Understanding Beijing’s playbook can help organizations anticipate their own exposure

On August 4, Japan’s Ministry of Defense released its 2026 white paper, once again naming the People’s Republic of China (PRC) as the country’s “greatest strategic challenge.” The next day, a Chinese Foreign Ministry spokesperson said the PRC “deplores and firmly rejects” the document and had lodged a formal protest with Tokyo. That exchange was just the latest diplomatic salvo in an ongoing dispute between the two nations. That dispute found a new gear last November when the PRC launched a coordinated campaign of economic coercion against Japan. What has transpired since offers one of the clearest windows yet into how Beijing builds and escalates pressure on perceived competitors.

It is well known that the PRC’s animosity toward Japan runs deep, and that history is part of why this particular campaign escalated as fast and as hard as it did. But the playbook underneath it, the triggers that provoke a response, the tools Beijing reaches for, and the order in which it deploys them, isn’t exclusive to Japan. Understanding it is what lets other countries and companies map their own exposure before they become the next case study.

The Trigger

Beijing’s coercive campaign traces back to November 7, 2025, when Japanese Prime Minister Sanae Takaichi told Japan’s national legislature that a PRC military move against Taiwan could constitute a “survival-threatening situation” for Japan. Since the 2015 reinterpretation of Japan’s pacifist constitution, this description is the legal trigger that enables Japan’s military to act in defense of an ally under attack, not only in defense of Japan itself. By applying it to Taiwan, Takaichi signaled that Japan could respond militarily to a cross-strait conflict. 

Beijing judged that Takaichi’s remarks had crossed one of its “Four Red Lines”—issues in which the PRC “will not tolerate a challenge.” Those four lines are the “Taiwan Issue,” “Democracy and Human Rights,” the PRC’s “Political System,” and “Developmental Rights.”

Beijing responded within days, demanding a retraction and warning that Japan would “bear all the consequences.” Officials also cast the remarks as interference in the PRC’s internal affairs. Takaichi has not walked the comment back, and what has followed since is a PRC economic coercion campaign that has grown more sophisticated with each passing month.

The PRC has used economic pressure against Japan before, but never quite like this. In 2010, after a Chinese fishing trawler collided with a Japanese Coast Guard vessel near the disputed Senkaku Islands, Beijing halted rare earth exports to Japan. In 2023, it banned Japanese seafood imports over the release of treated wastewater from the Fukushima Daiichi plant, a move framed as food safety but widely read as retaliation for Japan’s support of semiconductor export controls. Both were rooted in a concrete grievance: a territorial incident and a trade dispute. This new campaign, however, began with Takaichi’s remarks on Taiwan—a matter of political alignment rather than commerce or borders. It suggests Beijing now sees its grip on critical mineral supply chains as leverage over political and security commitments, and not only as a tool for settling economic scores.

How the Pressure Escalated

Beijing is employing economic coercion as a graduated campaign that progressively increases pressure as lower-cost measures fail to achieve its political objectives. Beginning on November 14, 2025, the Chinese Communist Party (CCP) rolled out travel advisories discouraging Chinese citizens from visiting Japan, followed by education warnings, renewed seafood restrictions, and the cancellation of Japanese cultural events. Within two weeks, more than 500,000 flight tickets from mainland China to Japan had been canceled. By January 2026, Chinese visitor numbers to Japan were down more than 60 percent year-on-year. A Chinese Foreign Ministry spokesperson made clear this had nothing to do with safety or tourism policy, saying Takaichi’s comments had “gravely hurt the sentiments of the Chinese people.”

When that pressure failed to produce a retraction, the CCP moved to the tools tied to Japan’s dependence on Chinese-controlled mineral supply chains. On January 6, 2026, the PRC’s Ministry of Commerce banned the export of dual-use items to the Japanese military and for any purpose that could contribute to Japan’s military capabilities. The restricted list included several medium and heavy rare earth elements, including samarium, gadolinium, terbium, dysprosium, and lutetium, which are used in permanent magnets, semiconductors, and drones. By mid-2026, customs data reported by Japanese and Western outlets showed dysprosium and terbium oxide exports to Japan had fallen to zero.

In May, PRC authorities also detained two Japanese nationals on allegations of violating export control laws tied to rare earths. There’s no public evidence that the detentions were ordered as retaliation for Takaichi’s remarks. But the timing, coming after the export controls tightened, shows Beijing is willing to enforce its new restrictions through more than licensing decisions alone.

Building Something Durable

The PRC’s campaign comes wrapped in legal and regulatory infrastructure that can be dialed up or down for years. On January 7, 2026, China’s Ministry of Commerce opened an anti-dumping investigation into a Japanese chemical used in semiconductor manufacturing. In February, it added 20 Japanese organizations to its export control list and another 20 to an enhanced-scrutiny watchlist, including subsidiaries of Mitsubishi Heavy Industries, Kawasaki Heavy Industries, and the Japan Aerospace Exploration Agency. Both lists were expanded again on June 29, months after the original dispute, a clear indication that the campaign is actively growing.

Each mechanism functions as its own lever: export licensing, entity list designations, customs delays, anti-dumping cases. Beijing can pull any one of them harder or ease off without touching the rest, and it can describe each move publicly as routine national security or trade enforcement.

What’s Likely Next

Prime Minister Takaichi shows no sign of backing down, and neither does Beijing. Strider assesses the next phase of the PRC’s campaign will likely widen licensing restrictions on permanent magnet inputs used by civilian automotive, robotics, and electronics manufacturers, extending pressure beyond Japan’s defense-industrial base and into its broader economy. That approach would allow Beijing to keep describing its restrictions as narrowly tailored to national security, while sidestepping the costs of a comprehensive rare earth embargo, a move that would risk a coordinated response from Japan’s allies. A full embargo remains possible if the political standoff worsens, but it’s the least likely outcome absent a bigger crisis.

