflows, according to an Anaplan-sponsored SupplyChainBrain webinar.
  • 03If forecasting moves to rolling 12-month models, carrier commitments and penalty clauses become a weekly planning variable, not an annual contracting artifact.

Sep 13, 2026

ProSight Sets Sept. 22 Deposits Webinar Amid Bank Planning

ProSight Sets Sept. 22 Deposits Webinar Amid Bank Planning

ProSight Financial Association will host its next State of U.S. Deposits quarterly webinar on Sept. 22, 2026, from 2:00 to 3:00 p.m. ET, according to BAI Banking Strategies. The session covers consumer and small-business deposit trends and year-end strategy signals, and is part of ProSight's 2026 quarterly webinar series.

  • 01ProSight's State of U.S. Deposits webinar series runs quarterly in 2026; the Sept. 22 session includes live Q&A and runs 2:00 to 3:00 p.m. ET.
  • 02BAI Banking Strategies states ProSight's benchmarking is used by all top 20 retail banks and most leading direct banks.
  • 03Deposit, branch, and digital teams may reference external sources like ProSight's data alongside internal data as one input during year-end planning.

Sep 13, 2026

Explore More Business Services Insights

Read more expert perspectives from across Business Services.

Browse Business Services Hub

About the Expert

John Petrozzelli
John Petrozzelli

Director, MassCyberCenter

John Petrozzelli is the Director of MassCyberCenter, a Cybersecurity Incident Responder, and an Insider Threat Instructor. Formerly, he directed cybersecurity operations for Magna5’s Boston Region and held senior leadership roles at the FBI, including as a Chief Security Officer overseeing security risk management impacting national security. Petrozzelli is a seasoned communicator, combining his decades of experience with his master's in information security to translate threat awareness to stakeholders. With extensive experience in crisis management, zero-trust models, and computer forensics, he has been a featured speaker at prestigious cybersecurity conferences worldwide. Petrozzelli's expertise spans cybersecurity advisory, crisis management, and insider threat training, with a track record of successfully implementing enterprise-wide security initiatives across various industries.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Business Services and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512