Skip to content
EternaEdge

Counterintelligence

The insider threat analyst was the insider

26 August 2026 · 2m read · By EternaEdge

On August 26, a former Defense Intelligence Agency IT specialist pleaded guilty to attempting to transmit national defense information to a foreign government, per the Department of Justice. Nathan Laatsch offered classified information to a foreign government by email, then dead-dropped a USB drive of Secret and Top Secret material to what turned out to be an undercover FBI agent. The detail that should stop every security leader mid-scroll: he worked in DIA's Insider Threat Division. The insider was inside the unit built to catch insiders.

Days earlier, a federal jury in Chicago convicted a former Philips Medical Systems engineer of conspiring to steal X-ray tube trade secrets for a Chinese competitor — copying proprietary technology from internal databases and recruiting colleagues as the company prepared to close his facility, per the Department of Justice. Two co-defendants had already pleaded guilty.

Two cases, one uncomfortable pattern

Different sectors, same anatomy. Both men held legitimate access. Both acted during periods of visible personal inflection — one openly disaffected, one facing a plant closure. Both were caught by external mechanisms (an FBI operation; a federal investigation), not by their organizations' internal detection. And in both cases the behavioral signals — grievance, unusual collection, outside contacts — existed well before the handoff.

Access plus inflection plus opportunity: every insider case is the same equation. The variable is whether anyone is watching it move.
  • Insider programs cannot exempt their own operators. Privileged users — security staff, IT administrators, investigators — need the same behavioral baselines they enforce on others, and the DIA case is now the permanent argument.
  • Organizational inflection points are risk windows: layoffs, closures, lost recompetes, passed-over promotions. Monitoring posture should tighten exactly when morale management says to look away.
  • The economics justify the discipline: Ponemon's 2026 research puts average annual insider-risk cost at $19.5 million per organization, up 20% in two years.

Behavioral baselines with cross-domain correlation — access patterns read beside travel, communications metadata, and open-source signals, resolved to one person over time — is the model OBSIDIAN — Counterintelligence implements, precisely because single-domain monitoring keeps missing what these cases keep showing. The determination that a colleague is a threat is among the gravest judgments an organization makes; it belongs to trained humans, working from evidence assembled early enough to matter.

Every insider conviction is retroactively obvious. The discipline is building the picture that makes it prospectively visible.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.