Back to Issues
Issue 5
June 15, 2026

Concentration: Where Insider Risk Really Lives

Why insider risk programs need to measure concentration, not just raw activity counts. Explore how understanding where risk lives helps organizations target controls intelligently.

Issue #5 June 15, 2026 8 Min ReadThe Insider Risk Metrics Series

Concentration: Where Insider Risk Really Lives

Why insider risk programs need to measure concentration, not just raw activity counts.

“Averages answer: ‘What does the enterprise look like overall?’ Concentration asks: ‘Where would a problem matter most?’”

Most insider risk programs are built as if risk is evenly spread across the enterprise.

It is not.

Risk does not politely distribute itself by headcount, department size, or org chart hierarchy. It gathers. It clusters. It shows up around certain roles, access patterns, business functions, assets, processes, vendors, and moments of change.

That is why two organizations can have the same number of employees, the same basic security tools, and the same number of reported incidents, but very different insider risk profiles.

The difference is concentration. Exposure tells you how much risk exists. Concentration tells you where that risk lives. That distinction matters. Because insider risk is not only a detection problem. It is a placement problem.

If you do not know where risk is gathering, you cannot prioritize the right controls, focus the right conversations, or explain why one area of the business deserves more attention than another.

You are left with averages. And averages are where insider risk hides.

The problem with average-risk thinking

Many organizations report insider risk in broad terms:

“The enterprise has X open cases.”
“We had Y policy violations this quarter.”
“Privileged user activity increased.”
“Data movement alerts are up.”

Those statements may be true. They may also be useful. But they often flatten the picture. They make the organization look like one big surface area, when in reality risk is usually uneven.

A business unit with a small number of employees may carry a large portion of sensitive access. A role family may touch critical systems across multiple regions. A vendor group may have temporary access to valuable data during a project. A team involved in a reorganization may have a different risk profile than the rest of the company.

A department with very few cases may still represent significant exposure because of what its people can access, move, approve, change, or disclose. That is the danger of average-risk thinking. It creates comfort where there should be focus.

Averages answer: “What does the enterprise look like overall?”

Concentration asks: “Where would a problem matter most?”

That is a much better question. It is also the question leaders actually need answered. That is a more mature conversation. It is also a more defensible one.

Notional case study
Same alert count, very different risk

Imagine two departments each generated 25 insider risk alerts this quarter. At first glance, they look equal.

Department A is a large customer support function. Most alerts involve routine policy exceptions, such as users trying to move low-sensitivity files to unapproved collaboration tools. Annoying? Yes. Worth understanding? Absolutely. But in many cases, the pattern may be tied to workflow friction.

Department B is a 14-person engineering team supporting a pre-release product. Their alerts are fewer in context, but the group has access to source code, unreleased designs, and partner integration details. One mistake or misuse event could create strategic, competitive, or regulatory consequences.

A raw dashboard may show both departments as “25 alerts.”

A concentration view asks a better question: Are those alerts happening in places where the business impact is meaningfully different?

That does not mean Department B is “bad.” It means the organization should not treat the two areas as equal simply because the count is equal.

The riskiest address in the enterprise is not always the loudest one.

What is insider risk concentration?

Insider risk concentration is the degree to which insider risk exposure is clustered in specific parts of the organization.

Those clusters may appear around:

Roles with elevated access
Business units with sensitive data
Functions with high operational authority
Groups undergoing workforce change
Teams supporting critical assets
Regions with unusual activity patterns
Vendor or contractor populations
Projects involving confidential strategy
Processes with outsized potential impact

The purpose is not to label a group as “bad” or create suspicion around a department. That is exactly the wrong framing. The purpose is to understand where exposure, access, business criticality, and organizational context come together in ways that deserve more disciplined attention.

Concentration is not a blame metric. It is a focus metric.

It helps leaders answer:

  • Where is insider risk most concentrated?
  • Which areas would create the greatest impact if something went wrong?
  • Where are our controls most dependent on a small number of people, processes, or assumptions?
  • Where should we prioritize review, training, monitoring, governance, or leadership attention?
  • Where are we treating unequal risk as if it were equal?

That last question is often the one that changes the conversation. And in many organizations, it is a conversation that is overdue.

Risk has gravity

A useful way to think about concentration is as a risk gravity map. Some parts of the organization naturally pull more risk toward them because of what they do, what they access, what they approve, what they build, what they know, or what they can change.

