Insider Threat and Former-Employee Violence: A Threat Intelligence Briefing on Workplace Attacks by Trusted Individuals, Pre-Incident Indicators, and the Detection Architecture That Closes the Familiar-Face Gap
Home / Intelligence / Insider Threat and Former-Employee Violence: A...

Insider Threat and Former-Employee Violence: A Threat Intelligence Briefing on Workplace Attacks by Trusted Individuals, Pre-Incident Indicators, and the Detection Architecture That Closes the Familiar-Face Gap

Twenty-one percent of workplace homicides are committed by insiders. Eighty percent of attackers exhibited observable warning behaviors before the attack. A threat intelligence briefing on the actor profile, the grievance trajectory, and the four-layer detection architecture that closes the familiar-face gap.

Published May 2026
Read Time 16 min read
21%
Of workplace homicides committed by insiders (BLS CFOI Type III & IV)
73%
Of mass attackers had prior connection to attack location (USSS NTAC)
80%
Of attackers exhibited observable warning behaviors (USSS NTAC)

Insider Threat: Three Numbers That Reframe the Workplace Violence Picture

21% Share of workplace homicides in the most recent BLS Census of Fatal Occupational Injuries data classified as Type III (worker-on-worker) or Type IV (personal-relationship) violence, where the assailant is a current employee, former employee, or known relation rather than a stranger (BLS CFOI, 2022 reference year, released 2023)
73% Share of mass attackers in the U.S. Secret Service National Threat Assessment Center five-year analysis (2016–2020) who had a known prior connection to the attack location, either as an employee, former employee, customer, or community member (USSS NTAC, Mass Attacks in Public Spaces, 2023)
80% Share of targeted violence attackers in the USSS NTAC dataset who exhibited observable behaviors of concern visible to coworkers, supervisors, or HR before the attack but where institutional reporting and threat assessment infrastructure failed to intercept the trajectory (USSS NTAC, 2023)

Twenty-one percent. Seventy-three percent. Eighty percent. The three numbers anchor a threat picture that most workplace security programs are not architected to address. The dominant frame in physical security planning is the external intruder: the unknown assailant arriving at a perimeter with hostile intent. The Bureau of Labor Statistics Census of Fatal Occupational Injuries, the FBI workplace violence typology, and the U.S. Secret Service National Threat Assessment Center mass-attack reviews all point to a different operational reality. A meaningful share of the most severe workplace violence events in the United States are perpetrated by people the institution already knows, often by people the institution employed within the prior twelve months.

This briefing is for risk officers, HR business partners, security directors, and threat assessment teams who need to understand the insider threat surface in physical violence terms, not cybersecurity terms. It maps the FBI workplace violence typology, the BLS perpetrator-relationship data, the USSS NTAC pre-incident behavioral findings, and the detection architecture implications of a threat actor who has institutional knowledge, badge access, building familiarity, and an existing employment file that already documents the warning signs. The Active Assailant Threat Intelligence Briefing covers the venue-pattern view across workplace, retail, and public spaces. This report covers the actor profile that sits inside the institution before the incident.

The FBI Workplace Violence Typology: Why Type III and Type IV Are the Insider Lens

The FBI and OSHA workplace violence typology, codified in the FBI's 2002 monograph "Workplace Violence: Issues in Response" and operationalized in OSHA's enforcement literature, divides workplace violence into four categories defined by the assailant's relationship to the workplace. Understanding the typology is the prerequisite to reasoning about insider threat as a distinct threat surface.

Type I (Criminal Intent). The assailant has no legitimate relationship to the workplace and is committing a crime in conjunction with the violence, typically robbery. Late-night convenience store and gas station homicides are the canonical examples. Type I violence is responsible for the majority of workplace homicides on a count basis, but the perpetrator is unknown to the institution and the incident is structurally similar to street crime.

Type II (Customer or Client). The assailant is a recipient of services from the organization: a patient, a customer, a student, a passenger, an inmate. Healthcare workplace violence is dominated by Type II events. The assailant has an institutional touchpoint but is not employed by the institution.

Type III (Worker-on-Worker). The assailant is a current or former employee of the organization. This is the canonical insider threat category in physical-violence terms. The assailant has badge access (active or recently revoked), building familiarity, awareness of camera placement, knowledge of supervisor schedules, and an HR file that may already document grievances, performance issues, or interpersonal conflicts.