The Playbook Beyond Japan

U.S. and allied countries and businesses based in those countries should anticipate phased coercion campaigns similar to the one against Japan. While the PRC’s campaign against Japan is heavily influenced by the two countries’ longstanding history and Japan’s critical dependence, the logic behind it—the triggers, the tools, the order in which they’re deployed—is worth tracking.

Between 2023 and 2025, Beijing’s restrictions on gallium, germanium, and graphite were direct responses to U.S. semiconductor controls. This campaign against Japan is different: it has been linked publicly to political signaling on Taiwan, rather than trade or technology restrictions. That shift suggests China increasingly views its mineral dominance as a way to deter allied security commitments, and not only as a tool to retaliate against economic pressure.

There’s a deeper calculation behind the timing, too. Since 2022, the U.S., Japan, Australia, and the EU have all invested in mining, refining, and stockpiling alternatives to Chinese supply. If Beijing believes that diversification is inevitable, it has less reason to hold its leverage in reserve. Using it now, while it still works, may look more valuable than preserving it for later.

The economic coercion against Japan is the first clear demonstration of a toolkit Beijing has built and is willing to use again: calibrated differently depending on the target, but drawn from the same set of triggers, tools, and sequencing. Government and business leaders should take note of what is happening to Japan and begin identifying their own vulnerabilities should the PRC use the same toolkit against their organization.

How state-sponsored hacking groups are exploiting the OSS ecosystem to advance strategic objectives

On June 23, 2026, a GitHub account called Xpos587 pushed updates to several unrelated repositories within the same narrow window of time. At the time, it seemed innocuous. But weeks later, researchers at Socket, a software supply chain security firm, traced that account back to a campaign called PolinRider and linked it to North Korean state hackers. By the time Socket published its findings on July 6, the attackers had compromised more than 100 open source packages across four different ecosystems. Some of the affected code carried a backdoor—a hidden way for attackers to get back into a system later. Other packages carried an information stealer (malware designed to quietly pull data, like passwords and files, off an infected computer). Developers installed both, believing they were ordinary, run-of-the-mill packages. Socket later determined the campaign had been running since December 2025, seven months before anyone caught it.

The packages involved in that campaign were open source software (OSS): code that anyone can view, use, and contribute to, usually for free. It underpins most of the digital world, from consumer apps to the systems banks and government agencies run on. Historically, the community behind OSS operated on mutual trust, good-faith collaboration, and open exchange. Anyone could submit a change. A smaller group of maintainers decided what made it into the final product. Nobody had to prove their identity or disclose if they were contributing on behalf of an entity or a nation-state.

Strider examined this trust-based system in a report titled Lying in Wait. For organizations’ security, the report introduced what it calls a contributor-centric risk model. In addition to focusing on what the code does—and potential vulnerabilities or malicious code—the approach adds the dimension of understanding who is behind the code.

A System Built on Trust

State-sponsored hacking groups have spent years working their way into open source communities, using the same openness that makes these platforms function against them. According to Strider’s research, groups like Lazarus Group, tied to North Korea, and Cozy Bear, tied to Russia, have infiltrated software supply chains, stolen sensitive data, and run long-term cyber-espionage operations through open source platforms. GitHub, where most of the world’s open source code is hosted and where millions of developers collaborate daily, has become both a primary target and an unwitting tool for this activity.

These groups do not behave like ordinary, financially motivated cybercriminals. A typical criminal group wants a fast payout, and it will abandon an approach quickly if one isn’t coming. State-backed groups operate on a different timeline. They are directed and funded by government entities pursuing specific strategic goals, allowing them to spend years building credibility inside a project before ever putting that access to use.

A Pattern That Keeps Repeating

Strider’s report walks through several OSS incidents that show this is far from an isolated problem.

In 2024, attackers uploaded malicious packages to the Python Package Index, a central repository that millions of developers pull free code from routinely, disguising malware called JarkaStealer as regular tools and using AI chatbots to help the deception spread. Japanese cybersecurity officials attributed the attack to Lazarus Group—a hacking group linked to North Korea.

The discovery of the Log4Shell vulnerability in Log4j, a widely used logging tool that records what is happening inside an application, exposed a large number of organizations to potential attack because so many unrelated systems depended on the same piece of code. Government agencies and cybersecurity firms observed advanced persistent threat (APT) groups—government-backed hacking teams built for long-term, stealthy access—from the PRC, Iran, North Korea, and Turkey actively exploiting the flaw. The costs were enormous. Experts estimate the vulnerability cost organizations more than $90,000 in incident response support per incident, with total costs across industries reaching into the billions. One U.S. federal agency alone dedicated more than 33,000 staff hours to its response, and more than half of corporate security teams spent weeks or longer remediating the issue. Even more than four years later, 72 percent of affected organizations were still detecting active exploitation attempts.

A third approach relied on patience. An individual using the alias “Jia Tan” started contributing to XZ Utils, a popular open source data compression tool, gradually building trust within the project. In 2024, after maintaining a high level of operational security over a lengthy period and earning co-maintainer status, Jia Tan inserted a malicious backdoor into the software. The identity of Jia Tan, and the nation-state group behind the attack, have still never been identified.

Growth Without Guardrails

According to Strider’s research, OSS adoption by businesses and governments has accelerated faster than the security practices meant to protect it. The transparency, decentralized governance, and volunteer-driven collaboration that made open source successful for decades also make it vulnerable to manipulation by well-resourced groups working on behalf of adversarial governments.

Each of the incidents above followed a different path. A vulnerability in one case, a compromised package in another. But in every one, the code passed the same review process every other contribution passes, and no scan or audit caught what was happening. The attackers had spent time earning a position inside the project, and that standing let their changes go through without a second look.

Security tools have grown considerably more capable at detecting the contents of code. They often flag known vulnerabilities, suspicious patterns, and malware signatures before a package ever reaches production. But Strider’s report argues that traditional software security focuses on the code itself while overlooking the people contributing to it. A scan can tell you a package is clean. It cannot tell you who wrote it, or whether that person has ties to a government with a reason to want the code approved.

