Home / Blog

The Insider Threat Has a Hardware Layer

Insider Threats - Securing the Hardware Layer

The 2026 Global Insider Threat Barometer found Trust Exposure to be the highest of its four strategic indices. But when organizations ask who and what they trust, one question is still too often missing: Can we trust the hardware being connected?

Trust Is Becoming the Attack Surface

For years, cybersecurity architectures have been built around a fundamental question:
Who should we trust?

Identity and Access Management verifies users. MFA validates credentials. PAM restricts privileged accounts. NAC determines whether users and endpoints should access the network. Yet the 2026 Global Insider Threat Barometer, published by the Australian Institute of Insider Threats (AIIT), suggests that organizations should pay considerably more attention to something that sits at the heart of all these controls: Trust itself.

AIIT analysed 409 intelligence records and assigned the global insider-threat environment a Barometer Index of 68.3. Of its four strategic indices, Trust Exposure was the highest, at 75.1. The report found that 307 of the 409 records involved trust, legitimate access, authority, organizational roles or relationships as a material pathway through which harm was enabled. For Sepio, that raises another Zero Trust question:
We verified the person. But did we verify the hardware?

Attackers Do Not Always Need to Break In

One of the most significant findings in the report is that trusted access is frequently being exploited rather than technically bypassed.

Among the Trust Exposure incidents identified by AIIT, the largest mechanism was Trusted Access Exploitation, accounting for 143 incidents – 46.6% of all Trust Exposure cases. The report notes that in these cases, harm did not necessarily require an attacker to defeat security controls or gain unauthorized access. Instead, the pathway had already been legitimately granted. That is an important distinction.

An attacker does not always have to defeat the firewall. They do not always have to bypass MFA. They do not necessarily have to compromise the NAC. Sometimes the attacker can exploit something the organization has already decided to trust. That could be a user. A contractor. An identity. A relationship. Or, from a hardware-security perspective, a connected device.

Trusted User. Untrusted Hardware

Consider a perfectly legitimate employee entering the office. Their identity is confirmed. Their MFA challenge succeeds. Their laptop is authorized. Their account permissions are correct. From the perspective of the traditional Zero Trust stack, everything may appear legitimate. But then that user connects something:

The employee’s identity does not establish the identity of that hardware. And this is where a potentially important trust assumption remains. A trusted user does not automatically make the hardware they connect trustworthy.

Insider threat - Trusted Hardware and Untrusted Hardware
A trusted user does not automatically make the hardware they connect trustworthy.

Deliberate Harm Changes the Security Model

This becomes even more important when looking at another AIIT finding. Of the 409 intelligence records analyzed, 291 – 71.1% involved deliberate intent to cause organizational harm. This included malicious insiders acting independently as well as external actors operating through trusted insiders.

AIIT’s Threat Index calculation identified 232 malicious-insider records and 59 external-actor-via-insider records. This means insider-risk programs cannot be designed exclusively around accidental behaviour. Organizations must also consider actors who may deliberately search for gaps in controls and intentionally exploit trusted access. That changes the hardware-security question from:
“What happens if somebody accidentally connects an unauthorized device?”
to:
“What happens if somebody intentionally connects one?”

When the External Attacker Becomes an Insider

The traditional separation between an external cyberattack and an insider threat is also becoming less clear. AIIT found that external actors increasingly operate through trusted people, identities, employment relationships and organizational pathways. Of the 409 records analysed, 59 involved an External Actor via an Insider, and the majority of those incidents were connected to espionage.

The report describes methods including recruitment, manipulation, credential compromise, contractor exploitation and deceptive employment. In other words:
The adversary does not always have to break into the trusted environment. Sometimes they find a way to operate through it.

From Sepio’s perspective, that makes hardware verification increasingly relevant. A legitimate identity could introduce an illegitimate device. A legitimate contractor could connect unauthorized hardware. A valid account could interact with hardware whose actual identity differs from what traditional identifiers suggest. And a network access decision based primarily on the identity of the user or the MAC address of the device may therefore leave another layer of trust unverified.

Zero Trust Must Extend to Hardware

Zero Trust is based on a straightforward principle:
Never trust implicitly. Verify explicitly.

But in practice, many Zero Trust architectures apply that principle much more rigorously to people and software than to hardware. Users are authenticated. Credentials are verified. Applications are inspected. Sessions are evaluated. Network access is controlled. Yet connected hardware is frequently trusted based on information such as:

  • MAC addresses
  • VID/PID values
  • IP information
  • Device declarations
  • Previously known inventory
  • Endpoint-agent data

These attributes are useful. But they are not necessarily sufficient to establish the actual identity of the physical device. This is the gap addressed by Sepio Zero Trust Hardware Access (ZTHA).

