top of page

Why Employees Stay Silent

  • Writer: Simon Ball
    Simon Ball
  • Aug 26
  • 9 min read
Employee silenced due to poor workplace culture.

Why employees stay silent: reporting culture, human behaviour and insider risk


This month’s blog is being published a little later than I originally intended. Over the last few weeks, I have been moving home, relocating and spending some important time with my family. That has delayed this post slightly, but it has also given me more time to think properly about the subject.


This month, I wanted to focus on something that sits at the heart of almost every serious insider risk discussion: silence. In many organisations, the first warning sign is not an alert, a report or an investigation. It is a quiet conversation between colleagues where someone says, “That does not feel right,” and then nothing happens.


Someone notices unusual behaviour, a security shortcut, a worrying comment, a welfare issue, a grievance, a conduct problem or a person acting out of character. It may not feel like a clear security incident, but it simply feels wrong. Then it sits there, unreported, unchallenged and unconnected. That is where insider risk often starts to grow.


This is personal to my experience


During my time in the RAF Police, I dealt with criminal suspects, victims, witnesses, managers, commanders and people caught somewhere between all of those categories. That experience shaped my view of reporting culture and the human realities behind why people do, and do not, raise concerns.


Service life is unique. Everyone can know everyone. People live together, work together, deploy together, socialise together and often depend on each other in high pressure environments. That creates strong loyalty, trust and identity, but it can also make reporting extremely difficult. If you report something, it may feel like reporting someone you know, someone you work with, someone your friends know, someone who outranks you, or someone you may need to work alongside again tomorrow.


I saw the same issue from the other side as well. In one RAF role, we introduced an anonymous reporting tool because I believed some concerns were not reaching the right people. That channel gave personnel an accessible and safer way to raise issues without feeling exposed or forced into a formal route before they were ready. To our surprise, the tool uncovered some serious concerns that would have stayed hidden, led to meaningful action, improved leadership visibility and, importantly, helped build a positive culture based on trust.


That experience reinforced something I strongly believe now. “Just report it” is not a strategy. It is a slogan. If an organisation wants people to report concerns, it has to create the conditions where reporting feels possible, safe, useful and worthwhile.


Most people do not want to stay silent

Employee speaking out against security issues.

This is the part I think many organisations misunderstand. Employees often do not stay silent because they are indifferent. They stay silent because the reporting environment is poor, unclear or not trusted.


From my own experience dealing with victims, witnesses, criminal matters and security incidents, one thing stood out. When I asked people why they eventually reported something, the answer was simple. More often than not, they did not agree with what had happened. It went against their values, their sense of fairness or their professional duty. They did not want to cause unnecessary trouble, but they also did not want to ignore something they believed was wrong.


That matters because the moral instinct to report is often already there. Most people do not want to see colleagues harmed, their workplace damaged, sensitive information exposed or inappropriate behaviour ignored. The problem is that this instinct can be weakened or suppressed when people do not know what to report, where to report it, whether anyone will take it seriously, or whether speaking up will create consequences for them.


A business may have a whistleblowing policy, a security policy, an HR policy, a cyber policy and an acceptable use policy. However, if people do not understand those policies, trust them or believe they will be acted on, they may not mean much in practice. Reporting confidence is created by repeated evidence that the organisation wants concerns raised, handles them fairly, protects those who report in good faith, and acts proportionately when something is wrong.


The cost of speaking up


People stay silent when the perceived cost of speaking is higher than the perceived value of reporting. If reporting a concern feels risky or socially dangerous, many people will choose silence, not because they agree with what they have seen, but because the organisation has failed to make reporting feel safe or useful.


Fear of repercussions is one reason. Employees may worry they will be labelled difficult, disloyal or “a grass”. They may worry the person they report will find out, managers will protect the wrong person, or their career will suffer.


Uncertainty is another reason. People often see things that feel wrong but are not sure whether they are serious enough to report, such as unusual access, worrying behaviour, ignored security rules, health and safety breaches, a person becoming angry or withdrawn, or a breach being brushed off as harmless. The more ambiguous the concern feels, the easier it becomes to talk yourself out of reporting it.


Culture is often the primary culprit. Some workplaces create an unspoken rule that problems should be kept local, hidden, softened or ignored. Silence becomes normal not because everyone agrees with it, but because the system quietly rewards it.


What silence can hide


When people hear “insider threat”, they often jump straight to the malicious insider intentionally stealing information or IP, committing fraud or helping an external actor. Those cases matter, but in most organisations the risk picture is wider and often less dramatic.


It may be the person who does not understand the risk, shortcuts a process because they are busy, shares information too widely, works around a control because it slows them down, or ignores a rule because “nothing bad has happened before”. It may be someone under pressure, someone being exploited, manipulated or coerced, or someone deliberately misusing trusted access. I explored some of this wider human and access risk in my recent post on the JLR cyber attack.


Someone worried to speak up.

The point is not to create labels for people. The point is to understand that insider risk can emerge through negligence, pressure, poor culture, weak management, personal vulnerability, hostile intent or organisational failure. That is why silence is so dangerous.


What the NPSA findings still tell us


The NPSA Insider Data Collection Study is now dated and should be treated in context. It used data collected and analysed between 2007 and 2012, and it excluded unintentional insider acts, so it does not capture the full range of negligent or accidental insider risk many organisations face today. Even so, the data remains useful.