Strider built a tool called Open Source Software Search to answer exactly that question. By analyzing contributor behavior, affiliations, and activity patterns across open source platforms, the tool helps organizations uncover hidden risks that traditional vulnerability scans completely miss.

Using OSS Search, Strider examined contributors to two widely used repositories: an AI toolkit that makes it possible to run generative AI models on consumer devices and a Python library used to organize data into tree structures. In both cases, it found individuals with direct ties to sanctioned entities and state-backed institutions, whose contributions were embedded inside code that companies rely on every day.

Data fragmentation, adversarial nation-states, and how Strider is building the system that enables organizations to navigate the next frontier of strategic intelligence

In a world defined by the abundance of data, the scarcest resource has become clarity.

More data has been created in the last three years than in all of prior history combined, driven largely by advances in technology like artificial intelligence. Yet, insights remain scattered across domains. Information stays siloed within systems. Critical decisions are still being made from incomplete pictures, even as the raw material to complete them sits in plain sight.

This is the central intelligence challenge of our time: connecting fragmented data and translating it into actionable information in real-time. The same technologies driving this explosion of data have also given us the tools to make sense of it. Now what’s needed is an intelligence model grounded in openness, networked collaboration, and machine-speed cognition.

The Intelligence Paradox: More Data, Less Clarity

The intelligence model that carried nations through the last century was built around a simple premise: information was scarce and the side that could find it first won. Back then, the biggest challenge was collection. Intelligence apparatuses relied on information gathered through human sources (HUMINT) and electronic signals and systems (SIGINT). The side with the best spies, deepest networks, and most classified insights held the advantage. Today, that problem has inverted.

Most of the world’s data is now being created in the public domain through the mass digitization of public records, social and news media, and AI. As a result, the challenge has shifted from collection to connection. With so much information already in the open, the advantage belongs to whoever can synthesize it fastest and act with precision.

The Public-Private Divide

Traditionally, governments and the private sector have held different halves of the same intelligence map. Governments see threats through classified intelligence about foreign actors, strategic intent, and geopolitical context. The private sector sees terrain: real-time data about supply chains, innovation networks, talent flows, and operational risks. The seam between them has become one of the most consequential vulnerabilities for democratic security in a digitally networked world.

This divide has real operational consequences. Consider how sanctions work. Governments regularly sanction foreign organizations, removing their ability to conduct commerce with domestic entities. But without visibility into how sanctioned entities and their affiliates adapt—shifting ownership structures, spinning up new front companies, rerouting capital—the action is rendered largely meaningless. It’s a real-life game of Whac-A-Mole: you think you address the threat, yet it reappears under a different identity. The same dynamic plays out across export controls, investment screening, and supply chain security.

The private sector faces an equally critical gap. The bulk of the talent, technology, intellectual property, and supply chains that power democratic economies exists outside government. This makes private sector entities prime targets for adversarial nation-states executing whole-of-society campaigns to capture these assets. Yet without the strategic context that governments hold, most are navigating those threats blind.

Democracies must adopt a new economic security model by fusing collaboration and intelligence sharing across public and private domains. The competitive advantage will not come from matching the secrecy of authoritarian regimes—it will come from mastering openness.

A New Intelligence Model

The world is entering the Intelligence Age, in which power is determined by who can see clearly, decide quickly, and act with precision.

Building an intelligence model equal to this moment requires a fundamentally new approach—one built not on secrecy and silos, but on collaboration and connection. One that fosters deep cooperation between the traditional intelligence community and private-sector innovators. One that leverages cutting-edge technology and intelligence capabilities to defend against threats and ensure continued leadership in science, technology, and global security.

Open-source intelligence (OSINT) should sit at the center of this new model.

But data alone does not create insight—structure does. When powered by agentic AI that can plan, collect, and synthesize information at scale, OSINT becomes a dynamic foundation for modern intelligence. Analytical methodologies, combined with AI-driven analysis and human judgment, transform disparate signals into strategic intelligence. These frameworks clarify how nation-state actors acquire technology, move capital, recruit talent, and exploit the seams of open societies, turning complexity into context and information into decision-ready insight.

This structured approach, however, cannot operate in isolation. No single institution can see the full picture alone. But a federated system—where each entity contributes to and benefits from a shared operating picture—can. This is the other essential component of any new model: an architecture that enables trusted data exchange and AI-driven synthesis between public and private networks, bridging national security insight with economic reality.

This should be the new intelligence philosophy: connection, not classification—gaining insight from integration rather than isolation.

The System Strider Built

Strider has built the system that enables organizations to navigate the next frontier of strategic intelligence.

Strider OS is an agentic AI-native system designed to continuously ingest, process, and synthesize unstructured global data into structured outputs. In other words, an agentic data refinery. We take the fragmented, multilingual, and constantly shifting data that defines the modern risk environment and turn it into something organizations can leverage to make faster, more confident decisions. The system resolves identities across sources, maps relationships across jurisdictions, and surfaces what is relevant based on the context of the decision at hand.

Analysis that used to require weeks of skilled human effort can now be maintained as a live picture that reflects the world at the moment a decision needs to be made. The goal is clarity at the moment of decision: what matters, why it matters, and what to do next.

What This Means for Democratic Societies

The global competition for data dominance is one of the defining battles of the 21st century. The ability to collect, process, and control vast amounts of data is now critical to economic and geopolitical power. This dynamic changes everything—how organizations investigate risk, how governments analyze and share intelligence, and how societies understand the forces shaping security, innovation, and influence.

Meeting this moment demands an all-of-society approach to intelligence. That means governments, industry, and academic institutions must operate not as separate actors, but as nodes in a shared intelligence network.  They must come together to protect the talent being recruited, the technology being acquired, the intellectual property being stolen, and the supply chains being compromised.

The intelligence model for this moment must be built on data, accelerated by AI, and strengthened through collaboration across public and private domains. It will require governments and industry to master openness and finally operate from a shared picture—contributing to and benefiting from a common understanding of the landscape.

By aligning the vastness of OSINT, the speed of AI, the creativity of the private sector, and the authority of government, we can outthink and outpace closed regimes.

