• ID: MT015
  • Created: 21st July 2024
  • Updated: 25th April 2025
  • Contributor: The ITM Team

Recklessness

The subject does not have a threatening motive. However, the subject under takes actions without due care and attention to the outcome, which causes an infringement.

Subsections (2)

ID Name Description
MT015.002Conformity

A subject knowingly engages in behavior that contravenes organizational policy, security requirements, or expected practice because the behavior is routinely performed, accepted, encouraged, or left unchallenged within their immediate working environment.

 

The subject does not necessarily intend to harm the organization and may understand that the behavior is formally prohibited. However, repeated observation of peers, managers, or other members of the population engaging in the same behavior without correction causes the local norm to take precedence over the formal organizational standard. The subject may therefore regard the infringement as normal, harmless, necessary, or informally permitted.

 

Conformity may be indicative of wider Behavioral Drift where repeated Deviation has progressed into Normalization across a team or population.

MT015.001Opportunism

The subject exploits circumstances for personal gain, convenience, or advantage, often without premeditation or major malicious intent. Opportunistic acts typically arise from perceived gaps in oversight, immediate personal needs, or desires, rather than long-term ideological, financial, or revenge-driven motivations.

 

Characteristics

  • Motivated by immediate self-interest rather than deep-seated grievance or ideology.
  • May rationalize actions as minor, justified, or harmless ("no one will notice," "this helps everyone," "it's not a big deal").
  • Often triggered by environmental factors such as poor oversight, operational stress, or unmet personal needs.
  • May escalate over time if not detected and corrected early.
  • Subjects often do not view themselves as "threat actors" and may retain a positive view of their organization.
  •  

Example Scenario

Senior enlisted personnel on a U.S. Navy warship collaborated to procure and install unauthorized satellite internet equipment (Starlink) to improve their onboard quality of life. Acting without command approval, they circumvented Navy IT security protocols, introducing significant operational security (OPSEC) risks. Their motive was personal convenience rather than espionage, sabotage, or financial gain.