The study examined more than 120 UK based insider cases and found that many were self initiated rather than deliberate infiltration. The risk developed after the person was already inside, which reinforces a key point in this article: insider risk is not static. People, circumstances, pressures, motivations and access change frequently.


The most useful part of the study, for me, is what it says about organisational conditions. Poor management practices, weak auditing, gaps in protective security, poor security culture, weak communication between business areas, lack of senior awareness of people risk and inadequate governance all appeared as enabling factors. Organisations should focus less on identifying a fixed “type” of person who becomes an insider, and more on understanding the conditions that allow insider risk to grow and remain unchallenged.


Dr Eric Lang and the human factors problem


Dr Eric Lang’s work on the Seven Science Based Commandments for Understanding and Countering Insider Threats is highly relevant here because it brings the discussion back to people. One of the strongest messages from his work is that human factors are paramount. Technology matters, but it is not enough. Insider threats are created, enabled, noticed, missed and ultimately stopped by people.


That aligns strongly with my own view and experience. A monitoring tool may detect an unusual login, but a colleague will probably notice the change in behaviour first. A policy may explain the rules, but a manager may be the first person to notice someone is struggling. A cyber alert may identify suspicious access as it is happening, but a trusted reporting route may identify the concern earlier.


Lang also highlights the importance of employees as an organisation’s greatest strength in identifying insider threats. That matters because in many cases, someone nearby has seen something. The problem is that they may not report it, or the report may not be handled properly. If people do not know what to report, if they do not know how to report or if they do not trust the process, the organisation loses one of its most important sources of early warning.


The strongest insider risk programmes are not built on technology alone. They are built on human understanding, leadership, reporting, fair assessment, proportionate action and culture. This is why positive reporting culture is not a side issue. It is part of the organisation’s protective security posture.


Reporting is not accusation, and management response matters


This is where many organisations can improve. They assume that if there is a concern, someone will report it. That assumption is dangerous because people often need cultural permission to report. They need to know that raising a concern about behaviour, welfare, security or access does not automatically mean accusing someone of wrongdoing.


A report can be about preventing harm, supporting a person, protecting the organisation or simply asking for something to be looked at. If reporting is framed only as whistleblowing or formal accusation, many people will avoid it because it feels too serious, too risky and too final. If reporting is framed as a responsible way to raise a concern, seek support and protect people, it becomes more usable.


Management response then determines whether trust grows or disappears. In many insider risk cases, the concern does not start as a security incident. It starts as a behavioural concern or issue.


Effective managers notice these things and act early. Poor managers avoid them. When managers ignore difficult issues, teams lose trust and the organisation carries risk without properly understanding it. Reporting channels and management capability therefore need to work together. Some employees may not report through their line manager, HR or security, particularly if the concern involves one of those teams. If the only available route is the route people do not trust, silence should not surprise anyone.


The aim is not to turn every concern into a formal disciplinary process. The aim is to create a middle ground where concerns are assessed with professional judgement, proportionate escalation and joined up governance.


What organisations should do about it


The answer is not to create a suspicious workplace where everyone watches everyone else. That would be counterproductive and culturally damaging. The answer is to create a workplace where people know how to raise concerns, trust the process, and understand that early reporting can protect both the individual and the organisation.


Employees should understand what insider risk and wider security risk mean, what types of concern should be reported, and how reporting differs from accusation. Reporting routes should be standardised, accessible, simple, trusted and, in some cases, anonymous. There should be more than one route, because a single line management route will not work for every concern.


Training also matters, but it needs to be practical. Employees and managers need realistic examples, discussion based learning and scenario led training that reflects their working environment.


Organisations also need to connect the dots. HR may see welfare and conduct issues. Security may see policy breaches. IT may see access anomalies. Managers may see behavioural changes. Legal or compliance may see regulatory risk. If each function keeps its own fragment of information in isolation, the organisation may never see the full picture. Governed intelligence matters because the aim is not to create more noise or suspicion, but to build better understanding and earlier intervention.


My view

Someone looking at the security culture problem.

My view is that employee silence is one of the biggest unresolved insider risk issues facing organisations, and it is also one of the most human. Most people do not come to work intending to ignore risk. Most people do not want to see their organisation harmed and most professionals do not want colleagues to struggle or become exploited.


However, many people will still stay silent because the culture tells them to, the reporting route is difficult, unclear or untrusted, they are not sure if the issue is serious enough, someone else probably knows, or raising concerns feels harder than saying nothing.


The uncomfortable truth is that many insider incidents show warning signs before the damage is done. They are visible, but not understood. They are seen, but not reported. They are reported, but not joined up or connected. They are escalated, but not acted on. Or they are handled too late, when the organisation is already facing serious operational, financial and reputational harm.


At Insider Threat Limited®, we help organisations reduce overall risk by making it easier to identify, report and act on concerns before they become serious problems. We support organisations with trusted reporting routes, security data analysis, staff and management training, specialist consultation and fully managed insider risk services. The aim is simple: help leaders see the risks they may currently be missing, give employees safe and effective ways to raise concerns, and turn early warning signs into action before harm is done.


Every organisation has the ability to tap into its own workforce and strengthen one of its most important lines of defence. Relatively small investments in people, culture, reporting and training can move organisational risk away from being unmanaged and reactive towards something better understood, better controlled and easier to act on.


If an organisation does not know what its people are seeing day to day, it does not know what risk it is carrying.


References and further reading


This article draws on open source research, UK insider risk guidance and established behavioural science perspectives. The sources below are included for further reading and context.


Comments


bottom of page