Sepio hardware visibility overview dashboard
Zero Trust Hardware Access (ZTHA) Infographic

Turning Hardware Trust from an Assumption into a Decision

Sepio discovers and identifies connected assets across IT, OT, IoT, IIoT and IoMT environments and provides organizations with an additional source of device truth.

Instead of relying solely on what a device claims to be, Sepio uses hardware-level characteristics and AssetDNA™ to help establish the identity and risk of the connected asset. The result is a different Zero Trust question. Not simply:
“Is this MAC address allowed?”
But:
“Is this hardware actually what we expect it to be?”

That distinction becomes important in environments where devices can be spoofed, substituted, unmanaged or intentionally introduced by someone who already possesses legitimate access.

Sepio hardware visibility overview dashboard
Sepio Visibility Overview

Reduce the Opportunity, Not Just the Intent

One of the strongest observations in the AIIT report is that malicious intent alone does not create organizational harm. The report argues that harm requires the convergence of capability, access, opportunity and organizational vulnerability.That concept maps particularly well to Zero Trust.

An organization cannot necessarily determine whether every employee will remain trustworthy. It cannot guarantee that every contractor will behave correctly. And it cannot completely prevent external actors from attempting to recruit, compromise or manipulate trusted individuals.

But organizations can reduce the opportunities available to them. For hardware, that means identifying what connects, verifying its identity, assessing its risk and applying policies before implicit trust becomes access. This is where Zero Trust Hardware Access (ZTHA) changes the equation.

Every Connected Device Represents a Trust Decision

A connected hardware asset is not just another inventory entry. It represents a decision.

  • Do we know what this device is?
  • Does its actual identity match what we expect?
  • Should it be here?
  • Does its risk justify the level of access it has?
  • Has something changed?

The AIIT report argues that organizations need to better understand where trust exists, what that trust enables and what could happen when it is exploited.

For Sepio, hardware must be included in that calculation. Because hardware that has never truly been verified represents implicit trust. And implicit trust is exactly what Zero Trust was created to eliminate.

AI Makes Hardware Trust Even More Important

The report also identifies Artificial Intelligence and Synthetic Activity as an emerging dimension of insider risk. Although AI and synthetic activity represented only 12% of the intelligence analyzed, AIIT argues that its significance lies in the way AI is changing trusted access, organizational authority and governance. That development becomes particularly significant as AI moves from cloud applications into physical endpoints.

AI PCs. AI accelerators. Edge AI systems. Embedded AI devices. Autonomous industrial equipment. Intelligent IoT systems. The more intelligence and autonomy organizations put into hardware, the more important the identity and integrity of that hardware becomes. Which leads to a simple principle:
There Is No Trust in AI Without Trust in Hardware.

Before trusting what an AI-enabled endpoint can decide, access or control, organizations first need confidence in what that endpoint actually is.

Completing the Zero Trust Architecture

Different security technologies answer different questions.

  • IAM asks: Who is the user?
  • PAM asks: What privileges should they have?
  • EDR asks: What is happening on the endpoint?
  • NAC asks: Should this endpoint access the network?
  • SIEM asks: What events should we correlate?
  • Sepio adds another question:
    What hardware is actually connected?

That additional source of truth can then strengthen the security controls organizations already have. Zero Trust Hardware Access is therefore not about replacing IAM, NAC, EDR, XDR or network security. It is about extending their reach to a layer that has historically been difficult to verify:
the physical hardware itself.

Zero Trust the Person. Zero Trust the Hardware.

The 2026 Global Insider Threat Barometer highlights an important evolution in the threat landscape. Trust is increasingly being exploited as a pathway to organizational harm. External and insider threats are converging. Deliberate behaviour dominates much of the observed intelligence. And AI is adding another layer of complexity to organizational trust.

The lesson for organizations is not that trust should disappear. Organizations cannot operate without trust. The challenge is to make trust explicit, visible and continuously verifiable.

  • That should include users
  • Identities
  • Applications
  • Access
  • And the hardware connected to the environment

You verified WHO. Now verify WHAT they connect. Sepio Zero Trust Hardware Access, Superintelligence for What Connects Next.

Talk to an expert. See What You’ve Been Missing.
October 8th, 2026