In the rapidly evolving landscape of cybersecurity, few challenges are as complex or as sensitive as the insider threat. Unlike external bad actors, whose movements can often be tracked via perimeter defenses and network monitoring, the insider threat represents a nuanced intersection of psychology, organizational culture, and digital access. At the heart of this critical defense strategy is Dina Atwell, Director of Cyber Insider Threat Program Management at Capital One.
In a recent episode of Security magazine’s Lock It Down podcast, Atwell sat down with Editor in Chief Rachelle Blair-Frasier to unpack her journey from a curious puzzle solver to a strategic leader overseeing a massive, high-stakes security division. Her narrative offers a masterclass in how modern enterprises are shifting from reactive security postures to proactive, human-centric risk management.
The Human Element: The Core of Modern Security
Atwell’s philosophy is rooted in a fundamental realization she made early in her 15-year career: security is not merely a technical discipline; it is a behavioral one.
"Looking back across my 15 or so years in insider threat, what has always drawn me to security is the human element," Atwell explains. For her, the "puzzle" is not just about code or infrastructure—it is about the "why." She emphasizes that understanding the motivations behind human actions—whether they are intentional acts of malice or accidental lapses in security protocol—is the most effective way to design robust safeguards.
This perspective has allowed Atwell to move beyond the traditional "policing" model of security. Instead, she advocates for a framework that combines behavioral insights with technical telemetry. By focusing on why people do what they do, Capital One’s program can implement safeguards that protect the organization without stifling the productivity or morale of its workforce.
Chronology: Scaling a Security Powerhouse
Atwell’s career trajectory is a testament to the growth of the cybersecurity sector itself. When she began her work in insider threat, the field was largely in its infancy, often treated as a peripheral concern within IT departments. Over the last decade and a half, she has been at the vanguard of transforming this function into a central pillar of enterprise risk management.
The Foundation Years
Atwell’s early career was defined by technical problem-solving. She cut her teeth in environments that required granular attention to detail, learning how to monitor user activity and establish baselines for "normal" behavior. These early years taught her that data alone is noise; context is the signal.

The Scaling Phase at Capital One
Perhaps the most impressive milestone in Atwell’s career has been her leadership at Capital One. Upon joining, she was tasked with formalizing and expanding the insider threat function. Under her guidance, the team underwent a period of rapid, strategic growth, expanding from a lean group of 12 specialists to a robust organization of 75 experts.
This expansion was not merely a matter of hiring more personnel; it was an exercise in building a diverse, multidisciplinary team. Atwell prioritized bringing in experts with varied backgrounds—ranging from data science and behavioral psychology to traditional network security. This cross-functional approach has allowed the program to address the multifaceted nature of modern insider threats, which rarely present as single-point failures.
Supporting Data: The Anatomy of Insider Risk
The industry at large supports Atwell’s focus on the "human element." According to recent cybersecurity threat reports, insider threats continue to be one of the most significant risks facing financial institutions. These risks typically fall into three categories:
- The Malicious Insider: An individual with authorized access who intentionally misuses their privileges for personal gain, espionage, or to sabotage the organization.
- The Compromised Insider: An employee whose credentials have been hijacked by an external actor, effectively turning the employee into an unwitting insider threat.
- The Negligent Insider: By far the most common category, this involves employees who bypass security protocols—often in the interest of efficiency—thereby creating vulnerabilities that can be exploited by bad actors.
Atwell’s work addresses all three by focusing on behavioral baselines. By leveraging machine learning and AI, the team at Capital One can identify anomalies in behavior that deviate from established patterns. If an employee suddenly begins accessing sensitive files they have never touched before, or if they are offloading data at unusual hours, the system triggers a review.
The goal, Atwell notes, is not to catch people in the act of being malicious, but to provide "guardrails" that prevent accidental exposure and identify potential stress points that might lead to human error.
Official Responses and Strategic Implications
The implications of Atwell’s work at Capital One extend far beyond the walls of the financial services sector. As digital transformation continues to accelerate, the "insider" definition is becoming increasingly fluid. With the rise of remote work, cloud-based infrastructure, and third-party contractors, the traditional "trusted" perimeter has effectively dissolved.
Implications for Organizational Culture
Atwell argues that security must be integrated into the culture rather than imposed upon it. Her focus on mentoring and supporting women in cyber groups is a strategic component of this. By fostering a diverse workforce, she ensures that the security team itself is not a monolith, which helps in identifying a broader range of potential risks and blind spots.

The Role of Mentorship
Atwell is a vocal advocate for the next generation of security professionals, particularly first-generation students and women looking to enter the STEM fields. She believes that the future of the industry depends on our ability to attract talent that approaches problems with curiosity and empathy. This is not just a philanthropic stance; it is a security imperative. A diverse team is more capable of questioning assumptions and identifying the subtle behavioral shifts that precede a security incident.
Conclusion: Looking Ahead
As we navigate an era where data is the most valuable asset, the insider threat will only grow in complexity. Dina Atwell’s transition from a puzzle solver to a program builder serves as a blueprint for the modern security leader. Her emphasis on the human element, combined with a commitment to scaling teams through diverse expertise, positions Capital One as a leader in proactive defense.
In our conversation, it became clear that for Atwell, the job is never "done." The security landscape is a living organism, shifting with every new technology and every new societal challenge. By keeping the human at the center of the strategy, she ensures that security remains a facilitator of business growth, rather than a barrier.
For those interested in the intricacies of threat hunting, organizational scaling, or the future of cybersecurity leadership, the full conversation with Dina Atwell is available on the Lock It Down podcast, accessible via Security magazine’s official channels or through Apple Podcasts. As the industry continues to evolve, leaders like Atwell remind us that while the tools of the trade may change, the most effective security strategy will always begin with an understanding of the people behind the keyboard.
Rachelle Blair-Frasier is Security magazine’s Editor in Chief. With over 15 years of experience in journalism and B2B editorial work, she provides deep insights into the intersection of physical security, risk management, and the human side of cyber defense.
