There’s a running joke in Canberra public sector circles about the obligatory shoulder check that occurs before discussing current work activity in public.
We’ve all been there. Standing at the coffee shop and overhearing someone sharing the latest ins and outs of what they are working on. Except the “goss” is a sensitive Cabinet decision.
A brief lapse in judgement doesn’t seem like a big deal and is often unintentional, but the reality is it can quickly incur significant consequences.
The concept of an “Insider threat” has always been an important part of protective security arrangements within government. However over the last decade we have seen both the threat landscape and the scale of vulnerabilities evolve at a pace that requires government agencies to invest in pro-integrity to proactively manage insider risks.
Traditionally, identifying an insider threat involved solely trying to analyse and understand threat actors with ill-natured intent and figuring out how they could cause harm. But there has been a shift in thinking with agencies now recognising that the unintentional insider threat can present just as much risk as those with malicious intentions.
According to APS Census data, 81 per cent of employees believe their agency manages integrity well. However, there is a gap between believing an organisation values integrity and feeling confident enough to act. Of those who had witnessed corruption, 74 per cent did not report the conduct.
Embedding true integrity across agencies is about creating environments where everyone clearly understands what is expected of them, feels confident making good decisions, knows what to do when something doesn’t seem right and beyond that, actually takes preventative actions.
From trusted insider to insider threat
Everyone in the APS is familiar with the concept of a trusted insider. An employee that has gone through clearance and processes before being deemed suitable by an organisation to have access to its assets, resources and people. So how do these people cross over from being a trusted insider to becoming an insider threat?
Often, it is simply a series of small decisions. Imagine three APS employees sitting in a Canberra café having lunch. They start talking about their weekend, but the conversation quickly moves to an upcoming ICT project. They discuss stakeholder challenges, budget pressures and frustrations with a legacy system.
Read also: Are Australian organisations ready for the new rules of AI and quantum cyberwarfare?
At the next table, someone is working on their laptop. They happen to recognise some of the information being discussed. They don’t directly work on the project, but they know enough to become interested and take out their phone and record the conversation. Later, they upload that audio file into an AI tool and use additional prompts to work out which agencies and project are being discussed.
The three APS employees never intended for information to leave the room and were oblivious to the fourth person. But a simple failure to consider their surroundings has created a potential security issue.
This is why insider threats are so challenging. They start with ordinary people doing ordinary things.
Integrity and insider threats are connected
A decline in integrity is a key driver of insider threat. When integrity and professional excellence are embedded across an organisation, the likelihood of these types of scenarios reduce significantly.
The National Anti-Corruption Commission’s Integrity Maturity Framework provides one example of how agencies can assess and strengthen their integrity approaches. Many agencies already operate within a complex landscape of fraud control frameworks, integrity frameworks, security frameworks, HR policies, procurement requirements and APS Code of Conduct obligations.
Controls generally fall into three categories:
- Preventative controls – things designed to stop a problem occurring, such as security clearances, suitability assessments and access controls.
- Detective controls – things that help identify issues when they occur, such as reporting processes.
- Corrective controls – things that reduce the consequences after something has happened, such as disciplinary action, sanctions or revisions to policy and process.
Some controls are particularly important because they are relied upon across multiple risks. These are the controls organisations really need to understand and test.
But it’s not enough for government organisations to just have the right controls and processes laid out, they need to be implemented and tested regularly. A policy sitting on an intranet does not necessarily mean people understand it. A training session being delivered does not necessarily mean behaviours have changed. A policy might describe how a process should work. But the reality of how people operate day-to-day can be very different and understanding that gap is critical.
Creating a culture where people speak up
Embedding integrity across an agency hinges on building the right culture.
There are many reasons why people may not report if they hear or see something that could pose a risk. They may be unsure whether their concern is serious enough. They may not feel empowered to act. They may worry about consequences for themselves, their relationships or their career. If people look around their organisation and see poor behaviours being tolerated, they are more likely to become a bystander rather than a champion for upholding APS integrity.
This is why psychological safety matters, and this is built through small behaviours every day.
If someone approaches their manager and says, “I’m really worried about this,” and the response is simply, “Don’t worry, it’ll be fine,” that interaction can determine whether they feel comfortable raising a concern in the future.
There is a saying: trust is gained in drops but lost in buckets.
Building a pro-integrity culture goes beyond just frameworks and policies and requires leaders and teams who understand their role, test whether controls are working and create environments where people feel confident doing the right thing.

Dannya Hu
Dannya is a pragmatic and engaging senior leader experienced in driving complex change and strategic communication to achieve outcomes.
Dannya has extensive experience leading and managing teams in both the public service and consulting to improve change management, communication and stakeholder engagement.
She has a practical, result-driven approach and is skilled at understanding and synthesising stakeholder concerns and developing approaches to address these issues. She thrives in uncertain environments and has a strong background in providing advice and products to senior executives on how to best communicate and engage with staff and external stakeholders in an environment of complexity and uncertainty.

Joanna Feeney
Joanna is a legal and assurance professional with over twelve years’ in-house legal and management experience leading legal, policy and corporate governance teams as well as experience providing professional services to Commonwealth agencies. Joanna has previously worked for a number of Federal Government agencies, including the Department of Finance, the Department of Parliamentary Services and the Department of Foreign Affairs and Trade.
In addition to legal and policy development experience, Joanna has experience with the Commonwealth Performance Framework, Integrity and Conduct requirements, Fraud Control and Business Continuity. Joanna has also managed multidisciplinary teams to deliver internal audits and management-initiated reviews for rapid program and policy implementation and transformation.
She possesses excellent communication skills and has a demonstrable track record of success in developing relationships with internal and external stakeholders, across both government and private sector. She is passionate about public sector performance, governance, accountability and transparency.
Joanna has a Bachelor of Laws and a Bachelor International Relations from Griffith University.
Outside of work, Jo can be found pottering around the garden, or taking her dog on adventures around Canberra.
