Insider threats remain one of the most complex and consequential risks organizations face today. Unlike external cyberattacks or obvious physical intrusions, insider threats often arise from trusted individuals—employees, contractors, or research partners—who exploit their access to sensitive data, intellectual property, or systems. While not every insider threat is malicious, the potential damage is significant: intellectual property theft, reputational harm, regulatory violations, and compromised national security.

At Strider, we recognize that the insider threat challenge is no longer limited to disgruntled employees or lone actors. Increasingly, these risks are linked to state-sponsored efforts that target organizations through talent recruitment, supply chain infiltration, and research partnerships. Our products are designed to give organizations the visibility and intelligence they need to identify these risks early, mitigate vulnerabilities, and protect what matters most.

In this blog post, we’ll explore how Strider’s suite of products empowers organizations to protect against insider threats by uncovering hidden affiliations, mapping risky connections, and delivering actionable intelligence.

Understanding the Modern Insider Threat

Traditional security models focused on access control and monitoring system anomalies. While these remain important, they fall short when insiders are recruited or influenced by foreign adversaries. For example, researchers may be courted by state-backed talent recruitment programs that encourage them to transfer cutting-edge innovations abroad. Or an employee may conceal ties to a foreign military entity during the hiring process.

These risks are especially acute in sectors like defense, high tech, energy, and academia—where sensitive intellectual property is both highly valuable and highly targeted. The challenge is that many of these threats do not leave digital fingerprints in the early stages.

Instead, they are rooted in affiliations, backgrounds, and institutional relationships that require deep analysis of open-source intelligence and proprietary data.

This is where Strider’s products deliver unmatched value.

People Search: Uncovering Hidden Affiliations

When hiring, vetting researchers, or evaluating collaborators, organizations often rely on self-disclosed resumes and standard background checks. Unfortunately, these methods are often insufficient when individuals deliberately conceal foreign ties.

Strider’s People Search addresses this gap by aggregating and analyzing open-source intelligence to uncover connections to high-risk entities, such as foreign intelligence services, governments, and militaries. With this capability, organizations can:

By enabling proactive screening, People Search helps organizations ensure trust in their workforce and avoid inadvertently granting access to individuals who may pose an insider threat.

Organizations Search: Securing the Supply Chain and Partnerships

Insider threats don’t always come from direct employees. Contractors, research partners, and suppliers can serve as entry points for state-sponsored influence. Often, affiliations are hidden in complex ownership structures or through partnerships with universities and institutes that serve as fronts for foreign militaries.

Strider’s Organizations Search empowers leaders to understand these hidden relationships within their organizations. Specifically, the Organizations Search tool reveals:

For example, before entering into an academic collaboration, a university can use Organizations Search to determine whether a foreign partner has ties to a hostile nation. By making these risks visible, Organizations Search prevents insider threats from entering through seemingly trusted third parties.

Open Source Software Search: Protecting the Software Supply Chain

Insider risks also extend to the software ecosystem. With open source software now serving as the foundation of many mission-critical systems, organizations face growing exposure if contributors to their code base have risky affiliations.

Strider’s Open Source Software Search (OSS Search) screens contributors across an organization’s software supply chain. By analyzing repositories and contributor backgrounds, OSS Search uncovers:

In an era where a single compromised software library can ripple across industries, OSS Search adds a critical layer of defense against insider threats buried in code.

Insights: Strategic Intelligence for At-Risk Teams

While detection and screening are essential, insider threat mitigation also requires a proactive approach to awareness and resilience. That’s where Strider’s Insights—our advanced intelligence—comes in.

Insights provides organizations with tailored strategic intelligence about which research areas, technologies, or people are most likely to be targeted by foreign adversaries. This intelligence enables organizations to:

By shifting the conversation from reactive to proactive, Insights ensures organizations can anticipate and blunt insider threat recruitment before it succeeds.

Shield: Real-Time Detection in Digital Systems

Insider threats often communicate with foreign sponsors through digital channels, blending into the noise of everyday email and network traffic. To help organizations spot these signals, Strider developed Shield.