Finance may have transaction authority. Engineering may hold product or source code sensitivity. Sales operations may have customer and pricing exposure. Executives and their support teams may have strategic information. Legal and HR may touch highly sensitive employee or investigation data. IT and security teams may have privileged access that reaches across the enterprise. Third-party support teams may sit outside the cultural and managerial controls that apply to employees, while still touching internal systems or data.

None of those facts imply wrongdoing. They simply mean risk has gravity.

A strong insider risk program does not treat every area the same. It recognizes that some areas require more precision, more governance, or more tailored controls because the potential consequence is different.

Concentration.

Where does the organization carry concentrated exposure, and are we managing it intentionally?

Notional case study
The small room with the big blast radius

A company has 8,000 employees, but only nine people can administer a critical identity platform.

Those nine people are well-trained, trusted, and essential to the business. They are not creating a high volume of alerts. In fact, compared with other parts of the company, their activity may look quiet. But their access reaches across systems, users, permissions, and business units.

That is concentrated trust.

A mature program does not look at that group and say: “They are risky people.” It asks:

  • Are we comfortable with this concentration of authority?
  • Is it visible?
  • Is it governed?
  • Would we know if the risk profile changed?
  • Are compensating controls strong enough for the level of trust being placed there?

That is how concentration changes the meeting. It helps leaders talk about the structure of risk without personalizing it.

That matters, because no one wants an insider risk program that turns every important function into a suspect population. The goal is not suspicion. The goal is stewardship.

Why concentration matters to executives

Executives and leaders rarely have time to inspect every event, alert, policy exception, or access pattern. They need a way to understand where attention should go.

Concentration metrics help translate insider risk from scattered operational activity into executive-level prioritization.

They support better decisions about:

Control Investment

Where to invest in additional controls to protect highly sensitive clusters of access.

Monitoring Coverage

Where to increase monitoring coverage to eliminate key organizational blind spots.

Access Governance

Where to review access permissions and structural delegation of authority.

Awareness & Enablement

Where to focus security awareness and manager training to support key cohorts.

Targeted Risk Reviews

Where to conduct structured risk evaluations for sensitive projects or role families.

Business Ownership

Where to assign clear business accountability for concentrated exposure areas.

Without a concentration view, programs often over-serve the loudest areas and under-serve the most material ones. That is a common failure mode.

The areas producing the most alerts are not always the areas carrying the highest risk. The areas with the most incidents are not always the areas where the organization is most exposed. The areas with the most people are not always the areas where an insider event would matter most.

Concentration helps correct that bias.

It gives leaders a way to distinguish noise from materiality. And that is one of the hardest things to do in a world full of dashboards.

Notional case study
The vendor surge nobody owns

A global company brings in a third-party implementation partner for a six-month systems migration. The vendor team is temporary. The access is approved. The project is urgent. Everyone agrees the work has to happen. So far, so normal.

Over time, the vendor population grows from 20 users to 75. A few accounts receive broader access than originally planned because deadlines are tight. Some access exceptions are documented; others are buried in project communications.

The business sponsor assumes IT is watching it. IT assumes the vendor manager is tracking it. Security only sees pieces of the activity. No single event looks dramatic. But concentration is growing.

The issue is not that the vendor is malicious. The issue is that a temporary business need has created a concentrated pocket of access, urgency, and unclear ownership.

A concentration lens would help leaders ask:

  • Is this temporary exposure still aligned to the original purpose?
  • Who owns the risk while the project is active?
  • What should happen when the project ends?
  • Would we see the difference between expected project activity and meaningful risk movement?

Those are practical governance questions. They are also the kinds of questions that broad enterprise averages rarely surface.

What concentration can reveal

A concentration lens can surface patterns that a traditional case count will miss. For example:

  • Small Teams with High AccessA small team may represent a large share of access to sensitive assets.
  • Large Departments with Low RiskA large department may generate many alerts but represent relatively low material exposure.
  • Vendor & Partner SurgesA vendor population may have limited headcount but unusually broad system reach.
  • Temporary High-Value ProjectsA project team may temporarily combine high-value data, compressed timelines, and expanded access.
  • Aggregated Role RisksA role family may appear low-risk when viewed individually, but significant when aggregated across the enterprise.
  • Geographic Control GapsA business unit may have strong controls in one region and weak visibility in another.
  • M&A and Reorg ResidualsA recent reorganization may have created new access combinations that were never intended as permanent.

Again, the goal is not to publish a list of “risky departments.” The goal is to see where the organization’s insider risk posture is becoming dependent on concentrated trust.

That phrase is worth remembering: Concentrated trust.

Every organization depends on trust. But when trust becomes highly concentrated in a small group, a high-impact role, a fragile process, or a poorly governed access pattern, it deserves measurement.