Type IV (Personal Relationship). The assailant has a personal relationship with an employee but no employment relationship with the organization itself. Domestic violence that crosses into the workplace, where an estranged spouse or former partner targets the employee at their place of work, is the dominant Type IV scenario. The assailant is an outsider to the institution but is known to the targeted employee, often with prior protective orders, restraining orders, or documented threat history.

The BLS Census of Fatal Occupational Injuries publishes annual breakdowns of workplace homicides by perpetrator-victim relationship. Across recent reporting years, Type III and Type IV homicides combined account for approximately 20 to 25 percent of the workplace homicide total. The exact figure varies year to year and the BLS classification methodology has evolved, but the order-of-magnitude finding is durable: roughly one in five workplace homicide victims is killed by a current employee, former employee, or domestic intimate of an employee. The remaining 75 to 80 percent are Type I and Type II events, which are the dominant focus of workplace security programs designed around perimeter intrusion and customer aggression. The Type III and Type IV slice is the underaddressed segment.

2 in 5 Workplace homicide events in which the assailant had an institutional touchpoint with the organization (Type II through Type IV combined) BLS CFOI methodology synthesis, 2018–2022
62% Share of USSS NTAC mass-attack perpetrators who exhibited grievance-related concerning behaviors directly observable to coworkers, supervisors, or HR personnel before the attack USSS NTAC Mass Attacks in Public Spaces, 2023
42% Share of workplace mass attacks in the USSS NTAC dataset where the attacker had been separated from the targeted organization within the prior 24 months USSS NTAC analysis, 2016–2020 incident set

The USSS NTAC Mass-Attack Findings: A Profile of the Workplace Insider Attacker

The United States Secret Service National Threat Assessment Center publishes the most rigorous open-source analytic work on targeted violence in the United States. Its Mass Attacks in Public Spaces series, published in 2023 covering the 2016–2020 incident set and updated in 2024 with additional case material, includes a substantial sub-population of workplace attacks suitable for primary-source analysis of the insider-threat actor.

The NTAC dataset defines mass attacks as incidents in which three or more people were harmed in a public or semi-public space. Of the workplace-located events in the 2023 NTAC release, the analytic findings on attacker profile cluster around a consistent set of characteristics. Approximately 73 percent of mass attackers in the broader NTAC dataset had a prior connection to the attack location. In the workplace-specific sub-population, current and former employees were the dominant actor category. The 42 percent of workplace mass attackers separated from the targeted organization within the prior 24 months represents the highest-risk window for institutional violence: the period after employment termination, layoff, or contentious resignation when grievance has been formalized but legal and operational distance from the organization is incomplete.

The behavioral findings are operationally significant. Approximately 80 percent of attackers in the NTAC analysis exhibited observable behaviors of concern in the weeks or months before the attack. These were not subtle internal states. They were verbalized statements of grievance, written communications with hostile content, escalating workplace conflicts, references to violence or revenge, and changes in appearance or affect that coworkers, supervisors, and family members noticed. In a substantial majority of incidents, multiple people in the attacker's professional or personal network were aware of at least one warning behavior. The systemic failure was not detection of the signals at the individual level. It was the absence of an institutional reporting and assessment pathway capable of aggregating signals across observers and converting them into a coordinated intervention.

Grievance was the dominant motivational substrate in the NTAC workplace dataset. The grievance categories included perceived unfair treatment, perceived termination or disciplinary injustice, perceived workplace bullying or harassment, romantic-relationship grievances spilling into the workplace, and financial grievances tied to compensation disputes or perceived contractual breaches. The grievance pattern is what separates insider workplace violence from Type I criminal-intent violence and from the random-target ideological attack profile that dominates public perception of the threat. The insider attacker is rarely opportunistic. The attacker has a specific institutional referent, a specific human target, and a specific complaint that the institution can typically locate in personnel records if it is asked the right question after the fact.

Analyst Note
The Insider Threat Is a Trajectory, Not an Event

The cybersecurity discipline has spent two decades developing frameworks for insider threat detection that treat the threat as a trajectory: a pathway from disgruntlement to grievance to ideation to planning to attack. The CISA Insider Threat Mitigation framework, the CERT National Insider Threat Center research at Carnegie Mellon, and the NITTF (National Insider Threat Task Force) guidance all model insider threat as a sequence of observable behavioral changes that produce intervention windows before any incident occurs.