Shield delivers a curated, expert-verified dataset of high-risk email addresses, domains, and multilingual keywords associated with state-sponsored actors. Integrated via API into an organization’s SIEM or DLP system, Shield enables:

By integrating Shield into existing systems, organizations gain a powerful capability to detect when insiders are engaging with adversarial entities.

Building a Comprehensive Insider Threat Defense

The insider threat problem is multi-faceted: it spans people, partnerships, software, and communications. Strider’s holistic approach ensures that organizations can address these risks from every angle:

Together, these tools give organizations the visibility and intelligence to detect risks early, respond decisively, and stay compliant with regulations. More importantly, they empower leaders to safeguard their people, technology, and intellectual property from insider threats driven by state-sponsored actors.

Spark, Strider’s proprietary AI engine, is layered onto each existing product. With Spark, organizations have the ability to security integrate internal DLP data with Strider’s AI risk intelligence for deeper, data-driven risk insights. It also features an intuitive chat interface with real-time analysis and query, suggested searches, multilingual data input, and sourcing for original intelligence sources.

Insider threats will never be fully eliminated—but they can be managed. The key is understanding that these risks are not random but often deliberate, coordinated efforts by nation-state actors. By shining light on hidden affiliations, risky partnerships, and subtle recruitment efforts, Strider helps organizations take back control.

With Strider’s products, insider threat protection becomes less about suspicion and more about clarity. Organizations gain the confidence to collaborate, innovate, and grow—knowing they are protected by intelligence built for the modern era of geopolitical competition.

In today’s evolving geopolitical landscape, with ever-increasing risks to organizations’ critical assets and innovation, it’s critical that leaders understand the maturity of their organization’s insider threat program. Policies may exist, but are they being consistently applied? Detection measures may be in place, but do they actually work against modern adversaries and threats? And perhaps most importantly: how does your insider threat program compare to industry peers?

To help security leaders answer these questions, Strider has developed the Insider Threat Readiness Evaluation—a first-of-its-kind tool designed specifically for CISOs, security professionals, and risk executives who need a clear picture of their organization’s readiness against insider risk.

Assess Your Program’s Maturity with Strider’s “Insider Threat Readiness Evaluation”

Nation-state actors are constantly shifting tactics. Instead of relying solely on cyber intrusions, they are increasingly targeting anyone in an organization who may have legitimate access to sensitive data. Insider risk is a primary tool for intellectual property theft, economic espionage, and reputational damage.

Operating reactively, responding to incidents after the fact rather than proactively preventing them, leaves an organization vulnerable to insider threats. Strider’s “Insider Threat Readiness Evaluation” (ITRE) provides a structured, evidence-based way to identify where your organization stands today. It allows security leaders to:

The ITRE evaluates your organization across a 24-point maturity model, broken into three phases:

Initial (0–9): Insider threat policies are missing, incomplete, or inconsistently applied. Organizations in this phase lack standardized processes, making them vulnerable to even basic threats.

Defined (10–18): Programs exist and are repeatable but may not be consistently enforced. Security leaders in this phase have laid the foundation but need to strengthen execution.

Optimized (20–24): Insider threat management is embedded in the organization’s culture and operations. These organizations proactively adapt to evolving risks and set the standard for resilience.

At the end of the assessment, you’ll receive a personalized readiness report that includes:

Why CISOs and Security Leaders Should Take the Assessment

The ITRE is designed to go beyond surface-level metrics. It doesn’t just tell you whether you have an insider threat program—it measures the depth, consistency, and effectiveness of that program.

For CISOs, this insight is invaluable in several ways:

Boardroom Readiness: Provides a data-driven snapshot you can share with executive leadership and boards of directors.

Strategic Road mapping: Highlights where investment and resources will have the greatest impact.

Operational Focus: Clarifies which policies, training, and detection measures need improvement today.

Competitive Benchmarking: Positions your security posture against peers to show whether you’re leading, lagging, or aligned with industry standards.

Most importantly, the report is designed to be actionable. It doesn’t stop at scoring—it provides concrete steps to strengthen your insider threat defenses in the near term and over time.