Not panic. Measurement.

Notional case study
The deal team that disappears from the dashboard

During an acquisition, a small corporate development team, legal team, finance group, and outside advisors are given access to confidential deal materials.

The population is small. The project has a code name. The work happens quickly. Some files are shared through approved systems, some through restricted deal rooms, and some through executive channels.

From a normal enterprise reporting view, the activity may not stand out. It is too small to move the overall numbers. But the business value of the information is high. Timing matters. Disclosure risk matters. Competitive sensitivity matters.

A concentration lens makes the risk visible without requiring anyone to claim that something improper is occurring.

The right question is: Where are small groups handling high-consequence information, and are we treating that concentration with the right level of attention?

That question applies to acquisitions, product launches, investigations, litigation, restructuring, market expansion, and other sensitive business events. These are the moments where insider risk is often most important, but least visible in enterprise averages.

Practical questions to ask in your next program review

Even before an organization has a mature metrics platform, leaders can improve the quality of the conversation by asking better questions.

Insider risk, security, HR, legal, compliance, and business teams can ask:

Where do we believe insider risk is most concentrated today?

Is that belief based on evidence, cases, intuition, or organizational folklore?

Which teams have access that is disproportionate to their size?

Which roles can create the greatest business impact through misuse, mistake, coercion, or negligence?

Which third-party populations have meaningful access to sensitive systems or data?

Where are temporary access patterns becoming permanent?

Which critical assets depend on a small number of highly trusted users?

Which groups have high exposure but low monitoring or governance coverage?

Where would we be least surprised to find a blind spot six months from now?

Where are we applying broad controls when targeted controls would be more effective?

These questions do not reveal a proprietary method. They do something more useful. They change how the program thinks.

That is the value of concentration. It forces risk leaders to move from general awareness to specific focus. And sometimes, that shift alone is enough to make the next leadership meeting much more productive.

Good use versus poor use of concentration metrics

Like any metric, concentration can be used well or badly.

Poor Use

  • Ranking departments without context
  • Treating concentration as suspicion
  • Using raw alert counts as a proxy for risk
  • Comparing groups without adjusting for role, access, business function, or operational reality
  • Punishing teams for being visible while ignoring teams with poor coverage
  • Creating heat maps that look impressive but do not change decisions

Good Use

  • It connects concentration to business context.
  • It separates volume from materiality.
  • It looks for patterns over time.
  • It helps leaders allocate attention proportionately.
  • It supports governance without creating unnecessary fear.
  • It informs targeted action without turning the program into a surveillance narrative.

The best concentration metrics do not simply tell leaders where activity is happening. They help leaders understand where risk deserves ownership. That is the shift.

Notional case study
The department that looks worse because it is better covered

A financial services company compares insider risk alerts across departments. One operations group appears to be a problem area because it generates more alerts than peer functions. Leadership initially assumes the group is higher risk.

Then the team looks closer. That group has better monitoring coverage, clearer reporting processes, stronger manager engagement, and more consistent policy enforcement. Another group appears cleaner, but only because visibility is weaker and fewer control points exist.

In other words, the first group may not be riskier. It may simply be more visible. This is one of the most common ways insider risk metrics can be misread.

A concentration view should not punish visibility. It should help the organization ask where exposure, visibility, and business impact are aligned, and where they are not.

A clean dashboard is not always a safe dashboard.

What high concentration means directionally

A high concentration signal does not automatically mean something bad is happening. It means the organization has a pocket of exposure that deserves a closer look.

That closer look may lead to several different conclusions:

  • The concentration is expected and well controlled
  • The concentration is expected but under-governed
  • The concentration is temporary and should be monitored until it declines
  • The concentration is accidental and should be reduced
  • The concentration is growing and should be escalated for review
  • The concentration is paired with poor visibility, which makes it more concerning
  • The concentration is paired with weak business ownership, which makes it harder to manage

That is why interpretation matters. A concentration metric should not be treated as a verdict. It should be treated as a prompt for better judgment.

The most useful version of the metric does not say: “This group is risky.” It says: “This is where risk is concentrated. Is that intentional, visible, governed, and acceptable?”

That question is far more valuable. It also keeps the conversation grounded, practical, and fair.

