
Insider threats occur when employees, contractors, or other trusted individuals misuse their access in ways that compromise patient information, research data, laboratory operations, or public safety. These incidents can range from privacy violations and data theft to security breaches and the deliberate misuse of biological materials.
Because insiders already know the organization and its processes, they can be difficult to detect. Warning signs may include unusual access patterns, repeated security violations, sudden behavioral changes, financial pressures, or unexplained wealth. While these indicators do not automatically suggest malicious intent, they should prompt awareness and appropriate follow-up.
Laboratory managers can reduce risk by maintaining strong access controls, regularly auditing sensitive materials and systems, and promptly removing unnecessary permissions. Just as important is fostering a workplace culture where employees feel comfortable reporting concerns without fear of retaliation.
Ultimately, laboratory security is about more than protecting pathogens and equipment. It also means safeguarding information, research, patient trust, and the people who depend on the laboratory’s work. By recognizing the potential for insider threats and promoting a culture of security, laboratory leaders can better protect their organizations and communities.
Key Takeaways
1. Laboratory Security Extends Beyond Pathogens
Many laboratories focus on protecting obvious high-risk materials such as select agents and dangerous pathogens. However, valuable assets also include:
- Patient and protected health information (PHI)
- Personally identifiable information (PII)
- Research data and genetic material
- Recombinant DNA and viral vectors
- Laboratory equipment and regulated glassware
- Chemical, radioactive, and pharmaceutical materials
- Laboratories should recognize that many different assets may be attractive targets for misuse or theft.
2. Biosafety and Biosecurity Are Different Concepts
Biosafety
Focused on protecting personnel from biological hazards through:
- Elimination or substitution of hazards
- Engineering controls
- Administrative controls
- Personal protective equipment (PPE)
Biosecurity
Focused on protecting biological materials, information, and systems from unauthorized access, theft, misuse, or intentional harm. This includes both physical and cyber threats.
3. Insider Threats May Be More Dangerous Than External Threats
An outsider threat is someone who gains unauthorized access to an organization.
An insider threat is someone with authorized access who uses that access in a way that harms the organization, its people, or potentially national security. Insider threats may act knowingly or unknowingly.
Because insiders already have access to facilities, systems, and information, they can be difficult to detect and may cause substantial damage before being identified.
4. Insider Threats Take Many Forms
Privacy Violations
- Unauthorized access to patient records
- Selling confidential patient information
- Accessing sensitive records of public figures
Cybersecurity Violations
- Theft of proprietary research data
- Installing malicious software
- Compromising hospital systems
Biological Misuse
- Deliberately contaminating individuals with pathogens
- Mishandling biological agents
- Improper acquisition or transfer of dangerous organisms
These examples demonstrate that insider threats can affect patient safety, organizational reputation, finances, and public trust.
5. Behavioral Changes May Signal Risk
While no single behavior proves malicious intent, laboratory managers should pay attention to changes such as:
- Unusual work hours or facility access patterns
- Accessing information unrelated to job responsibilities
- Sudden personality or behavioral changes
- Financial distress or unexplained wealth
- Repeated violations of security procedures
- Increasing aggression or fixation on unusual topics
- Significant personal crises affecting workplace behavior
These indicators should be evaluated holistically, as many have legitimate explanations.
6. Understanding Motivation Is Critical
C – Compromise
An individual is coerced, blackmailed, or pressured into actions.
R – Revenge
Attempts to retaliate against coworkers, employers, or organizations.
I – Ideology
Political, religious, or social beliefs motivate the behavior.
M – Money
Financial gain drives theft, fraud, or unauthorized disclosure.
E – Ego
Desire for recognition, power, control, or personal gratification.
Understanding motivations can help managers recognize vulnerabilities and implement preventative measures.
7. Employees Should Report Concerns Promptly
When suspicious behavior is observed:
- Report concerns to laboratory leadership or designated security personnel.
- Maintain factual observations and documentation.
- Record dates, times, and specific details.
- Avoid discussing suspicions broadly with coworkers.
- Allow trained investigators to determine whether further action is needed.
Accurate, objective reporting helps enable appropriate investigations.
8. Managers Should Assess Situations Carefully
- Avoid direct accusations or confrontations.
- Consider personal and workplace factors that may explain behavioral changes.
- Maintain communication with employees.
- Conduct thoughtful threat assessments rather than informal investigations.
- Preserve potential evidence and cooperate with authorized investigators if an investigation occurs.
It’s important to balance security concerns with fairness and professional judgment.
9. Prevention Requires Strong Security Practices
Effective strategies include:
Access Control
- Regularly review access permissions.
- Remove unnecessary access immediately.
- Prevent “tailgating” into secure areas.
- Ensure only authorized personnel enter restricted spaces.
Inventory Control
- Maintain accurate inventories of biological materials.
- Audit sensitive materials regularly.
- Document transfers, use, destruction, and disposal.
Security Culture
- Encourage reporting without retaliation.
- Treat concerns professionally.
- Reinforce both biosafety and biosecurity responsibilities.
Strong systems and consistent accountability help identify problems before they become serious incidents.
10. Insider Threat Awareness Training Matters
Laboratories routinely train for biosafety but rarely train employees to recognize insider threats.
Regular awareness training can help:
- Increase vigilance
- Improve reporting
- Reduce opportunities for misconduct
- Strengthen laboratory security culture
Although training may make potential offenders more aware of warning signs, individuals engaged in misconduct often revert to their normal behaviors over time or eventually make mistakes that reveal the activity.
Bottom Line for Emerging Laboratory Managers
Laboratory managers play a critical role in protecting not only biological materials, but also patient information, research data, organizational assets, and public trust. Insider threats are often difficult to recognize because they originate from trusted individuals with legitimate access. By fostering a culture of security, maintaining strong access controls, encouraging reporting, and staying attentive to behavioral changes, laboratory leaders can significantly reduce risk while supporting a safe and accountable workplace.
This information was originally presented at the January 2025 Emerging Laboratory Managers Collaborative Conference (ELMC²) by Casey Schroeder, PhD, SM(ASCP), in “Pathogens and Betrayal: When the Threat is Inside the Laboratory.”