Moral Harm Is Your New Insider Threat Vector
Recently I attended a presentation by Dr. Chloe Wilson, an expert in the organizational dynamics of moral harm that arise from witnessing or participating in activities that run against a person's own moral or ethical code. This may sound abstract, but relying on trite college-sophomore retorts -- whose morals, whose ethics? -- misses the point entirely. Wilson's research doesn't measure harm against some external moral standard, it measures whether the person themself perceives a violation of their own values. That sidesteps the sophomoric relativism question rather than getting stuck in it. The grind of high-op-tempo work in a SOC can wear on someone's sense of right and wrong, or their professional pride, whether or not anyone outside them would agree there's anything to object to.
Brendan's posts on threats arising from unintentional damage, negligence, and malice are strong statements about conceptualization of traditional insider threat. They describe the behavioral and cognitive side of insider threat: capability failures and intent failures. Wilson's work expands that picture by adding the side neither capability nor intent covers: the emotional cost of doing the job as instructed.
Moral injury is a term that came out of military and healthcare research. It's the psychological damage done to a person not by what happens to them, but by what they're required to do, witness, or fail to prevent that violates their own sense of right and wrong. A soldier ordered to act against their conscience; a nurse forced to ration care she knows someone needs. The distress isn't fear. It's betrayal by the institution, by a leader, or, in the person's own eyes, by themselves.
Wilson's 2021 dissertation on occupational moral suffering makes a distinction worth considering carefully. She found that moral suffering splits into two measurably different things: witnessing something that violates your values, and being the one who does it. Watching your organization make a call you disagree with is corrosive. It predicts worse mental health and less meaningful work. But being the one who actually builds the tool, runs the query, or executes the instruction is the version that predicts counterproductive work behavior specifically. Not disengagement or burnout. The exact behavior category insider threat lives inside is predicted by nothing external, but by whether the person's own sense of themselves took the hit.
That distinction should reorganize how you think about your own cyber-defender team.
Ask what you're actually asking your cyber-defenders to do, not just witness. Increasingly, it's things like: monitor employee communications more invasively than anyone's comfortable with; deploy AI tools whose behavior nobody fully understands and that occasionally do something nobody sanctioned; build detection systems that double as surveillance systems, depending on who's asking. Each of those has someone's hands on it. That's perpetration, not witnessing, and per Wilson's research, it's the version that predicts the behavior you're actually trying to prevent because the person doing it is the one whose own values are on the line, not just their opinion of someone else's decision.
Compare that to the analyst who simply watches leadership downplay a breach that should have been disclosed. That's corrosive too, but it's the witness version: worse for morale and mental health, less directly tied to counterproductive action. Both versions matter, but one is building toward an incident.
Here's the uncomfortable part for a CISO: you're often the one issuing those instructions. Not because you're callous, but because someone above you decided the surveillance tool, the aggressive scraping, the AI system nobody fully audited, was worth the "tradeoff." You're the transmission point between a decision made in a boardroom and the analyst who has to actually build and run the thing. If that analyst's own sense of themselves takes damage along the way, that's not collateral -- it's a risk factor you now own, whether or not you asked for it. It's the analyst who did the building, not the one who merely heard about it, whose risk you should be watching most closely.
The fix isn't a new detection tool. Brendan's taxonomy still tells you plenty about capability and intent. What Wilson tells you is that you need to know where your people stand on the work they're being asked to personally execute. It's the same discipline we keep coming back to in this series: talent and performance management done well, before a values conflict becomes a resignation, a leak, or worse.
We at Pythia Cyber build the assessment infrastructure to catch what financial-pressure models miss, including the fourth category of insider risk that doesn't announce itself until it's already cost you someone.
Ask us how to identify moral harm before it becomes your next insider incident.
(image credit: Author, CC0, via Wikimedia Commons)
Comments
Post a Comment