The physical violence variant of insider threat operates on the same trajectory model. The USSS NTAC behavioral findings are the open-source confirmation. The institutional failure mode is identical across cyber and physical domains: an organization has the signals, has the supervisory observations, has the HR file documentation, and lacks the assessment infrastructure to convert dispersed signal into coordinated response. The detection architecture problem is therefore not whether the signal exists. It is whether the institutional plumbing routes that signal to a multidisciplinary threat assessment team with the authority and the training to evaluate it.

IntelliSee AI gun detection system showing real-time bounding box and confidence score on a firearm detected in an indoor workplace environment, used as terminal failsafe in insider-threat detection architectures
LIVE CAM-12 · ADMIN ENTRY
Actual IntelliSee detection output. A firearm classified by the computer vision model with a visible bounding box and confidence score. In the insider-threat context, the detection layer functions as the terminal failsafe in a defense-in-depth architecture that begins with behavioral observation, supervisory reporting, and HR threat assessment. The system reads weapon geometry in the video frame; it does not identify the person carrying the firearm. No facial recognition is performed. No video is stored or transmitted off-network for detection processing. The alert reaches the security operations console, facility manager, and on-call HR partner within seconds of the weapon entering camera coverage, upstream of a 911 call and upstream of the median 5-to-8-minute law-enforcement response window in suburban and rural commercial sites.

The Termination Window: Why the First 90 Days Are the Highest-Risk Period

The most actionable finding in the insider-threat physical violence literature is the temporal concentration of risk around employment termination, separation, or layoff events. The USSS NTAC workplace-attack sub-dataset, when sorted by the interval between the attacker's separation from the organization and the attack itself, produces a clear right-tail distribution. A substantial share of attacks occur within the first 90 days after separation. A further significant share occur within the first 12 months. By the end of the second year post-separation, the institutional risk has largely normalized to baseline.

The temporal pattern is consistent with the grievance-trajectory model. Separation is the precipitating event that converts unresolved workplace grievance into externalized blame focused on specific institutional actors: the supervisor who delivered the termination, the HR partner who facilitated it, the colleague perceived to have triggered it, the executive whose decision was perceived to be the proximate cause. The 24-month window is the period in which the grievance is most operationally active and the practical distance between the attacker and the organization is most psychologically incomplete.

The risk-management implication is precise. A threat assessment program that does not have a formal, documented post-separation engagement protocol is operating with a blind spot in its most consequential risk window. The protocol elements include continued behavioral monitoring of the separated employee's communications with current staff, review of badge-access termination completeness, assessment of whether the separated employee retains physical knowledge of building security architecture, and proactive coordination with local law enforcement if specific grievance-related threats have been documented in HR records. None of these elements requires the level of investigation appropriate for a criminal proceeding. They require the assessment infrastructure to evaluate whether routine separation has features that warrant elevated attention.

The Society for Human Resource Management (SHRM) workplace violence prevention guidance and the OSHA workplace violence enforcement framework both recognize the elevated post-separation risk window in their published recommendations. The OSHA General Duty Clause analysis in the IntelliSee Intelligence library documents how OSHA citations against employers for workplace violence have increasingly cited the absence of post-separation risk assessment as a contributing factor in cases where a former employee returned to attack current staff.

Threat Intelligence Briefing

The Insider Threat Trajectory: Five Phases From Grievance to Attack

Synthesized from USSS NTAC Mass Attacks in Public Spaces (2023, 2024), CISA Insider Threat Mitigation guidance, and CERT National Insider Threat Center pathway research. Phase durations are illustrative medians; individual cases vary substantially.

P1
Grievance Formation

The employee develops a sustained sense of injustice tied to specific institutional referents: termination, discipline, perceived harassment, denied promotion, compensation dispute. The grievance is verbalized to coworkers and may appear in HR records. This phase often spans months to years before any escalation. The signals are mundane and the volume of false positives is high.

HR & Supervisor Layer
P2
Ideation and Grievance Externalization

The grievance shifts from internal complaint to externalized blame focused on specific individuals or the organization itself. Verbal references to revenge, fairness, or violence appear. Communications become more hostile in tone. Coworkers may report concerns informally. This is the canonical window for behavioral threat assessment intake.

