On August 26, a former Defense Intelligence Agency IT specialist pleaded guilty to attempting to transmit national defense information to a foreign government, per the Department of Justice. Nathan Laatsch offered classified information to a foreign government by email, then dead-dropped a USB drive of Secret and Top Secret material to what turned out to be an undercover FBI agent. The detail that should stop every security leader mid-scroll: he worked in DIA's Insider Threat Division. The insider was inside the unit built to catch insiders.
Days earlier, a federal jury in Chicago convicted a former Philips Medical Systems engineer of conspiring to steal X-ray tube trade secrets for a Chinese competitor — copying proprietary technology from internal databases and recruiting colleagues as the company prepared to close his facility, per the Department of Justice. Two co-defendants had already pleaded guilty.
Different sectors, same anatomy. Both men held legitimate access. Both acted during periods of visible personal inflection — one openly disaffected, one facing a plant closure. Both were caught by external mechanisms (an FBI operation; a federal investigation), not by their organizations' internal detection. And in both cases the behavioral signals — grievance, unusual collection, outside contacts — existed well before the handoff.
Access plus inflection plus opportunity: every insider case is the same equation. The variable is whether anyone is watching it move.
- Insider programs cannot exempt their own operators. Privileged users — security staff, IT administrators, investigators — need the same behavioral baselines they enforce on others, and the DIA case is now the permanent argument.
- Organizational inflection points are risk windows: layoffs, closures, lost recompetes, passed-over promotions. Monitoring posture should tighten exactly when morale management says to look away.
- The economics justify the discipline: Ponemon's 2026 research puts average annual insider-risk cost at $19.5 million per organization, up 20% in two years.
Behavioral baselines with cross-domain correlation — access patterns read beside travel, communications metadata, and open-source signals, resolved to one person over time — is the model OBSIDIAN — Counterintelligence implements, precisely because single-domain monitoring keeps missing what these cases keep showing. The determination that a colleague is a threat is among the gravest judgments an organization makes; it belongs to trained humans, working from evidence assembled early enough to matter.
Every insider conviction is retroactively obvious. The discipline is building the picture that makes it prospectively visible.