That is the frontier of strategic intelligence.

How remote hiring is creating new risk vectors for Western and Japanese companies

On paper, there is nothing unusual about your company’s new hire.

A remote contractor with an impressive resume of relevant experience. A credible background that passes the test. They reside in a location that doesn’t raise concern. They are exactly the kind of employee your company is looking for amid the growing demand for technical talent and the continued rise of remote work.

But beneath the surface is something far more malicious.

A fabricated identity. A borrowed work history. And a quiet connection to one of the most dangerous and authoritarian regimes in the world.

This scenario is not hypothetical.

A recent Strider report, Inside the Shadow Network, reveals how North Korean operatives, with the support of entities in the People’s Republic of China (PRC), have successfully secured work with companies across the U.S., Japan, and Western nations. By operating under false—or sometimes stolen—identities and posing as freelance developers or engineers, these operatives have led targeted efforts to:

This threat points to an alarming new reality: the global talent market itself is being weaponized by adversarial nation-states to advance objectives.

The Global Talent Market Has Become a Strategic Battleground

We have entered a new geopolitical moment.

Industry and academia have now joined governments on the frontlines for this global battle for technological and data superiority. Supply chains and the global talent market have become part of the terrain.

This shift has fundamentally changed where risk resides for Western and Japanese companies, making it harder to separate legitimate business activity from state-directed operations. Instead of attacking systems from the outside, state actors are finding ways to embed themselves within global systems, using ordinary commercial activity to pursue strategic goals with less visibility and greater reach.

The rapid normalization of remote work has accelerated this threat. Distributed teams have expanded access to talent, scaled technical capacity, and accelerated growth across industries. At the same time, they have created new opportunities for nefarious actors to exploit unsuspecting organizations and plant insider threats. As a result, the line between innovation and infiltration has never been thinner.

One recent case brings this into sharper focus. Last year, a woman from Arizona was sentenced to more than eight years in prison for running a laptop farm that helped North Korean operatives gain employment at over 300 U.S. companies. Over the span of three years, she helped North Korean operatives steal the identities of U.S. citizens, pose as remote IT workers, and illegally funnel more than $17 million back to the DPRK government.

This case reflects a broader pattern of remote hiring fraud tied to North Korea already identified by U.S. authorities.

U.S. government investigations have uncovered fraud campaigns carried out by North Korean operatives that span years and continents. According to the U.S. Department of the Treasury, up to 90 percent of the earnings generated through these schemes were then funneled back to the North Korean government, where they were used to support weapons of mass destruction and ballistic missile programs.

In response, U.S. authorities have escalated enforcement efforts. New sanctions have been imposed by the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) targeting multiple individuals and entities involved in this scheme. Meanwhile, the FBI and U.S. Department of Justice continue to release indictments and public service announcements to increase awareness about these schemes and the importance of due diligence in the hiring process.

This isn’t Happening in Isolation

These schemes are not confined to a single country or actor. They are part of a broader illicit ecosystem that provides the infrastructure and support needed to operate across borders and markets.

As detailed in Strider’s report, many of the DPRK operations uncovered in U.S. government indictments and sanctions involve facilitators and front companies based in the PRC, where North Korean operatives often reside and access the global internet. These PRC-based intermediaries allow access to digital platforms, payment systems, and employment marketplaces, creating a cross-border infrastructure that helps North Korean operatives to work outside the DPRK while obscuring their true origins.

But the DPRK is not the only actor exploiting this dynamic. Strider’s research also found cases of remote workers from the PRC, India, and Pakistan using fake identities, fabricated work histories, and falsified credentials to secure roles inside Western and Japanese companies.

In a world increasingly reliant on remote work and globalized talent pools, this activity is no longer a fringe risk or a series of isolated incidents. It is being normalized by state actors to infiltrate the global talent market and exploit business as usual.

Conclusion

This challenge reflects a major shift in the threat landscape Western and Japanese companies now operate in. Geopolitics have become an integral part of global business operations, particularly in how companies source their talent.

Understanding how these fraudulent worker schemes take shape inside hiring pipelines—how identities are constructed, how roles are secured, and how activity is sustained across borders—is critical for business leaders to secure their company from the inside.

In today’s evolving geopolitical landscape, with ever-increasing risks to organizations’ critical assets and innovation, it’s critical that leaders understand the maturity of their organization’s insider threat program. Policies may exist, but are they being consistently applied? Detection measures may be in place, but do they actually work against modern adversaries and threats? And perhaps most importantly: how does your insider threat program compare to industry peers?

To help security leaders answer these questions, Strider has developed the Insider Threat Readiness Evaluation—a first-of-its-kind tool designed specifically for CISOs, security professionals, and risk executives who need a clear picture of their organization’s readiness against insider risk.

Assess Your Program’s Maturity with Strider’s “Insider Threat Readiness Evaluation”

Nation-state actors are constantly shifting tactics. Instead of relying solely on cyber intrusions, they are increasingly targeting anyone in an organization who may have legitimate access to sensitive data. Insider risk is a primary tool for intellectual property theft, economic espionage, and reputational damage.

Operating reactively, responding to incidents after the fact rather than proactively preventing them, leaves an organization vulnerable to insider threats. Strider’s “Insider Threat Readiness Evaluation” (ITRE) provides a structured, evidence-based way to identify where your organization stands today. It allows security leaders to:

The ITRE evaluates your organization across a 24-point maturity model, broken into three phases:

Initial (0–9): Insider threat policies are missing, incomplete, or inconsistently applied. Organizations in this phase lack standardized processes, making them vulnerable to even basic threats.

Defined (10–18): Programs exist and are repeatable but may not be consistently enforced. Security leaders in this phase have laid the foundation but need to strengthen execution.

Optimized (20–24): Insider threat management is embedded in the organization’s culture and operations. These organizations proactively adapt to evolving risks and set the standard for resilience.