Threat Assessment Trigger
P3
Separation Event (Termination, Layoff, Resignation)

The precipitating event. The employee is separated from the organization, often under conditions the employee perceives as unjust. Badge access is revoked. The institutional relationship is formally severed but psychological proximity remains high. The next 90 days are the period of elevated risk where most post-separation attacks cluster.

Highest-Risk Window Begins
P4
Planning and Approach Behavior

If the trajectory continues, the separated employee may engage in research, reconnaissance, or acquisition behaviors. Returning to the workplace under pretext, contacting current employees with hostile communications, acquiring firearms inconsistent with prior pattern, or making explicit threats. CISA and CERT pathway research documents this as the highest-yield intervention window if institutional awareness exists.

Intervention Window
P5
Attack Execution

The attacker arrives at the workplace, parking lot, or related facility. In many documented insider attacks, the assailant uses familiarity with building layout to bypass perimeter monitoring or approach a specific target by route. Physical detection systems function as the terminal failsafe at this phase. The 60-to-180-second window between weapon visibility and law-enforcement arrival determines casualty outcomes.

AI Detection Terminal Failsafe

The Familiar-Face Detection Problem: Why Insider Threat Breaks Perimeter-Centric Architecture

Most physical security programs are architected against the external intruder. The threat model assumes an unknown person attempting to penetrate a defended perimeter. Access control restricts entry to credentialed personnel. Visitor management screens guests. Perimeter cameras detect approach behavior at the property edge. The architecture is sound for Type I criminal-intent threats and reasonably effective against external Type II customer-aggression events that originate at the entry point.

The insider threat actor breaks the architecture at every layer.

Access control. A current employee has a valid badge. A former employee separated within the prior 90 days may have access that was not fully revoked. The CERT insider threat research documents that incomplete badge deprovisioning is a persistent finding in post-incident reviews. Even where the badge is revoked, a former employee retains knowledge of which doors are propped open during shift changes, which staff entrances are unmonitored, and which contractor access patterns can be exploited.

Visitor management. A former employee returning to the facility under pretext of retrieving personal property, attending an off-boarding meeting, or contacting a former colleague is not flagged by visitor screening designed to detect strangers. The institution knows the person. The system is designed to admit the known, not interrogate it.

Perimeter monitoring. Camera coverage focused on detecting unauthorized approach to the perimeter does not generate an alert when a known employee walks through the front door. Behavioral analytics tuned to detect loitering, perimeter probing, or approach during off-hours are calibrated against the external-intruder threat model. The insider threat actor's approach pattern is operationally indistinguishable from a normal employee arrival.

Behavioral observation by staff. The most consequential detection failure is the absence of an institutional channel for converting coworker observations into actionable assessment. The USSS NTAC finding that 80 percent of attackers exhibited observable behaviors of concern visible to multiple coworkers is not a statement about whether the signals were present. It is a statement about whether the institutional reporting infrastructure existed to aggregate signals across observers, route them to a multidisciplinary threat assessment team, and produce a coordinated intervention before the trajectory reached its terminal phase. In a substantial share of post-incident reviews, the signals were documented in HR files, supervisor notes, or coworker conversations but were not integrated into any threat assessment process.

This is the familiar-face detection problem. The threat actor is not an anomaly the perimeter is designed to identify. The threat actor is a feature of the institution that the institution has not yet recognized as a hazard. Defense-in-depth against insider threat therefore requires architecture choices that complement perimeter monitoring rather than replicate it. The Seven-Tier Workplace Violence Cost decomposition documents how the financial and human cost of an insider attack typically exceeds that of an external attack of equivalent casualty count, primarily because of the litigation surface created by foreseeability findings against the employer in cases where pre-incident warning signals were institutionally documented but not acted upon.