If you’ve ever wondered whether your program is prepared to handle the threats of tomorrow, this is your opportunity to find out.

Take the Insider Threat Readiness Evaluation now:

By: Padrick Doyle, Chief Information Security Officer, and Victor Vichith, Sr. Manager of Insider Risk, Strider Technologies

Insider Threat Awareness Month serves as a reminder that many significant risks to organizations come from within. Strider’s strategic intelligence empowers organizational leaders across industry, government, and academia to safeguard their most critical assets and innovation from state-sponsored threats—both from within the organization and from external relationships.

“Insider Risks” and “Insider Threats” are not new concepts (these terms are synonymous). In addition to protecting their company’s intellectual property and assets, insider threat teams are also responsible for protecting employees and the important work they do. All full-time employees, contractors, and trusted partners have access to sensitive material and therefore carry the shared responsibility to protect critical technology and information pertaining to their organization. Sensitive material is not just an organization’s IP and employee personnel records—it also includes any material that is considered business confidential or information that is not publicly available.

Threats constantly evolve as technology becomes more sophisticated. Today’s insiders are motivated by ideology, financial gain, and coercion. Regardless of whether the threat event was done deliberately or carelessly, the consequences may be catastrophic.

Industry reports indicate that 60%-80% of organizations experienced an insider threat in the past year. This risk is amplified by nation-state actors focused on acquiring sensitive technology and trade secrets in sectors like aerospace, defense, life sciences, and semiconductor manufacturing.

To best protect our own organization, Strider constantly evolves its Insider Risk Program to identify risk behaviors and actions that serve as indicators for vulnerabilities that may be exploited by foreign governments to exfiltrate intellectual property or other sensitive information.

A Culture of Vigilance

Mitigating insider threats and risks demand an organization-wide culture of trust, transparency, and shared responsibility. A resilient insider threat program rests on four pillars:

People and Trust

People are the heart of every company; therefore, every insider risk program requires a culture of trust. Employees are the first line of defense. Building a culture of trust means fostering an environment where individuals feel valued, supported, and responsible for the mission.

Open communication, consistent leadership engagement, and strong ethics empower employees to speak up when they notice concerning behaviors. Organizations can reinforce trust by encouraging early reporting, reducing fear of retaliation, and creating a climate where security is seen as a shared goal—not a burden.

Education and Awareness

Awareness is essential, but it must go beyond one-off trainings or compliance checklists. Education around insider threats should be continuous, relevant, and tailored to the roles and responsibilities of the workforce.

Strider advocates for scenario-based training that addresses real-world insider threat cases, including insider activity linked to foreign adversaries. Trainings should highlight behavioral red flags, potential coercion tactics, and ethical dilemmas, which helps employees recognize subtle risks before they escalate. Education must also emphasize positive reinforcement, empowering employees to act and feel ownership in protecting the organization.

Technology and Tools

Technology plays a critical role in identifying insider threats. Modern insider threat programs should transparently incorporate tools for user activity monitoring, behavioral analytics, and anomaly detection that respects privacy while enabling visibility into risk.

Strider’s capabilities proactively combine open-source intelligence and behavioral signals to identify strategic insider threats. While technology detects technical anomalies, it’s the human-centric indicators like anomalous patterns, historic violations, or changes in behavior that provide the context. Tools deployed responsibly and transparently create a safety net that augments human judgment without eroding trust.

Evaluation and Feedback

Threats evolve, organizations change, and mitigation strategies must adapt in kind. Regular evaluation through red teaming (a practice where a team of experts simulates real-world attacks on an organization’s systems and defenses to identify vulnerabilities and improve security), risk assessments, and post-incident reviews ensures security controls remain relevant and effective.

Employees at each level of the organization need a voice in how insider threat policies are implemented. Anonymous reporting tools, feedback surveys, and after-action debriefs help organizations refine their approach and uncover blind spots. Treating insider threat defense as an ongoing learning process enables organizations to build resilience.

Looking Ahead: From Awareness to Action

Insider Threat Awareness Month is a call to action. We encourage organizations of all sizes to assess their exposure, revisit their insider threat programs, and engage with trusted partners to strengthen their defenses. Together we can safeguard innovation, economic competitiveness, and national security.