At the end of the assessment, you’ll receive a personalized readiness report that includes:

Why CISOs and Security Leaders Should Take the Assessment

The ITRE is designed to go beyond surface-level metrics. It doesn’t just tell you whether you have an insider threat program—it measures the depth, consistency, and effectiveness of that program.

For CISOs, this insight is invaluable in several ways:

Boardroom Readiness: Provides a data-driven snapshot you can share with executive leadership and boards of directors.

Strategic Road mapping: Highlights where investment and resources will have the greatest impact.

Operational Focus: Clarifies which policies, training, and detection measures need improvement today.

Competitive Benchmarking: Positions your security posture against peers to show whether you’re leading, lagging, or aligned with industry standards.

Most importantly, the report is designed to be actionable. It doesn’t stop at scoring—it provides concrete steps to strengthen your insider threat defenses in the near term and over time.

If you’ve ever wondered whether your program is prepared to handle the threats of tomorrow, this is your opportunity to find out.

Take the Insider Threat Readiness Evaluation now:

By: Padrick Doyle, Chief Information Security Officer, and Victor Vichith, Sr. Manager of Insider Risk, Strider Technologies

Insider Threat Awareness Month serves as a reminder that many significant risks to organizations come from within. Strider’s strategic intelligence empowers organizational leaders across industry, government, and academia to safeguard their most critical assets and innovation from state-sponsored threats—both from within the organization and from external relationships.

“Insider Risks” and “Insider Threats” are not new concepts (these terms are synonymous). In addition to protecting their company’s intellectual property and assets, insider threat teams are also responsible for protecting employees and the important work they do. All full-time employees, contractors, and trusted partners have access to sensitive material and therefore carry the shared responsibility to protect critical technology and information pertaining to their organization. Sensitive material is not just an organization’s IP and employee personnel records—it also includes any material that is considered business confidential or information that is not publicly available.

Threats constantly evolve as technology becomes more sophisticated. Today’s insiders are motivated by ideology, financial gain, and coercion. Regardless of whether the threat event was done deliberately or carelessly, the consequences may be catastrophic.

Industry reports indicate that 60%-80% of organizations experienced an insider threat in the past year. This risk is amplified by nation-state actors focused on acquiring sensitive technology and trade secrets in sectors like aerospace, defense, life sciences, and semiconductor manufacturing.

To best protect our own organization, Strider constantly evolves its Insider Risk Program to identify risk behaviors and actions that serve as indicators for vulnerabilities that may be exploited by foreign governments to exfiltrate intellectual property or other sensitive information.

A Culture of Vigilance

Mitigating insider threats and risks demand an organization-wide culture of trust, transparency, and shared responsibility. A resilient insider threat program rests on four pillars:

People and Trust

People are the heart of every company; therefore, every insider risk program requires a culture of trust. Employees are the first line of defense. Building a culture of trust means fostering an environment where individuals feel valued, supported, and responsible for the mission.

Open communication, consistent leadership engagement, and strong ethics empower employees to speak up when they notice concerning behaviors. Organizations can reinforce trust by encouraging early reporting, reducing fear of retaliation, and creating a climate where security is seen as a shared goal—not a burden.

Education and Awareness

Awareness is essential, but it must go beyond one-off trainings or compliance checklists. Education around insider threats should be continuous, relevant, and tailored to the roles and responsibilities of the workforce.

Strider advocates for scenario-based training that addresses real-world insider threat cases, including insider activity linked to foreign adversaries. Trainings should highlight behavioral red flags, potential coercion tactics, and ethical dilemmas, which helps employees recognize subtle risks before they escalate. Education must also emphasize positive reinforcement, empowering employees to act and feel ownership in protecting the organization.

Technology and Tools

Technology plays a critical role in identifying insider threats. Modern insider threat programs should transparently incorporate tools for user activity monitoring, behavioral analytics, and anomaly detection that respects privacy while enabling visibility into risk.

Strider’s capabilities proactively combine open-source intelligence and behavioral signals to identify strategic insider threats. While technology detects technical anomalies, it’s the human-centric indicators like anomalous patterns, historic violations, or changes in behavior that provide the context. Tools deployed responsibly and transparently create a safety net that augments human judgment without eroding trust.

Evaluation and Feedback

Threats evolve, organizations change, and mitigation strategies must adapt in kind. Regular evaluation through red teaming (a practice where a team of experts simulates real-world attacks on an organization’s systems and defenses to identify vulnerabilities and improve security), risk assessments, and post-incident reviews ensures security controls remain relevant and effective.

Employees at each level of the organization need a voice in how insider threat policies are implemented. Anonymous reporting tools, feedback surveys, and after-action debriefs help organizations refine their approach and uncover blind spots. Treating insider threat defense as an ongoing learning process enables organizations to build resilience.

Looking Ahead: From Awareness to Action

Insider Threat Awareness Month is a call to action. We encourage organizations of all sizes to assess their exposure, revisit their insider threat programs, and engage with trusted partners to strengthen their defenses. Together we can safeguard innovation, economic competitiveness, and national security.

Insiders have the advantage. They understand the systems, culture, and weaknesses. Armed with a culture of vigilance and trust, consistent training, and the appropriate tools and policies, organizations can take back their power.

Within organizations, everyone has a role to play when it comes to mitigating insider risk. And the more we understand the threat within, the better prepared we are to defend what matters most.

Understanding the Hidden Risks Within Your Organization

September is National Insider Threat Awareness Month, a timely reminder that not all security risks come from external hackers. Some of the most damaging incidents originate inside an organization—whether through negligence, malice, or simple human error.

Understanding what an insider threat is, recognizing the warning signs, and building a strong insider threat management program are essential steps for every organization to protect itself from threats—from nation-states actors or others.

In this post, we’ll break down the fundamentals of insider threats, including:

What is an Insider Threat?

An insider threat refers to a security risk that originates from within an organization. Unlike external attackers, insiders already have some level of trusted access to company systems, data, intellectual property (IP), or facilities—as well as knowledge of business processes, company policies or other information that would help carry out such an attack. This makes insiders uniquely dangerous, as they can bypass traditional perimeter defenses and exploit their access for malicious or unintended purposes.