External Intruder vs. Insider Threat: Detection Architecture Coverage Map
Detection LayerExternal Intruder (Type I)Customer Aggressor (Type II)Insider Threat (Type III & IV)Architecture Implication
Access control / badge managementEffective — restricts entryLimited — customer access is purposeLargely ineffective — valid or recent credentialsRequires post-separation deprovisioning protocol
Visitor management / screeningEffective — flags unknownsEffective at registration stepLimited — pretextual visit appears legitimateRequires former-employee flag in visitor database
Perimeter behavioral analyticsEffective — detects unusual approachLimited — normal entry patternLargely ineffective — normal employee patternRequires interior detection complement
Behavioral threat assessment programNot applicable — unknown actorLimited — episodic contactCritical — primary detection layerRequires multidisciplinary team and reporting channel
AI weapon detection on camerasHigh — perimeter and entry coverageHigh — entry and public area coverageTerminal failsafe — after behavioral failureCompresses detection-to-response by 60+ seconds
Post-separation engagement protocolNot applicableNot applicableCritical — 90-day high-risk windowRequires HR/security coordination workflow
Domestic violence workplace awareness (Type IV)Not applicableNot applicableCritical — protective order integrationRequires HR confidential disclosure pathway

Type IV: The Domestic Violence Crossover Threat

The Type IV personal-relationship category in the FBI workplace violence typology is consistently the most underdiscussed segment of workplace violence threat intelligence and the most operationally distinct from the other three types. The threat actor is not employed by the institution. The threat actor is connected to an employee, usually as a current or former intimate partner, sometimes as a family member, occasionally as a stalker with no relationship history. The workplace becomes the venue not because of any institutional grievance but because the workplace is where the targeted employee can be reliably located when they have moved residences or otherwise restricted their accessibility outside of working hours.

The BLS CFOI data on workplace homicide perpetrator relationship consistently shows that domestic intimate partners and former partners account for a meaningful share of female workplace homicide victims. The pattern is asymmetric. Female employees are disproportionately the targets of Type IV workplace violence. The institutional implication is that workplace safety programs that treat domestic violence as a personal matter outside the employer's responsibility are systematically failing a documented risk category.

The detection architecture for Type IV is fundamentally different from Type III. The threat assessment intake is not driven by HR records of internal grievance. It is driven by employee confidential disclosure: a current employee informing HR or security that they have a protective order, a stalking situation, or a known threat from a former intimate partner. The institutional infrastructure required is a confidential disclosure pathway that does not penalize the employee for disclosing, a coordinated workplace safety plan that may include schedule modification, parking arrangement changes, escort protocols, and proactive security awareness, and integration with local law enforcement domestic violence units.

The Workplace Violence Prevention Plan Mandate Compliance Briefing documents how California SB 553 and similar emerging state laws explicitly require employers to include domestic-violence-related workplace safety planning in their written prevention programs. This is a regulatory recognition that Type IV violence is the employer's responsibility to address, not merely the employee's personal matter.

The Multidisciplinary Threat Assessment Team: The Institutional Plumbing That Closes the Gap

The dominant finding across primary-source research on insider threat physical violence is that detection signals exist before the attack and that the institutional capacity to act on those signals is the binding constraint on prevention. The USSS NTAC, the CISA Insider Threat Mitigation framework, the CERT National Insider Threat Center, the FBI Behavioral Threat Assessment Center, and the Association of Threat Assessment Professionals (ATAP) all converge on a common structural recommendation: the multidisciplinary threat assessment team.

The team is the institutional plumbing. It is a standing committee with representation from HR, security, legal, employee assistance, and where appropriate medical or behavioral health expertise. It receives reports from supervisors, coworkers, and confidential channels. It evaluates whether a reported set of behaviors crosses a threshold warranting structured assessment, additional information gathering, or coordinated intervention. It maintains documentation. It coordinates with law enforcement when external assistance is appropriate. It executes the post-separation engagement protocol for terminated employees flagged as elevated-risk during their employment.

The DHS Insider Threat Mitigation guide, CISA's Insider Threat Mitigation Guide, and OSHA's workplace violence prevention enforcement materials all explicitly recommend the multidisciplinary team structure. The team is not a security function. It is not an HR function. It is the integration of multiple institutional functions designed precisely to overcome the silo failure mode in which different parts of the organization each hold partial information about a developing threat trajectory but no integration point exists to assemble the full picture.

The structural argument is the analytical conclusion of the threat intelligence picture. If 80 percent of attackers exhibited observable concerning behaviors visible to multiple coworkers, supervisors, or HR personnel before the attack, and if the institutional pathway to aggregate those observations and convert them into action is absent, then the binding constraint on insider threat prevention is institutional integration, not signal detection. Physical detection systems are valuable as terminal failsafes. They are not substitutes for the upstream institutional infrastructure that the primary-source evidence identifies as the locus of preventable failure.