Common mistakes when thinking about concentration

  • Confusing activity with concentration.A group that generates a lot of activity may simply be busy. A group that generates fewer events may still hold more consequential access. Volume is not the same as concentration.
  • Comparing teams unfairly.A research group, finance team, executive office, engineering team, customer support function, and IT admin population may all have different access profiles and business purposes. Treating them as if they should look identical creates bad conclusions.
  • Ignoring small populations.Some of the most important insider risk concentrations live in small groups: privileged administrators, specialized engineers, deal teams, acquisition teams, executive support, sensitive investigation teams, and certain third-party users. Headcount can mislead.
  • Building a heat map without a decision path.If a concentration view does not change prioritization, ownership, review cadence, or control strategy, it is probably just decoration.
  • Assuming concentration is permanent.Concentration changes. It can rise during transactions, reorganizations, major product releases, migrations, investigations, workforce reductions, or vendor transitions. A static view can miss the moment when concentration becomes most important.
  • Treating concentration as a security-only issue.Security may help measure and monitor it, but concentration often reflects business design: who has access, how processes work, where authority sits, how vendors are used, and how change is managed. The business has to be part of the conversation.

A memorable rule: risk has an address

One of the simplest ways to make concentration stick is this:

A memorable rule

Risk has an address.

It lives somewhere. It may live in a role. It may live in an access pattern. It may live around an asset. It may live in a process. It may live in a vendor population. It may live during a transition. It may live in the gap between what the organization thinks is controlled and what is actually visible.

The point is not to create fear. The point is to stop pretending that enterprise averages are enough.

When leaders ask, “Where does this risk live?” they make the program more practical immediately.

They stop arguing about abstract insider threat scenarios and start managing real organizational exposure. That is what separates a mature insider risk program from a reactive one.

Notional case study
The quiet executive support function

An executive assistant team may not look like a traditional insider risk priority. They may not administer systems. They may not write code. They may not approve payments. They may not appear in high-volume alert reporting.

But they may handle board materials, strategy documents, travel details, sensitive communications, calendar intelligence, personnel matters, and confidential attachments. The risk is not obvious if the program only looks for technical privilege.

But concentration is not only about technical access. It is also about business context.

A person or group can have relatively modest system permissions and still sit close to highly sensitive information.

That is why a good concentration discussion includes more than security telemetry. It includes the business reality of who knows what, who can reach what, and where the consequences would be greatest.

Why this is hard to compute consistently

Conceptually, concentration is straightforward. Operationally, it is difficult.

To measure it well, organizations need consistent ways to understand users, roles, access, assets, business context, control coverage, organizational structure, third-party relationships, and changes over time.

Those data points rarely live in one place. They are often fragmented across identity systems, HR data, asset inventories, case management tools, data protection platforms, security telemetry, vendor systems, and business records.

Even when the data exists, comparison is hard.

A raw number from one business unit may not mean the same thing as the same number from another. A role in one region may not carry the same exposure as a similar role elsewhere. A vendor group may appear small but have access patterns that make it materially significant.

This is where many organizations discover that concentration is easy to discuss in a meeting and hard to maintain in a spreadsheet. Not because the idea is too complicated. Because the organization is.

Notional case study
The spreadsheet that could not explain itself

A security team builds a spreadsheet to identify high-risk groups. The first version looks promising. It includes departments, alert counts, user counts, privileged access, and sensitive data access. Leaders like the heat map. Then the questions start.

  • Why is one region compared directly to another when the business functions are different?
  • Why does a contractor population appear lower risk when their access is broader?
  • Why did a department improve this quarter because risk went down, or because coverage changed?
  • Why does the model treat temporary project access the same as standing access?
  • Why do two teams with the same score have completely different business impact?

The spreadsheet did not fail because the team was careless. It failed because insider risk concentration is a multi-dimensional problem.

The hard part is not drawing a heat map. The hard part is making it defensible, repeatable, comparable, and useful over time.

Where RiskTKO® fits

The concepts in this series are broadly applicable. Any serious insider risk program should be able to discuss exposure, concentration, coverage, change, effectiveness, and outcomes in a disciplined way.

The challenge is producing those metrics consistently from real-world data and using them repeatedly enough to support decisions.

RiskTKO® is designed to help organizations operationalize insider risk metrics so teams can compute, monitor, benchmark, and act on them with greater consistency. For concentration specifically, the value is not simply seeing another dashboard.

The value is helping leaders develop a defensible view of where insider risk lives, where attention should go, and where current program assumptions may be too broad to be useful.

Because insider risk does not spread evenly. It gathers. And the programs that learn where it gathers will make better decisions than the ones that only count what already happened.

Closing thought

The next time your team reviews insider risk, do not start with: “How many cases do we have?” Start with a better question:

“Where is our risk concentrated, and are we managing that concentration intentionally?”

That single question can change the meeting. And over time, it can change the program.

Remember, insider risk has an address. The mature programs are the ones that learn how to find it.