Insiders have the advantage. They understand the systems, culture, and weaknesses. Armed with a culture of vigilance and trust, consistent training, and the appropriate tools and policies, organizations can take back their power.

Within organizations, everyone has a role to play when it comes to mitigating insider risk. And the more we understand the threat within, the better prepared we are to defend what matters most.

Understanding the Hidden Risks Within Your Organization

September is National Insider Threat Awareness Month, a timely reminder that not all security risks come from external hackers. Some of the most damaging incidents originate inside an organization—whether through negligence, malice, or simple human error.

Understanding what an insider threat is, recognizing the warning signs, and building a strong insider threat management program are essential steps for every organization to protect itself from threats—from nation-states actors or others.

In this post, we’ll break down the fundamentals of insider threats, including:

What is an Insider Threat?

An insider threat refers to a security risk that originates from within an organization. Unlike external attackers, insiders already have some level of trusted access to company systems, data, intellectual property (IP), or facilities—as well as knowledge of business processes, company policies or other information that would help carry out such an attack. This makes insiders uniquely dangerous, as they can bypass traditional perimeter defenses and exploit their access for malicious or unintended purposes.

But not all insider threats are driven by malice. In fact, many incidents arise from negligence, simple mistakes, or a lack of awareness. An employee who clicks on a phishing email, reuses weak passwords, or mishandles sensitive files can unintentionally create the same level of risk as someone acting with hostile intent. Leaders recognizing this broader spectrum of insider threats is essential to ensuring the security of their organization.

Why Insider Threats Matter

Organizations often spend millions of dollars fortifying their external defenses against cyberattacks, deploying firewalls, intrusion detection systems, endpoint security, and advanced authentication protocols to keep bad actors out. Yet insiders—who are already inside the walls—represent a different class of risk. They have context, privileged access, and the ability to bypass defenses that would stop most outsiders.

In many cases, insider threats remain undetected—and thus uncontained—for longer periods than external attacks. According to a recent report, organizations took an average of 81 days to contain an insider incident (compared to an average of 73 days to contain an external attack) and spend on average $17.4 million annually on activities to resolve these events.

The stakes are high—insider threats can result in:

For many organizations, insider threats represent the most difficult and costly category of risk to manage.

Types of Insider Threats

Another challenge is that insider threats are not one-size-fits-all. Organizations should be aware of several distinct categories:

  1. Departing Employees
    Employees leaving the company voluntarily or involuntarily are among the most common insider threats. They might take materials they’re proud of to help land a new job or, more viciously, steal and expose sensitive data out of revenge.

    Example: In 2024, Meta filed a lawsuit against a former vice president of infrastructure who allegedly uploaded a trove of highly sensitive internal documents—including Meta’s “Top Talent” compensation dossier—to his personal Google Drive and Dropbox just before leaving to join an AI startup.

  2. Malicious Insiders
    These are employees or business partners who intentionally cause harm. Motivations often include financial gain, revenge, or loyalty to a competing organization or nation-state. This can also include individuals affiliated with a criminal group or act on behalf of political, social, or activist causes. Additionally, malicious insiders could be privileged users, such as system administrators, who abuse elevated permissions for personal gain or retaliation.

    Example: In 2008, a former Intel design engineer stole trade secrets related to the Itanium microprocessor and transferred them to rival AMD. Intel estimated the value at between $200 million and $400 million. Pani pleaded guilty in 2012 and was sentenced to three years in federal prison.

  3. Negligent Workers
    These are well-meaning employees who inadvertently create risk through carelessness or poor cybersecurity hygiene. This could include clicking on phishing emails, mishandling sensitive data, or using weak passwords.

    Example: In 2017, Boeing notified its employees of a data breach after an employee emailed a spreadsheet to his wife (who was not an employee) hoping she could help him resolve formatting issues. Unbeknownst to the employee, by bypassing security protocols and sending the spreadsheet to both an unsecured device and a non-employee, he compromised the employee ID, place of birth, and social security numbers of approximately 36,000 coworkers, which were located in “hidden” columns of the spreadsheet.