What Primary-Source Data Cannot Yet Tell Us

Honest threat intelligence requires acknowledging the boundaries of what the available evidence supports. Several questions in the insider threat physical violence literature remain underdetermined by current primary-source research.

Base-rate prevalence is poorly estimated. The USSS NTAC datasets are explicitly purposive selections of high-severity events. They are not random samples of all workplace grievance trajectories. The denominator question, how many employees with documented grievance escalate to any form of workplace violence, cannot be answered with the available evidence. This makes it difficult to construct probability-weighted risk models for individual cases. The threat assessment literature is therefore largely about pattern recognition, not statistical prediction.

False positive cost is undocumented. A threat assessment team that errs on the side of escalation will generate substantial false positives: employees referred for assessment whose grievance trajectory never escalates beyond the early phases. The institutional cost of these false positives, in terms of employee morale, legal exposure under discrimination law, and HR resource consumption, is real but is not systematically quantified in the open literature. Programs designed under the assumption that false positives are costless tend to underperform programs that explicitly manage the false-positive rate.

The deterrence effect of visible threat assessment infrastructure is unclear. The criminological deterrence literature suggests plausibly that visible institutional commitment to threat assessment, communicated through training and policy disclosure, may discourage some grievance trajectories from escalating. The empirical evidence specific to workplace threat assessment is thin. Claims that any specific threat assessment program prevents attacks rest more on inference from the observed signal-gap pattern than on randomized evidence.

The Detection Architecture Synthesis: Layering Behavioral, Procedural, and Technical

The threat intelligence picture above produces a coherent architectural recommendation that does not depend on any vendor's product positioning. The recommendation is structural and is supported by the convergent findings of BLS CFOI, USSS NTAC, FBI behavioral threat assessment guidance, CISA Insider Threat Mitigation, and OSHA enforcement materials.

Layer 1: Behavioral observation and reporting infrastructure. Supervisor training on warning behaviors. Coworker training on the institutional reporting pathway. Confidential disclosure channels with anti-retaliation protections. HR documentation standards that capture grievance trajectories in real time rather than reconstructing them after the fact.

Layer 2: Multidisciplinary threat assessment team. Standing committee with cross-functional representation. Documented intake procedures. Structured assessment methodology (ATAP, CISA, or FBI BTAC frameworks are the dominant reference standards). Escalation pathways including external coordination with law enforcement, mental health resources, and protective measures.

Layer 3: Post-separation engagement protocol. For employees separated under conditions involving documented grievance, performance disputes, or interpersonal conflict, a formal 90-day post-separation engagement plan. Elements include badge deprovisioning verification, continued behavioral monitoring of communications with current staff, building access pattern surveillance for any return visits, and proactive law enforcement coordination if specific threats have been documented.

Layer 4: Physical detection terminal failsafe. AI-based weapon detection on existing camera infrastructure provides the final detection layer for the case where the upstream layers have failed and the attacker has arrived at the facility. The detection compression value is well-documented: sub-five-second weapon classification with automated alert routing reduces detection-to-response latency by approximately 60 seconds against the median human-vigilance baseline. This compression is most consequential in the first 60 to 180 seconds of an active threat, which is the window in which the highest share of harm occurs.

The four-layer model is the synthesis of what the primary-source evidence supports. None of the layers is sufficient on its own. The architectural error in many programs is treating a single layer as a substitute for the integration. The Four-Variable ROI Framework and the Detection-to-Response Latency Economics reports in the IntelliSee Intelligence library quantify the financial value of the technical layer in detection-to-response compression terms. For technical context on how computer vision performs detection without facial recognition, biometric identification, or video retention, see How AI Gun Detection Works: A Technical Reference and How Computer Vision Models Handle Occlusion, Low Light, and Adversarial Conditions.

For organizations seeking to operationalize the terminal failsafe layer, IntelliSee's computer vision platform applies real-time detection to existing camera infrastructure across weapon detection, fall detection, and perimeter monitoring scenarios. The architecture is privacy-by-design: no facial recognition, no video storage for detection processing, no biometric profile creation. The detection event is what the system produces, not an identity record. For risk-management contexts where the threat assessment program already exists and the question is how to add the terminal failsafe layer, see the AI Gun Detection Procurement Methodology.

