Trend and Velocity: Is Your Insider Risk Exposure Moving?
Your current exposure matters. Where it is heading matters more.
“A static measurement may accurately describe a moment in time. It cannot tell you whether the organization is improving, deteriorating, or simply standing still while everything around it moves.”
A recurring theme through all of our ITMG engagements is that most insider risk programs can tell you what happened. Few can describe where exposure exists today. Far fewer can answer if exposure is increasing, decreasing, or quietly moving somewhere else. That is the purpose of trend and velocity.
Earlier articles in this series explored why insider risk needs a common metrics language and why programs must understand exposure, concentration, and coverage. Those concepts establish the picture. Trend and velocity tell us whether that picture is changing—and it is always changing.
People join and leave. Contractors rotate. Companies reorganize. Access accumulates. New technologies change how employees interact with sensitive information. Business leaders make decisions that seem routine operationally but can materially change insider risk exposure.
A Snapshot Is Not a Strategy
Over the course of my career, I have reviewed hundreds of insider risk assessments, dashboards, maturity models, and executive briefings. Many looked impressive. They included heat maps, risk ratings, control inventories, and enough graphics to light up a Christmas tree.
The problem was rarely the presentation. The problem was that the information represented a single moment in time.
I have seen organizations complete a thoughtful assessment, approve a roadmap, and begin implementation with real momentum. Six months later, however, the company had reorganized, changed technologies, expanded contractor access, lost several key stakeholders, or shifted business priorities. The original assessment had not suddenly become wrong. It had become incomplete.
That distinction matters. A static assessment is a valuable baseline, but it should begin the management process, not end it. Too often, the final report is presented, everyone nods thoughtfully, the recommendations are accepted, and the document begins its distinguished career as a PDF attachment.
A living insider risk program must be able to show what changed after the assessment and whether those changes improved or increased exposure.
Trend and Velocity Are Not the Same Thing
While both terms capture movement, they describe fundamentally different properties of organizational change:
Direction over time
Trend tells you the general direction of exposure. Is it rising, declining, or remaining relatively stable? Slow increases point to unresolved access accumulation, drift, or a stagnant roadmap.
Speed of movement
Velocity tells you how quickly that movement is occurring. Rapid increases indicate a workforce transition, sudden expansion of third-party contractor access, control breakdowns, or major technology adjustments.
The current exposure might look similar on paper across two different areas, but the management urgency is not. velocity helps leaders distinguish gradual drift from meaningful acceleration. When staffing, budget, and executive attention are limited, teams need to know not only where exposure is highest, but where it is changing quickly enough to require immediate intervention.
The Enterprise Average Can Hide the Real Story
Organization-wide trends are useful, but I have repeatedly seen them create a false sense of comfort. An enterprise-level score may remain relatively stable while exposure within one population rises sharply. Improvements in one part of the company can offset deterioration somewhere else, leaving the overall number largely unchanged. The executive dashboard says "stable." The experienced practitioner asks, "Stable where?"
In multiple assessments, I observed that the real movement was not occurring across the entire workforce. It was concentrated within a smaller population such as privileged users, contractors, technical administrators, employees in transition, or a business unit experiencing rapid change.
One anonymized pattern I encountered involved an organization that had expanded its contractor population faster than its governance processes had evolved. The enterprise did not appear to be experiencing a broad insider risk increase. At the population level, however, access ownership, onboarding consistency, and accountability were beginning to weaken. The overall picture looked calm. The concentrated movement did not.
This is why trend must be considered alongside concentration. Insider risk rarely moves evenly across an organization. It shifts among populations, technologies, assets, business activities, and operating conditions. A stable enterprise score can still contain an emerging problem.
Not Every Increase Means the Program Is Failing
This is one of the most important interpretation issues I have encountered in both national security and corporate environments. An increase in measured exposure does not always mean the organization became less secure. Sometimes it means the program became better at identifying exposure that was already present.
I have watched programs improve their data access, bring new stakeholders into the process, document previously informal practices, and begin evaluating populations that had never been examined consistently. When the next assessment or measurement was completed, the reported exposure increased.
Someone would inevitably ask, "We invested in the program, so why did the score get worse?" It was a fair question. But the answer was often that the score had become more honest.
The organization had not necessarily created new exposure. It had developed a clearer understanding of existing conditions. Punishing a team for identifying previously hidden risk sends exactly the wrong message. It encourages comfortable numbers rather than useful ones.
Before reacting to a change, leaders should ask whether the environment changed, whether visibility changed, or whether both occurred at the same time.
What I Observed During Workforce Transitions
Workforce transitions provide one of the clearest examples of why movement matters. In several environments I have observed, enterprise-level insider risk indicators initially remained relatively stable during a reorganization, reduction in force, or other significant personnel change. There was no immediate wave of confirmed incidents, and alert volumes often remained within expected ranges.
From a distance, the situation appeared manageable. When we looked more closely, however, exposure was changing within the affected population. Managers were uncertain about timing and responsibilities. Access decisions were inconsistent. Some employees retained permissions that no longer aligned with their expected duties. Different business units followed different procedures, and critical coordination was taking place through informal conversations and email threads.
The issue was not that every affected employee represented a threat. That assumption would have been both inaccurate and unfair. The issue was that the organization's operating conditions had changed faster than its controls and coordination processes.
What I learned from these situations was that broad, organization-wide action was rarely the best answer. Increasing monitoring across the entire workforce would have created more noise, more privacy concerns, and more work for already stretched teams.
"The better response was focused and proportional: Identify the affected population, validate whether existing safeguards still fit the situation, clarify ownership, and coordinate the teams responsible for access, personnel decisions, investigations, legal review, and business continuity."
Trend identified that conditions were changing. Velocity established that the change required attention. Concentration showed where that attention belonged. That was far more useful than reporting that alert volume had increased by a certain percentage.
What I Observed When Visibility Improved
Another recurring pattern appeared when organizations invested seriously in improving their insider risk capabilities. I have worked with programs that strengthened governance, expanded stakeholder participation, documented procedures, improved access to relevant information, and began evaluating populations that had previously received little attention.
The next measurement sometimes showed higher exposure. At first glance, that appeared to be a poor return on investment. In reality, the program was finally seeing the organization more clearly.
I recall more than one executive discussion where the initial reaction was concern that the program's score had worsened after new investments had been made. Once we examined the reasons, however, it became clear that the organization had uncovered unresolved ownership, uneven control implementation, or previously unrecognized exposure.
The program had not made the organization less secure. It had made the risk harder to ignore. That is an important distinction because good metrics are not designed to flatter the program. They are designed to help the organization make better decisions.
Sometimes progress initially looks like discovering more problems. Anyone who has conducted a serious assessment knows this feeling. You open one door expecting a closet and find an entire basement. That is not failure. It is visibility.
Move Beyond Activity Reporting
Many insider risk programs still describe progress primarily through activity counts. They report the number of alerts reviewed, cases opened, employees trained, policies updated, or meetings conducted. Those measures help manage operations. They do not necessarily tell leadership whether exposure is moving.
The activity was real. The risk reduction was less clear. A stronger executive update explains what changed, where the movement occurred, what likely caused it, and what the organization intends to do next.
Questions I Learned to Ask
You do not need a sophisticated scoring model to improve the conversation immediately. Some of the most useful questions are also the most straightforward. At the next program review, ask:
- What changed since the previous measurement and where did that movement occur?
- Did exposure truly change or did the program simply gain better visibility?
- What business or security decision should result from this movement?
- What do we expect to see after corrective action is taken?
These questions reveal whether the program is measuring risk or simply collecting numbers. They also create accountability. When leaders approve a new control, process change, staffing increase, or technology investment, the organization should be able to explain what improvement it expects to see.
In my experience, this is where many roadmaps become disconnected from risk management. Recommendations are completed, but no one returns to the original exposure to determine whether the work produced the intended result.
From Static Reporting to a Living Exposure View
Across national security work and hundreds of corporate insider risk engagements, I have found that the hardest question is rarely, "What happened?" The harder question is, "What changed before it happened, and did we notice?"
That question is why insider risk programs must move beyond annual assessments and static maturity reviews. Those activities remain valuable. They establish a baseline, surface gaps, and help create a roadmap. But a roadmap only creates value if the organization can track whether the work is being completed and whether that work is actually changing exposure.
This was one of the most consistent gaps I observed in traditional consulting and assessment models. An organization would receive a detailed report and a well-considered set of recommendations, but the assessment itself remained frozen in time. Months later, leaders had limited visibility into how conditions had changed, which actions had produced value, or where new exposure was accumulating.
A living exposure view allows leaders to see how conditions are changing, whether planned improvements are producing results, and where new issues may be emerging. It gives the organization a more defensible basis for changing priorities before an incident forces the issue.
This is also where the practical difficulty becomes clear. The concepts are straightforward. Applying them consistently across changing organizational conditions, different populations, varying evidence quality, and multiple improvement efforts is not.
RiskTKO was built around this management challenge. It connects exposure, concentration, coverage, planned improvements, and movement over time so organizations can understand not only where they stand, but where they appear to be heading. The value is not another colorful dashboard. The value is maintaining a decision-ready view of insider risk as the organization changes.
The Bottom Line
Exposure tells you where risk exists. Concentration shows where it is accumulating. Coverage tells you how much of the picture you can credibly see. Trend and velocity add the dimension that static assessments cannot: movement.
What I have learned over more than two decades in this field is that insider risk rarely announces itself as a sudden enterprise-wide problem. More often, conditions begin changing within a population, process, technology, or business activity.
The organizations that manage this well are not necessarily the ones with the most alerts or the largest dashboards. They are the ones that notice meaningful movement early, understand what is driving it, and make a proportionate decision before the issue becomes an incident.
A mature insider risk program should not wait for an incident to discover that exposure had been accelerating for months. By that point, the trend line is no longer intelligence that can guide a decision. It is evidence of what the organization missed.