  4. Compromised Insiders
    These individuals have had their accounts or credentials hijacked by external attackers—whether through social engineering, phishing campaigns, credential stuffing, malware, or brute-force attacks—and are then used as unwitting entry points into the organization. This can also include insiders who have been manipulated or coerced into sharing information without realizing the consequences.

    Example: In 2020, Twitter employees were targeted in a coordinated social engineering campaign. Attackers manipulated insiders to gain access to internal admin tools, enabling them to hijack high-profile accounts.

  5. Third-Party Insiders
    Contractors, vendors, and partners who have access to corporate resources can also pose insider threats. Their security practices may not align with the organization’s standards, making them an attractive entry point for attackers. Additionally, threats from third-party insiders could include contractors with divided loyalties, who may be balancing obligations to your organization with ties to another outside entity.

    Example: In the Target breach of 2013, attackers gained access to Target’s network by compromising the credentials of a third-party HVAC vendor. This foothold ultimately allowed them to steal payment information from over 40 million customers, illustrating how weak vendor security can have massive downstream consequences.

Understanding these types of insider threats helps organizations tailor their defenses appropriately.

Insider Threat Indicators

Detecting insider threats early is challenging but critical. Some common insider threat indicators include:

While these indicators don’t always signal malicious activity, taken together they can paint a picture of elevated risk. Modern insider threat programs rely on behavioral analytics and AI-driven monitoring to connect these dots in real time.

What is the Goal of an Insider Threat Program?

Every organization should establish a structured approach to mitigate insider risks. But what is the goal of an insider threat program?

At its core, the goal is to protect sensitive data, intellectual property, and operations from insider-driven harm while balancing privacy and trust within the workforce. More specifically, an insider threat program aims to:

  1. Identify: Detect potential risks and suspicious behavior early.
  2. Mitigate: Reduce vulnerabilities through training, monitoring, and access controls.
  3. Respond: Take swift action to contain and remediate incidents.
  4. Deter: Foster a culture of security awareness to discourage malicious intent.

In practice, this means implementing both proactive and reactive measures—ranging from user training and policy enforcement to automated detection tools and incident response playbooks.

Insider Threat Management: Best Practices

Effective insider threat management requires a multi-layered approach that combines technology, processes, and people. Here are some proven best practices:

  1. Implement Least Privilege Access
    Limit user access to only the data and systems they need for their role. Regularly review and adjust permissions.
  2. Monitor User Behavior
    Use behavioral analytics and security information and event management (SIEM) tools to detect unusual activities.
  3. Conduct Regular Training
    Educate employees about security best practices, phishing awareness, and data handling responsibilities.
  4. Establish Clear Policies
    Define acceptable use, data sharing, and reporting protocols. Make sure employees understand consequences for violations.
  5. Secure Third-Party Access
    Vet vendors and contractors carefully, and enforce strict controls on their access.
  6. Encourage a Speak-Up Culture
    Create channels for employees to report suspicious behavior without fear of retaliation.
  7. Leverage Threat Intelligence
    Integrate insider threat programs with external threat intelligence to spot patterns that may indicate targeted recruitment of insiders by adversaries.
  8. Perform Continuous Risk Assessments
    Insider threat management is not static. Regular assessments help organizations adapt as roles, technologies, and business processes change.

Insider Threat Prevention: Building a Security-First Culture

While technology and monitoring tools are essential, the most effective insider threat prevention strategy is fostering a culture of security.

Prevention is about empowering people as the first line of defense, not just treating them as potential risks.

Lessons Learned from Insider Threat Cases

The real-life examples throughout this article highlight several critical lessons for organizations:

Insider threats are not a hypothetical risk—they’re a proven danger to organizations across all industries. From contractors leaking classified intelligence to employees mishandling sensitive data or vendors leaving a back door open, these incidents show how devastating the consequences can be.

