Cyber Risk Compendium

Employee / staff

Employees are a stakeholder in several roles at once. As a data subject, their own (HR records, health data, etc.) must be protected. As a Control owner or general user, they operate day-to-day controls such as following password policy or reporting suspicious emails.

At the same time, employees can be a Threat agent — as a disgruntled insider acting with intent, or, far more commonly, accidentally through human error (e.g. clicking a phishing link or misconfiguring a system). This dual role is why security awareness training and a clear reporting culture are themselves important Controls.