But not all insider threats are driven by malice. In fact, many incidents arise from negligence, simple mistakes, or a lack of awareness. An employee who clicks on a phishing email, reuses weak passwords, or mishandles sensitive files can unintentionally create the same level of risk as someone acting with hostile intent. Leaders recognizing this broader spectrum of insider threats is essential to ensuring the security of their organization.

Why Insider Threats Matter

Organizations often spend millions of dollars fortifying their external defenses against cyberattacks, deploying firewalls, intrusion detection systems, endpoint security, and advanced authentication protocols to keep bad actors out. Yet insiders—who are already inside the walls—represent a different class of risk. They have context, privileged access, and the ability to bypass defenses that would stop most outsiders.

In many cases, insider threats remain undetected—and thus uncontained—for longer periods than external attacks. According to a recent report, organizations took an average of 81 days to contain an insider incident (compared to an average of 73 days to contain an external attack) and spend on average $17.4 million annually on activities to resolve these events.

The stakes are high—insider threats can result in:

For many organizations, insider threats represent the most difficult and costly category of risk to manage.

Types of Insider Threats

Another challenge is that insider threats are not one-size-fits-all. Organizations should be aware of several distinct categories:

  1. Departing Employees
    Employees leaving the company voluntarily or involuntarily are among the most common insider threats. They might take materials they’re proud of to help land a new job or, more viciously, steal and expose sensitive data out of revenge.

    Example: In 2024, Meta filed a lawsuit against a former vice president of infrastructure who allegedly uploaded a trove of highly sensitive internal documents—including Meta’s “Top Talent” compensation dossier—to his personal Google Drive and Dropbox just before leaving to join an AI startup.

  2. Malicious Insiders
    These are employees or business partners who intentionally cause harm. Motivations often include financial gain, revenge, or loyalty to a competing organization or nation-state. This can also include individuals affiliated with a criminal group or act on behalf of political, social, or activist causes. Additionally, malicious insiders could be privileged users, such as system administrators, who abuse elevated permissions for personal gain or retaliation.

    Example: In 2008, a former Intel design engineer stole trade secrets related to the Itanium microprocessor and transferred them to rival AMD. Intel estimated the value at between $200 million and $400 million. Pani pleaded guilty in 2012 and was sentenced to three years in federal prison.

  3. Negligent Workers
    These are well-meaning employees who inadvertently create risk through carelessness or poor cybersecurity hygiene. This could include clicking on phishing emails, mishandling sensitive data, or using weak passwords.

    Example: In 2017, Boeing notified its employees of a data breach after an employee emailed a spreadsheet to his wife (who was not an employee) hoping she could help him resolve formatting issues. Unbeknownst to the employee, by bypassing security protocols and sending the spreadsheet to both an unsecured device and a non-employee, he compromised the employee ID, place of birth, and social security numbers of approximately 36,000 coworkers, which were located in “hidden” columns of the spreadsheet.

  4. Compromised Insiders
    These individuals have had their accounts or credentials hijacked by external attackers—whether through social engineering, phishing campaigns, credential stuffing, malware, or brute-force attacks—and are then used as unwitting entry points into the organization. This can also include insiders who have been manipulated or coerced into sharing information without realizing the consequences.

    Example: In 2020, Twitter employees were targeted in a coordinated social engineering campaign. Attackers manipulated insiders to gain access to internal admin tools, enabling them to hijack high-profile accounts.

  5. Third-Party Insiders
    Contractors, vendors, and partners who have access to corporate resources can also pose insider threats. Their security practices may not align with the organization’s standards, making them an attractive entry point for attackers. Additionally, threats from third-party insiders could include contractors with divided loyalties, who may be balancing obligations to your organization with ties to another outside entity.

    Example: In the Target breach of 2013, attackers gained access to Target’s network by compromising the credentials of a third-party HVAC vendor. This foothold ultimately allowed them to steal payment information from over 40 million customers, illustrating how weak vendor security can have massive downstream consequences.

Understanding these types of insider threats helps organizations tailor their defenses appropriately.

Insider Threat Indicators

Detecting insider threats early is challenging but critical. Some common insider threat indicators include:

While these indicators don’t always signal malicious activity, taken together they can paint a picture of elevated risk. Modern insider threat programs rely on behavioral analytics and AI-driven monitoring to connect these dots in real time.

What is the Goal of an Insider Threat Program?

Every organization should establish a structured approach to mitigate insider risks. But what is the goal of an insider threat program?

At its core, the goal is to protect sensitive data, intellectual property, and operations from insider-driven harm while balancing privacy and trust within the workforce. More specifically, an insider threat program aims to:

  1. Identify: Detect potential risks and suspicious behavior early.
  2. Mitigate: Reduce vulnerabilities through training, monitoring, and access controls.
  3. Respond: Take swift action to contain and remediate incidents.
  4. Deter: Foster a culture of security awareness to discourage malicious intent.

In practice, this means implementing both proactive and reactive measures—ranging from user training and policy enforcement to automated detection tools and incident response playbooks.

Insider Threat Management: Best Practices

Effective insider threat management requires a multi-layered approach that combines technology, processes, and people. Here are some proven best practices:

  1. Implement Least Privilege Access
    Limit user access to only the data and systems they need for their role. Regularly review and adjust permissions.
  2. Monitor User Behavior
    Use behavioral analytics and security information and event management (SIEM) tools to detect unusual activities.
  3. Conduct Regular Training
    Educate employees about security best practices, phishing awareness, and data handling responsibilities.
  4. Establish Clear Policies
    Define acceptable use, data sharing, and reporting protocols. Make sure employees understand consequences for violations.
  5. Secure Third-Party Access
    Vet vendors and contractors carefully, and enforce strict controls on their access.
  6. Encourage a Speak-Up Culture
    Create channels for employees to report suspicious behavior without fear of retaliation.
  7. Leverage Threat Intelligence
    Integrate insider threat programs with external threat intelligence to spot patterns that may indicate targeted recruitment of insiders by adversaries.
  8. Perform Continuous Risk Assessments
    Insider threat management is not static. Regular assessments help organizations adapt as roles, technologies, and business processes change.