Understanding insider threats, how to identify insider threat indicators, and how to apply robust insider threat management and prevention strategies is no longer optional—it’s a business imperative. By implementing least-privilege access controls, enforcing rigorous vendor oversight, investing in user awareness training, and leveraging advanced monitoring tools, organizations can significantly reduce their exposure.

Ultimately, an insider threat program’s goal is not only to detect and stop malicious actors—but also to create a culture of security where every individual plays a role in protecting the organization. The organizations that succeed will be those that combine people, processes, and technology into a proactive defense strategy—one that adapts as quickly as the threats evolve.

Strider is pleased to introduce Services, a new set of offerings to help private-sector organizations develop advanced economic security programs to better manage state-sponsored risks. 

Through customized, hands-on training, Services empowers security professionals to enhance their existing economic security program, utilize high-impact data and research, and increase competitiveness in a rapidly changing global risk landscape. 

Services is led by Strider expert Gunnar Newquist, who has 30 years of experience as a special agent at the US Naval Criminal Investigative Services, along with 10 years of experience working with major corporations on corporate security issues, including Deloitte and Boeing. 

Services is separated into three offerings designed to meet your organization’s current needs. Each offering can be purchased separately or can be purchased as a comprehensive package. 

Environment 

To secure your organization effectively, you need to comprehend both external and internal environments. Externally, you need to understand what foreign governments are seeking and how they get what they want. What technologies are they after? What steps do they take to get what they are after? Internally, you must understand who (i.e., employees, collaborators, or visitors) and what (i.e., specific technology, critical infrastructure, or data) are likely to be targeted.  

Services helps you to understand these two areas intimately so that you can allocate your resources strategically and be prepared to protect what matters effectively.  

Strategy  

With so many potential risks and threats in unique circumstances constantly requiring your attention, it can be easy to slip into reactive, ad-hoc security responses. Services partners with you to develop a proactive security response that works for you and your organization. It includes developing robust threat assessments, risk prevention strategies, and clear investigative plans.  

Protect proactively and clearly by having a comprehensive strategy written and processed before risks turn into threats.  

Education 

Educating your people, stakeholders, and executives in a thoughtful way not only builds trust within your organization, it also empowers employees to make wise decisions to avoid getting entangled in relationships that could hurt them and the company. 

Services provides a paradigm to educate your organization of the most pertinent information based on your audience concerning state-sponsored risk. It includes developing training materials for targeted work unit, executives, and all employees at large.  

Request a demo for Services today and see how you can better harness the full power of open-source intelligence and safeguard against state-sponsored risk.  

By Gunnar Newquist, Client Advisor at Strider 

In my years in the security industry working with both government counterintelligence programs and corporate insider threat programs, I’ve seen many programs at varying degrees of maturity. Some had experienced practitioners, a well-defined working group of stakeholders, and program members knew their responsibilities and understood the actual risk environment. Other programs had loose procedures and followed processes on a case-by-case basis. Many of the less experienced programs were driven by enthusiasm but lacked a clear threat picture. Over the years, I’ve observed three critical differences between mature programs and less mature programs: 

  1. Mature programs understand that data without context leads to more danger 
  1. Mature programs have clearly defined processes  
  1. Mature programs focus on educating their at-risk employees 

Mature programs understand that data without context leads to more danger

“False positives” is a term all too familiar to insider teams.  User and Event Behavior Analysis (UEBA) tools are effective at generating indicators of abnormal behaviors, which are indicative of insider risk. However, the UEBA tools use of risk indicators are only as effective as the actual data feed. When the UEBA data is reviewed, there is a temptation to feel the information is conclusive, when in fact the data is often limited to simple binary indicators which need to be further examined or investigated.  

For example, a certain employee has a high-risk score in a UEBA platform because they have worked unusual hours, exfiltrated a large volume of unidentified material, and expressed hostile sentiment. These combined observed behaviors are an indicator of potential risk but may not provide conclusive evidence of a policy violation or IP theft. Understanding why the employee violated policy provides valuable context. Knowing if this information has been targeted by state-sponsored actors and if the employee has any indicators of an ongoing relationship with state sponsored actors provides much needed context to understanding the actual intent and associated motivation.  

