Nobody's coming to inspect most of you.
The Defense Counterintelligence and Security Agency inspects fewer than 40% of cleared facilities. The requirement to run a working insider threat program doesn't scale down with the oversight — it shifts the burden of proof onto you.
The regulator can't keep up. The obligation hasn't moved.
DCSA oversees the cleared industrial base — but by its own accounting it can't inspect most of it. That doesn't reduce your exposure. It shifts the burden of proof onto you, and it means gaps go unfound until something goes wrong.
Required facility inspections actually conducted
GAO, FY2025In 2023 DCSA reported it had funding to oversee only 25–30% of the cleared industrial base. By September 2025, no additional investment options had been pursued and no additional industrial security personnel had been hired.
cleared facilities under DCSA oversight, alongside roughly 5,500 classified IT systems — covering an estimated 90–95% of all classified contracts government-wide.
security reviews conducted in FY2025, producing 815 documented security violations and 1,032 open security vulnerabilities across cleared industry.
requires every cleared contractor to maintain a functioning insider threat program. Participation in recurring reviews is required to keep your facility clearance.
The violations aren't technical failures. They're people.
Look at what DCSA documented across cleared industry in FY2025. Almost none of it is a firewall problem. Nearly all of it is somebody doing the wrong thing with classified information.
815 documented security violations
A spill is a decision, not a defect
Someone moved information where it didn't belong. The control didn't fail — a person worked around it, rushed it, or didn't think.
Your tools log it after the fact
Monitoring tells you a spill happened. It doesn't tell you who was cutting corners for three weeks beforehand, and why.
The fix is human, so the program has to be
A program that only watches systems will keep producing these numbers. One that trains people to notice stops them earlier.
Big enough to carry real risk. Too lean to staff a program.
Defense, IT services & professional-services firms
Organizations holding facility clearances and federal contracts. You carry the NISPOM obligation and the audit exposure — but your Facility Security Officer (FSO) and Information System Security Manager (ISSM) are already stretched, and the program lives more on paper than in practice.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for your FSO, ISSM, managers, and security leads — the precursor framework plus a one-page escalation playbook a concern can actually travel through.
Program Readiness & Gap Assessment
2–3 weeks: document review, stakeholder interviews, process walk-through — scored against the standards DCSA assessors use, with a prioritized 12-month roadmap.
Program Advisory
A monthly advisor who knows your program inside out — mock DCSA reviews, manager training, quarterly policy and roadmap tuning as you grow.
Curious where your program actually stands?
A 20-minute call, no pitch. Tell me where you're exposed and what your contracts require — I'll tell you honestly where I'd start.
Book a 20-minute call