Insider Threat Prevention: Building a Security-First Culture

While technology and monitoring tools are essential, the most effective insider threat prevention strategy is fostering a culture of security.

Prevention is about empowering people as the first line of defense, not just treating them as potential risks.

Lessons Learned from Insider Threat Cases

The real-life examples throughout this article highlight several critical lessons for organizations:

Insider threats are not a hypothetical risk—they’re a proven danger to organizations across all industries. From contractors leaking classified intelligence to employees mishandling sensitive data or vendors leaving a back door open, these incidents show how devastating the consequences can be.

Understanding insider threats, how to identify insider threat indicators, and how to apply robust insider threat management and prevention strategies is no longer optional—it’s a business imperative. By implementing least-privilege access controls, enforcing rigorous vendor oversight, investing in user awareness training, and leveraging advanced monitoring tools, organizations can significantly reduce their exposure.

Ultimately, an insider threat program’s goal is not only to detect and stop malicious actors—but also to create a culture of security where every individual plays a role in protecting the organization. The organizations that succeed will be those that combine people, processes, and technology into a proactive defense strategy—one that adapts as quickly as the threats evolve.

Russia launched its full-scale invasion of Ukraine on February 24, 2022, initiating one of the largest conflicts in Europe since World War II. This war, which has lasted far longer than many experts anticipated, has led to widespread international condemnation and a significant humanitarian crisis.

Over the past three years, Russia’s technology sector has fallen behind, and the Kremlin is now resorting to increasingly nefarious tactics to close the gap and achieve “technological sovereignty”—its ability to develop, control, and maintain its own critical technologies and technological infrastructure without relying on foreign countries or multinational corporations. 

This concept has gained increasing importance for Russia, especially in the context of geopolitical tensions, economic sanctions, and its efforts to insulate its economy and national security from external influence.

In this article, we’ll talk about the drivers behind Russia’s technological stagnation, four areas where they’re adapting their tactics, and the steps your organization can take to protect your own technology. 

For a deeper dive, though, download “Navigating the New Geopolitical Reality”—a comprehensive white paper written by Strider’s Global Intelligence Unit about Russia’s evolving strategy.

Russia adapts economic espionage tactics in Europe

Its ongoing war with Ukraine has been devastating to Russia’s technology sector, which continues to lag further behind the West.

As a result, Russia is adapting its strategies to navigate economic isolation and sustain its technological edge. This includes a growing reliance on individuals operating under non-official cover—such as oil and gas workers, professors, and other professionals—who may utilize social media platforms like LinkedIn to connect with targets in Europe and the United States.

This means that private companies are now being subjected to greater risk from Russia and other adversarial nations.

The Kremlin ramps up reverse-engineering efforts

After Russia invaded Ukraine, many firms chose to close up shop in Russia and move elsewhere. Likely as a form of retribution against those firms, Russian president Vladimir Putin directed the government to use funds from the “exit tax” imposed on foreign companies leaving Russia to finance reverse-engineering initiatives.

As a result, since 2022, the Russian government has funneled at least $110 million USD into projects focused on imitating Western-made products. This push toward imitation technology has raised concerns that foreign companies may face increased competition from Russian knockoffs in markets favorable to Russia, such as India. 

The Russian government is seeking to reverse engineer hundreds of products manufactured by leading American and European companies, including integrated circuits, chemical compounds, automotive parts, and engines, and weapons systems.

Russia leverages relationships for “gray zone” operations

“Gray zone” activities—such as arson, attempted bombings, vandalism, cyberattacks, propaganda and misinformation, territorial encroachment, and other disruptive actions—generally fall between traditional states of peace and war. These actions, in which Russia has been heavily involved, are often ambiguous, covert, or non-traditional, designed to achieve strategic objectives without crossing thresholds that would typically provoke a formal military response or war.

The Russian government has reportedly been analyzing online profiles of individuals in Europe to identify those who may be susceptible to manipulation by the Kremlin—and then using them to target infrastructure and organizations (especially those providing support to Ukraine) as part of a broader campaign intended to create chaos and undermine NATO and EU cohesion. 

The European Union has increased export prohibitions in an attempt to punish Russia for evading sanctions 

Starting in January 2025, new prohibitions on exports to Russia will raise compliance burdens and risks for businesses based in the European Union (EU).

Since the war started in 2022, the EU and its allies have implemented hundreds of sanctions aimed at limiting Moscow’s access to foreign technology necessary to sustain the war. These sanctions, however, are notoriously difficult to uphold, and third-party countries continue to play a key role in helping Russia evade them. According to Ukraine’s military intelligence agency, there has been no significant change in the flow of foreign components to Russia.

Read more about how companies with ties to Russia—including some within Ukraine—pose a risk to Western organizations.

What can you do to mitigate risk for your organization?

This complex environment requires more than traditional due diligence or surface-level risk assessments. Organizations must have a comprehensive understanding of how state actors—like Russia—manipulate supply chains, leverage global networks, and exploit access to sensitive technology.

Strider’s Organizations Search provides unparalleled visibility into complex supply chains, uncovering hidden connections to state-sponsored actors and high-risk entities. This is especially critical in the context of Russia’s evolving tactics to acquire foreign technology despite extensive sanctions.

When it comes to your company’s research through open collaboration, who can you trust? 

(It’s a big question, we know.)

America’s research enterprise continues to deliver immense benefits for our health, economy and national security—but it’s under attack.

Eric Lander, former director of the White House Office of Science and Technology Policy (OSTP), explained the importance of having strong national R&D programs. 

“We’ve led the world for two key reasons: because we invest heavily, and because we do science openly,” he said. “This openness matters a great deal—and there’s strong bipartisan support for it.”

