WorkRight23 Logo
Back to all insights
White PaperLeadership and GovernanceAugust 4, 2026

Insider Threats in Organisations

WorkRight23

Author

Share
Insider Threats in Organisations

How Internal Power Dynamics Undermine Performance, Governance, and Trust

Executive Summary

When most people hear the term “insider threat,” they picture stolen data, hacked systems, or compromised intellectual property. Yet, there is a more pervasive, and often more damaging, threat within organisations: the misuse of authority and internal power networks that silence, retaliate against, and conceal misconduct.

WorkRight23 data and real-world cases demonstrate that bullying, harassment, and discrimination are rarely just “HR problems.” Instead, they are early warning signals of deeper governance failures. When ignored, these signals allow misconduct to escalate, leaving organisations vulnerable to financial losses, reputational damage, and even criminal exposure.

This paper redefines insider threats for the organisational context, presents case examples, including recent New Zealand prosecutions and a WorkRight23-supported case, and explains why boards and executives must treat psychosocial hazards as critical risks to organisational sustainability and profitability.

Rethinking Insider Threats

The traditional definition of insider threats has been dominated by IT and cybersecurity concerns. Employees or contractors who deliberately or negligently compromise information systems are rightly seen as a risk. But insider threats do not end at the server room.

Organisations are also exposed when individuals misuse institutional power, form informal alliances, and retaliate against those who try to do the right thing. In this expanded context, insider threats are not just about protecting data but about protecting culture, governance, and trust. Employees who are silenced or punished for raising concerns often hold early knowledge of misconduct. When boards and executives fail to listen, those risks multiply, governance oversight erodes, and organisations find themselves blindsided by crises that could have been prevented.

Case Examples from New Zealand

The risks are not theoretical. Two recent prosecutions in New Zealand highlight how insider threats manifest in practice.

In 2023, two former staff members of the Canterbury Earthquake Recovery Authority (CERA) were convicted of fraud after using confidential information to benefit themselves during the Christchurch rebuild. Their misconduct only came to light after a significant investigation, long after opportunities for early detection had been missed. The case highlighted how the misuse of authority by insiders, often hidden within complex recovery operations, can damage both public trust and institutional credibility (RNZ, July 6, 2023).

Another example involved Constable Vili Taukolo of the Auckland Police, who in 2019 was sentenced to prison for selling sensitive information from the police intelligence system to criminal groups. His actions compromised not only the integrity of investigations but also public confidence in law enforcement. This was a classic insider threat: an individual exploiting institutional access for personal gain, with systemic risks that extended far beyond the immediate misconduct (1News, December 6, 2019).

Both cases illustrate the same lesson: when insider threats are overlooked, misconduct festers within the system until external investigators intervene, by which point the damage to trust, performance, and governance is already severe.

The WorkRight23 Case: Procurement Fraud and Documented Resilience

In one case supported by WorkRight23, a target raised early concerns about potential procurement misconduct. Rather than addressing the issue, a manager attempted to sideline her, framing retaliation as performance management; a tactic she experienced as bullying. This approach is sadly familiar: organisations often mask retaliation under procedural or managerial labels, discouraging others from speaking out.

What made this case different was the target’s decision to document evidence as well as every incident in detail using the WorkRight23 platform. Each entry was time-stamped and preserved, creating an undeniable record of what had occurred. When mediation was eventually convened, this documentation became pivotal. With our support, enough inconsistencies and unanswered questions were raised to trigger an external investigation.

That investigation ultimately confirmed her concerns, leading to criminal fraud charges against those responsible. Most importantly, the target herself was vindicated. Not only was she offered her job back, but she was also promoted; an outcome that highlights the value of accurate documentation and the power of independent support.

The case demonstrates that when employees are protected and encouraged to record their experiences, organisations are not only more likely to identify misconduct but also to reward integrity rather than punish it.

Why Boards and Executives Must Act

These cases make one point very clear: psychosocial hazards are not side issues for human resources departments. They are critical governance and strategic risks.

When employees are bullied, harassed, or retaliated against, it is not just individual well-being that is compromised. The organisation loses innovation, productivity, and trust. Informal alliances and hidden power structures erode ethical standards and oversight, leaving boards blind to misconduct. The financial consequences are severe, ranging from litigation and regulatory fines to long-term reputational harm.

By treating psychosocial safety as a strategic priority, boards and executives move beyond mere compliance and begin to see it as a foundation for sustainability and profitability. In a volatile business environment, an organisation that ignores these hazards risks undermining its own future.

Recommendations

To address insider threats in their full organisational context, boards and executives should take five critical steps.

  1. Reframe Psychosocial Risks as Core Governance Priorities
    1. Move from moral framing (e.g., “bullying is wrong”) to strategic risk framing: “These dynamics compromise performance, governance, and profitability.”
    2. Acknowledge that cultural dysfunction is as dangerous to performance as a data breach. 
  2. Establish Early-Warning Systems
    1. Leverage employee surveys, whistleblower data, complaints, case documentation, and tribunal reports, treating these not as noise but as leading indicators of systemic issues.
  3. Audit Investigation Processes
    1. Ensure investigations examine systemic drivers, not just individual behaviour, but also informal power networks, retaliation patterns, and enabling policies and processes such as incentive structures.
  4. Protect Documented Caseworkers
    1. Encourage and protect those who document concerns. Provide visible, active support and protection for employees who document concerns, making it clear that truth-telling is valued, not punished. 
  5. Embed Psychosocial Safety in Strategy
    1. Make psychosocial safety a board-level priority, aligning it with performance metrics and governance indicators—treat it as a strategic enabler, not just compliance.

Conclusion

Insider threats cannot be confined to cybersecurity manuals. They live within organisational cultures, in the power dynamics that silence dissent and retaliate against whistleblowers. As recent New Zealand prosecutions and the WorkRight23 procurement fraud case demonstrate, these dynamics can undermine governance, performance, and public trust.

For organisations committed to resilience and sustainability, psychosocial hazards must be managed as critical risks. By acting early, enabling and leveraging supporting documentation, and reframing insider threats as strategic issues, boards and executives can protect not only their people but also the integrity and profitability of their institutions.

About the Author

WorkRight23

WorkRight23 Contributor

Insights Delivered Weekly

Join thousands of leaders receiving our latest research and insights on psychosocial risk management directly to their inbox.

More from this topic