The first flag is human · Cleared & federal contractors

Nobody's coming to inspect most of you.

The Defense Counterintelligence and Security Agency inspects fewer than 40% of cleared facilities. The requirement to run a working insider threat program doesn't scale down with the oversight — it shifts the burden of proof onto you.

The regulatory backdrop

The regulator can't keep up. The obligation hasn't moved.

DCSA oversees the cleared industrial base — but by its own accounting it can't inspect most of it. That doesn't reduce your exposure. It shifts the burden of proof onto you, and it means gaps go unfound until something goes wrong.

Required facility inspections actually conducted

GAO, FY2025

In 2023 DCSA reported it had funding to oversee only 25–30% of the cleared industrial base. By September 2025, no additional investment options had been pursued and no additional industrial security personnel had been hired.

12,500+

cleared facilities under DCSA oversight, alongside roughly 5,500 classified IT systems — covering an estimated 90–95% of all classified contracts government-wide.

GAO-26-107861, April 2026
4,600+

security reviews conducted in FY2025, producing 815 documented security violations and 1,032 open security vulnerabilities across cleared industry.

GAO-26-107861, April 2026
32 CFR 117

requires every cleared contractor to maintain a functioning insider threat program. Participation in recurring reviews is required to keep your facility clearance.

NISPOM Rule · DCSA SRRP, effective 1 Oct 2024
What actually goes wrong

The violations aren't technical failures. They're people.

Look at what DCSA documented across cleared industry in FY2025. Almost none of it is a firewall problem. Nearly all of it is somebody doing the wrong thing with classified information.

815 documented security violations

Cleared industry · FY2025
Data spills~60%
Improper storage11.5%
Access breach / unauthorized disclosure6.5%
Physical losses6.3%
Improper physical transfers5.6%
Source: GAO-26-107861, April 2026. A data spill is classified information appearing on an unclassified system.

A spill is a decision, not a defect

Someone moved information where it didn't belong. The control didn't fail — a person worked around it, rushed it, or didn't think.

Your tools log it after the fact

Monitoring tells you a spill happened. It doesn't tell you who was cutting corners for three weeks beforehand, and why.

The fix is human, so the program has to be

A program that only watches systems will keep producing these numbers. One that trains people to notice stops them earlier.

Who this is for

Big enough to carry real risk. Too lean to staff a program.

Cleared & federal contractors

Defense, IT services & professional-services firms

Organizations holding facility clearances and federal contracts. You carry the NISPOM obligation and the audit exposure — but your Facility Security Officer (FSO) and Information System Security Manager (ISSM) are already stretched, and the program lives more on paper than in practice.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for your FSO, ISSM, managers, and security leads — the precursor framework plus a one-page escalation playbook a concern can actually travel through.

From $3,500Founding rate $2,500 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: document review, stakeholder interviews, process walk-through — scored against the standards DCSA assessors use, with a prioritized 12-month roadmap.

From $5,500Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

A monthly advisor who knows your program inside out — mock DCSA reviews, manager training, quarterly policy and roadmap tuning as you grow.

From $3,000/mo6-month minimum
Let's talk

Curious where your program actually stands?

A 20-minute call, no pitch. Tell me where you're exposed and what your contracts require — I'll tell you honestly where I'd start.

Book a 20-minute call