All too often when conducting a reactive investigation, investigators are looking for evidence which simply demonstrates the policy violation, and in their rush to protect the data, do not take the time to understand the employee’s motivations and intent. In some cases, the investigators do not understand or appreciate the relevance of the state-sponsor nexus. Therefore, their investigation is deemed successful as it discovered a policy violation, but the opportunity to uncover deeper damage is missed.    

Mature programs have clearly defined processes

Economic Security programs should not be run like a police homicide unit, only initiating investigations in response to discovering a dead body. Mature programs work to protect their employees at greatest risk and prioritize their focus on the technology of greatest interest to state-sponsored actors. Mature programs understand which company data needs to be protected and have repeatable and defensible processes for prioritizing their investigations.    

Repeatable: Mature programs have developed standard processes to use when triaging surfaced risk. These standardized processes prevent mistaken omissions, allow for better understanding of the threat environment, and prioritize their limited resources to focus on the incidents which could cause the greatest damage to the company. Creating an investigative response matrix to standardize investigative response utilizing such factors as “value of information at risk,” “state-sponsored interest,” “employee’s nexus to state-sponsored actors,” “violation of policy,” and “past risky behavior” creates a repeatable process which allows for more comprehensive understanding of your risk vectors.  

Defensible: Mature programs recognize that any employment action in response to the results of an investigation can result in legal action. Therefore, clear policies should be established. Having a standard investigative response process focused on identifying policy violations and gathering tangible evidence can help avoid these lawsuits and help defend the company’s actions when they inevitably occur.   

Proactive: Mature programs understand their risk environments and therefore are proactive in their efforts to prevent state-sponsored actors from stealing their intellectual property (IP). Developing a deep understanding of who the state-sponsored actors are, what they are interested in, and how they initiate relationships with targeted employees with whom they can later exploit, allows mature programs to identify this behavior in the initial stages to proactively confront their efforts and better protect their IP.     

Without established processes, mistakes are made that can end in uneven results, missed opportunities, or the appearance of unethical behavior. 

Mature programs focus on educating their at-risk employees

Mature programs understand the value of educating at-risk employees regarding the methods in which they may be approached by state-sponsored actors. Educating your people, stakeholders, and executives in a thoughtful way empowers them to make wise decisions and avoid getting entangled in relationships which could hurt them and the company. Once you understand your threat landscape, it can be shared with those at risk so they too understand it and can take defensive action. 

Providing customized briefings that clearly demonstrate what technology is being targeted and by whom resonates with the employees directly working on the technology in question. These briefings instill trust between the affected employees and the security program, resulting in a greater exchange of information. 

Informing all employees about the risks of workplace violence is important. However, security programs aimed at countering state-sponsored risk should prioritize the protection of critical technology assets and the evaluation of relationships between employees and state-sponsored entities. Mature economic security programs build customized training material for the employees directly associated with the technologies targeted by state-sponsored actors. Security teams share:  

The training material is designed and delivered in a way which instills trust and encourages employees to notify security when they suspect they have been approached. 

Conclusion
Maturing programs may not always recognize the value in gathering relevant information to get a complete understanding of intent behind the theft of IP, they may be reluctant to formalize a repeatable, defensible, and proactive strategy and they may still use generic training material when educating their employees.   

Developing an effective security program is a complex endeavor that requires time, experience, financial resources, stakeholder support, and strong leadership. Nevertheless, well-designed programs necessitate and benefit from strategic planning. Established programs place value not only on data but also on grasping the underlying motives for behavior, taking proactive measures, maintaining repeatable and defensible procedures, and fostering a culture of trust in the workplace by transparently sharing their understanding of risk with the most susceptible employees. 

According to Crunchbase, more than 90,000 workers were laid off in 2022 in the US tech sector alone.[1] With continued economic uncertainty in 2023, many organizations are continuing to consider the potential need to lay off employees and downsize their operations. This is causing employees to have anxiety concerning their employment status. 

Such anxiety will inevitably lead those with access to the organization’s valued intellectual property (IP) to consider exfiltrating it from the organization’s network to somewhere they can maintain access, if and when their employment status changes.  Most of these incidents will not be made with the intent to steal the IP, or damage the organization, but to preserve their access to the material for later referral. 

However, there will be other employees who recognize the value of the IP and will feel they are justified in maintaining access because they participated in the creation and therefore feel they deserve to reap the associated perpetual rewards. These same individuals may offer their related IP expertise to competitors during their efforts to find their next employment and want to be able to have an example of their work to share.  All of these cases represent a challenge to any organization’s Insider Team and their ability to respond to the changing conditions.

Following are the four measures that insider threat teams can proactively take to secure the organization’s IP in these challenging times. 

#1 As soon as identified, conduct enhanced monitoring of the employees who are mostly likely to be affected by layoffs. 

Studies show that half of departing employees leave with confidential company information — either deliberately or unintentionally. By determining the work units who will be laid off in advance of their notice, the insider threat teams can set up a monitoring system that will capture the affected employee’s efforts to exfiltrate data as a response to the notice. 

For this monitoring to be effective, however, the insider threat teams need to know what information is most critical to the organization, and they need to have the capacity to respond quickly to recover this material when exfiltration is detected.  

Additionally, insider threat teams need the ability to prioritize their investigative response so that they are focused on the greatest long-term risks to the organization.  While conducting enhanced monitoring of every employee exiting the organization may be possible, responding to every incident in which a departing employee has exfiltrated data will be a challenge.  

Prioritizing the response, so the insider threat teams are focused on the greatest risk, is essential to mitigating damage.

#2 Offer departing employees the opportunity to submit materials they want to take with them for a review. 

This opportunity allows the employee to consciously think of the material they want to remove from their computer hard drives, recognize that they are not allowed to make this decision independently, and give them the opportunity to obtain approval to remove non-sensitive material. 

The vast majority of departing employees will have personal items, such as family photos, tax returns, and personal correspondence that they would like to keep access to – even if the organization had prohibited the storing of personal material on their equipment all along. And while employees conduct large volume data transfers from their work computers to their home computers, it is highly likely that the organization’s valued IP will be mixed in with those personal material. By having the review process, such mix-up can be prevented. 

It is also critical when reviewing the items to determine the intent and the damage of the exfiltration, the insider threat teams look for materials that contain the organization’s Crown Jewels and for materials which are desired by competitors, including nation-state actors, as they represent the greatest potential to harm the organization.   

#3 Raise employee awareness about the organization’s governance regarding the exfiltration of data prior to announcing layoffs.

This applies to both the employees who are about to be terminated and those employees with long-term future with the organization.  The most common answer provided when an employee is questioned about unauthorized exfiltration is, “I did not know I was violating an organization policy.”  Raising the awareness for supervisors and employees is a proactive step to prevent the loss of IP and reduce the amount of unauthorized IP exfiltration. It can also be a positive message shared with employees to collectively work together to protect the organization’s future.  If this training is shared after announcing layoffs, it will be interpreted as a threat and could lead to unintended consequence of further damaging company morale and culture.

#4. Maintain awareness of which external entities could benefit from the organization’s layoffs.

Organizations can’t dictate where their laid-off employees find their next employment.  However, maintaining an awareness of which entities could benefit from the organization’s former employees is extremely valuable. 

After layoff announcements are made, the departing talent is likely to draw the attention of nation-state actors, competitors, or startup companies, looking to reap the benefits. Limiting the ability of these actors to contact and communicate with the departing employee could reduce their success.  Nation-state actors are known to guess the employee’s email addresses by utilizing a person’s name and their company’s email domain in order to establish a channel to communicate.  If successful, nation-state actors will use this method to determine the employee’s interest in future employment with one of their favored enterprises.

Conclusion

Company layoffs, real or perceived, represent a real threat to organizations’ ability to safeguard their most valued IP. Insider threat teams must implement proactive measures and processes to effectively minimize such threat.

[1] Vedantam, K. (2022, December 16). Tech Layoffs In 2022: The U.S. Companies That Have Cut Jobs. Crunchbase News. https://news.crunchbase.com/startups/tech-layoffs-2022/