Doing science openly leads to several positive outcomes:

Mr. Lander also added a warning:

“It has become clear, though, that some foreign governments, including the Chinese government, are working vigorously to illicitly acquire, and in some cases outright steal, U.S. research and technology. There have been efforts to induce American scientists to secretively conduct research programs on behalf of foreign governments or to inappropriately disclose non-public results from research funded by U.S. government sources. Such threats are real, serious, and completely unacceptable.”

Which brings us back to the initial question: Who can you trust?

In this article, we’ll take a high-level look at the specific threat from the People’s Republic of China (PRC) and other more general security threats—as well as ways to protect yourself against those risks. For an in-depth review of these topics, check out our free white paper: Securing the Future of Academic Research.

Combating the threat from the PRC government

China has been vocal about seeking to advance its technological capabilities through international collaboration and research partnerships (such as its “Made in China 2025” initiative). It’s important, however, to read its statements with a healthy dose of skepticism, because the Chinese government is also known to target any person from any national origin who has expertise in a field that it deems necessary for self-reliance and national strength.

Consider the directive from Xi Jinping, President of the PRC, for his country’s scientists to “not forget their original intention, keep the mission firmly in mind, and adhere to the supremacy of the national interest. … Science has no borders, but scientists have motherlands.” 

So while the US research enterprise thrives on openness and collaboration to add diverse perspectives and accelerate innovation, these same qualities can also make it vulnerable to exploitation by China and other foreign entities.

In 2021, the United States government took action to combat potential vulnerabilities, creating National Security Presidential Memorandum 33 (NSPM-33). This directive aims to safeguard federally funded research while still fostering international collaboration and academic freedom. 

Understanding NSPM-33

NSPM-33 provides detailed guidance for federal agencies and research organizations (such as public and private universities, national laboratories, or any private company receiving federal grants for R&D projects) on implementing these protections effectively.

Here’s a quick rundown of the most important aspects from NSPM-33:

Proactively leading the way in research security

Once you understand what the threats are and why the guidance within NSPM-33 is critical, the next step is determining how to implement practical measures to protect your research organization. Consider these recommendations:

(For more ideas on how to establish secure and compliant research partnerships, check out this recent blog post.)

As compliance with NSPM-33 becomes increasingly important, those institutions that proactively lead the charge in research security will influence best practices across the sector, ultimately shaping the future of academic research.

For a deeper dive into China’s tactics, download the full white paper—or you can book a demo now to see how Strider’s security solutions can protect your most valuable assets.

Russia’s strategies for sustaining its technological edge and navigating economic isolation have drastically shifted in recent years, particularly since the war in Ukraine.  

During our recent webinar, Navigating the New Geopolitical Reality, Strider intelligence specialists delved into the findings from our latest white paper and shared actionable insights for organizations to safeguard their operations.  

If you missed it, here are five key themes we explored. 

1. Technological Sovereignty: Russia’s Driving Ambition 

One of the central themes discussed was Russia’s pursuit of “technological sovereignty.” This concept underscores Russia’s effort to reduce its reliance on foreign technologies and talent, a challenge exacerbated by sanctions, export controls, and a significant brain drain. 

To achieve these goals, Russia has intensified efforts to recruit foreign talent, leverage academic connections, and invest in domestic reverse engineering projects. As a Strider intelligence specialist highlighted, “Russia’s push for technological sovereignty isn’t just about survival—it’s a long-term strategy to dominate key industries.” 

2. Reverse Engineering as a Strategic Pillar 

Reverse engineering emerged as a critical focus area in the discussion. Russia has been using funds from its “exit tax” on departing foreign companies to finance reverse engineering projects aimed at replicating Western technologies. These efforts, often coordinated with intelligence agencies, target industries like defense and high-tech manufacturing. 

A Strider expert noted, “The integration of intelligence services into reverse engineering projects allows Russia to weaponize this knowledge, not just for domestic use but also to compete in global markets. The partnership between Russia and Iran further amplifies the risks.” 

3. The Shift in Espionage Tactics 

Sanctions and diplomatic restrictions have disrupted Russia’s traditional intelligence networks, leading to a reliance on unconventional methods. Strider intelligence specialists explained that Russia increasingly recruits individuals already living in Europe and leverages online platforms like LinkedIn to target potential assets. This shift toward “non-official covers” has made it harder for organizations to detect and mitigate risks. 

The team emphasized that “Strider’s intelligence solutions are uniquely positioned to uncover these connections, flagging risk signals tied to individuals and entities with potential ties to state-sponsored activities.” 

4. Gray Zone Operations: Beyond Espionage 

The webinar also explored Russia’s “gray zone operations,” which encompass sabotage, vandalism, and cyberattacks targeting countries and organizations supporting Ukraine. These low-cost, high-impact tactics aim to sow fear and undermine cohesion within NATO and the EU. 

A Strider expert highlighted, “Russia’s gray zone tactics blur the lines between traditional and unconventional warfare, making it essential for organizations to stay vigilant and proactive.” 

5. Sanctions Evasion: A Persistent Challenge 

The discussion wrapped up with insights into Russia’s sophisticated sanctions evasion networks. Despite stringent export controls, Russia continues to acquire critical technologies through intermediaries in countries like China and Turkey. The upcoming EU enforcement of “No Re-Exports to Russia” clauses in 2025 was highlighted as a key development to watch. 

A Strider specialist observed, “Sanctions are like a game of whack-a-mole—just as one network is disrupted, another emerges. The private sector plays a critical role in staying ahead by conducting rigorous supply chain due diligence.” 

How Strider Can Help 

The webinar underscored the importance of leveraging strategic intelligence to mitigate risks posed by state-sponsored actors. Strider’s platform combines advanced analytics with exclusive data to provide unparalleled visibility into supply chain vulnerabilities, personnel connections, and other risk factors. 

As a Strider intelligence specialist put it, “Every organization has unique challenges, and Strider is here to help you tackle them at scale.” 

Next Steps 

For a deeper dive into these insights, we encourage you to: 

If you’d like to discuss how these themes specifically impact your organization, schedule a consultation here.  

Together, we can navigate these challenges and protect what matters most.