Frequently Asked Questions: Insider Threat and Workplace Violence

What percentage of workplace homicides are committed by insiders versus strangers?

The BLS Census of Fatal Occupational Injuries (CFOI) classifies workplace homicides by perpetrator-victim relationship. Across recent reporting years, approximately 20 to 25 percent of workplace homicides are Type III (current or former coworker) or Type IV (personal relationship with an employee, typically domestic intimate partner). The remaining 75 to 80 percent are Type I (criminal intent by stranger) or Type II (customer, client, or service recipient). The Type III and Type IV combined slice represents the insider threat surface in physical violence terms.

What is the highest-risk window for an attack by a former employee?

The U.S. Secret Service National Threat Assessment Center mass-attack analysis documents that the first 90 days following separation are the highest-risk window, with elevated risk continuing through approximately 24 months post-separation. Approximately 42 percent of workplace mass attackers in the NTAC dataset had been separated from the targeted organization within the prior 24 months. The temporal pattern is consistent with the grievance-trajectory model in which separation is the precipitating event that converts unresolved workplace grievance into externalized blame focused on specific institutional actors.

Were there warning signs before workplace attacks by insiders?

Yes, with strong consistency. The USSS NTAC mass-attack analysis found that approximately 80 percent of attackers exhibited observable behaviors of concern visible to coworkers, supervisors, or HR personnel before the attack. The signals included verbalized grievance, hostile communications, escalating workplace conflicts, references to violence or revenge, and visible changes in affect or appearance. The institutional failure was not individual-level signal detection. It was the absence of an integrated reporting and threat assessment pathway capable of aggregating signals across observers and converting them into coordinated intervention.

What is a multidisciplinary threat assessment team and is it required?

A multidisciplinary threat assessment team is a standing committee with representation from HR, security, legal, employee assistance, and where appropriate medical or behavioral health expertise. It receives reports of concerning behavior and evaluates whether reported behaviors warrant structured assessment or coordinated intervention. The team structure is recommended by CISA, the USSS NTAC, the FBI Behavioral Threat Assessment Center, and the Association of Threat Assessment Professionals. It is not federally required for most private employers, but California SB 553 and several emerging state workplace violence prevention laws now mandate similar institutional infrastructure for covered employers.

How does insider threat differ from Type II customer or patient violence?

Type II violence (customer, client, or service recipient) is the dominant workplace violence category in healthcare and is characterized by episodic contact between aggressor and institution, typically without sustained pre-incident grievance trajectory targeting specific institutional actors. The detection architecture for Type II focuses on de-escalation training, customer-facing physical security, and behavioral cues observable in real time during interactions. Insider threat (Type III and Type IV) involves a sustained behavioral trajectory often spanning months, embedded institutional knowledge by the aggressor, and pre-incident warning signals visible to coworkers and HR. The detection architecture is fundamentally different and emphasizes upstream behavioral assessment rather than real-time interaction management.

Does AI weapon detection help against insider threat attacks?

AI weapon detection functions as the terminal failsafe layer in a defense-in-depth architecture against insider threat. It does not replace the upstream behavioral threat assessment infrastructure that primary-source evidence identifies as the locus of preventable failure. When a separated employee returns to the facility with a firearm despite missed upstream warning signals, automated detection compresses the detection-to-response latency by approximately 60 seconds against the human-vigilance baseline. This compression is most consequential in the first 60 to 180 seconds of an active threat event. The detection layer is necessary in a complete architecture but is not sufficient on its own.

What is Type IV workplace violence and why does it matter to employers?

Type IV workplace violence is committed by a person with a personal relationship to an employee but no employment relationship with the organization itself. Domestic intimate partners and former partners account for the dominant share. The BLS CFOI data shows Type IV violence is asymmetric: female employees are disproportionately the targets. The institutional implication is that workplace safety programs treating domestic violence as a personal matter outside employer responsibility are failing a documented risk category. California SB 553 and similar state laws now explicitly require employers to address Type IV scenarios in written workplace violence prevention plans, including confidential disclosure pathways, schedule and parking modifications for at-risk employees, and integration with law enforcement domestic violence units.

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment