Report by Fortinet

2025 Insider Risk Report

67 FINDINGSPublished Oct 16, 2025
View Original Report →

Key Findings

Only 15% of organizations feel fully prepared to handle the movement of sensitive data through SaaS and Shadow IT tools.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskSensitive dataSaaSShadow IT

77% of organizations experienced insider-driven data loss in the past 18 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData loss

43% of security professionals are concerned about disgruntled employees.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDisgruntled employees

55% of security professionals are concerned about departing employees.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider risk

• 21% of organizations faced more than 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData loss

17% of insider incidents involved personal healthcare information.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossHealthcare information

73% of security professionals are concerned about careless, negligent, or uninformed employees.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider risk

53% of insider incidents involved customer records.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossCustomer records

47% of insider incidents involved personal information or Personally Identifiable Information (PII).

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossPII

12% of detected insider incidents could not be attributed, underscoring challenges in detection.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider risk

40% of insider incidents involved business-sensitive financial and strategic information.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossFinancial data

59% of security leaders are very concerned about accidental employee data leaks over the next 12 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData leak

Most insider incidents are unintentional: 62% were caused by negligent or compromised users.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskNegligent userCompromised user

Nearly half (49%) of insider incidents resulted specifically from accidental or negligent behavior.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskNegligent user

Only 16% of insider incidents involved confirmed malicious intent.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider risk

37% of organizations reported detecting between 6 and 20 insider-related data loss incidents in the past 18 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData loss

76% of organizations reported losses exceeding $100,000 due to their most significant insider incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

36% of insider incidents involved user credentials.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossCredentials

29% of insider incidents involved Intellectual Property (IP).

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossIP

62% of security professionals are concerned about employees directly involved in the handling of sensitive data such as PII, PHI, or PCI.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskPIIPHIPCI

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 61% said personal cloud storage.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelPersonal cloud storage

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 56% said Generative AI tools like ChatGPT.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelGenAI

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 55% said personal webmail.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelPersonal webmail

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 47% said removable media/storage devices like USB drives.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelRemovable mediaStorage device

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 44% said messaging apps.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelMessaging app

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 31% said screen captures.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelScreen capture

49% of organizations agree, and 23% strongly agree, that they lack visibility into how users interact with sensitive data across endpoints, cloud apps, and GenAI platforms.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskVisibility Sensitive data

72% of organizations lack visibility into how users interact with sensitive data across endpoints, cloud apps, and GenAI platforms.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskVisibility Sensitive data

61% of security leaders are very concerned about credential compromise being used for insider activity over the next 12 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskCredential compromise

51% of organizations report operating at Maturity Level 2 (Implemented: tools are in place but fragmented across teams with limited integration).

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturity

46% say a lack of skilled staff is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityStaffSkillsTalent

42% say organizational silos (e.g., Security vs HR vs Legal) is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturitySilos

35% say insufficient budget is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityBudget

31% say maintenance burden is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityMaintenance

23% say user pushback or fear of harming culture is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityCulture

72% of organizations say their budgets for insider risk or data protection are increasing.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskBudgetInvestment

Only 12% of organizations have a dedicated Insider Risk team.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider risk team

47% of organizations utilize legacy Data Loss Prevention (DLP) tools to monitor insider activity.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

Only 47% of security professionals strongly agree that their existing DLP tools are effective in protecting sensitive data from leaving the organization.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

52% of security leaders cite Shadow AI/SaaS application control as a priority for next-generation solutions.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

29% of organizations detected between 1 and 5 insider incidents in the past 18 months.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider risk

41% of organizations reported financial losses between $1 million and $10 million for their most significant insider incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

67% of organizations reported a financial impact between $100,000 and $10 million for their most significant incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

9% of organizations reported losses above $10 million due to their most significant insider incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

13% of insider incidents involved credit cardholder data.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData lossCardholder data

45% of organizations reported revenue or financial loss as the primary consequence of their most significant insider incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

43% of organizations reported reputational damage as the primary consequence of their most significant insider incident.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

Only 11% of organizations said their most significant insider incident had no significant impact.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskInsider incident consequences

43% of security professionals are concerned about third-party partners or contractors with access to their environment.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskThird-party partnersThird-party contractors

35% of security professionals are concerned about employees directly involved in the creation/development of intellectual property.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskIP

21% of security professionals are concerned about whistleblowers sharing or exposing data.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData exposure

When asked which egress channels for the outflow of sensitive data does your organization worry most about, 69% said email.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskEgress channelEmail

45% of respondents are very concerned about sensitive data being shared with generative AI tools like ChatGPT.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData leakData exposureGenAI

Only 12% of organizations feel fully prepared to detect or respond to sensitive data being shared with GenAI tools.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData leakData exposureGenAI

Only 26% of organizations feel fully prepared to respond effectively to accidental employee data leaks.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData leak

Only 18% of organizations report achieving Maturity Level 3 (Optimized: Unified strategy, cross-functional governance, behavioral analytics, and integrated enforcement).

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturity

Only 14% of organizations feel fully confident in their insider threat detection capabilities.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskThreat detection

38% say privacy or surveillance concerns is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityPrivacy

38% of organizations place the insider risk function within Security/SOC.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskSOC

52% say difficulty monitoring SaaS and hybrid work environments is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturitySaaSHybrid work environment

49% say tool complexity is the biggest barrier to maturing their insider risk program.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskMaturityToolsComplexity

27% of organizations report significant growth in their insider risk or data protection budget over the past year.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskBudgetInvestment

26% of organizations place the insider risk function within a dedicated Data Protection or Data Security team.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskData protectionData security

Only 33% of organizations using DLP agree they gained immediate insight into data usage.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

Only 27% of organizations using DLP can identify which users are putting data at risk.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

66% of security leaders prioritize real-time behavioral analytics in a next-generation DLP or insider risk solution.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP

61% of security leaders prioritize "Day-one" data visibility across environments in a next-generation solution.

Fortinet2025 Insider Risk Report·Oct 16, 2025
Insider riskDLP