While these capabilities are a necessary part of any Insider Threat program, they are insufficient for implementing a comprehensive program. These capabilities are reactive in their response to potential threats. Their focus on internal information—network logs and files accessed, for example—limits the organization’s ability to proactively prevent potential Insider Threats. Moreover, these capabilities almost entirely fall within the organization’s IT administration, meaning that they are only useful in detecting IT-related Insider Threats. These techniques do not identify employees on the verge of physical harm. And because these capabilities are reactive, they do not provide management with the knowledge required to intervene before an Insider Threat occurs. In short, these capabilities do not consider all the aspects relevant to an employee’s risk as an Insider Threat.