When boards imagine espionage, they imagine an intruder. The evidence from three decades of casework points the other way: the majority of serious information loss involves a person the organisation vetted, hired, badged and trusted.
Why insiders dominate
The economics are decisive. Recruiting or pressuring someone with existing access costs a fraction of a technical operation and carries less risk of criminal exposure for the sponsor. An insider needs no device: they attend the meeting. And when a device is used, an insider is very often the placement mechanism, the contractor with after-hours access, the assistant who knows the meeting schedule, the facilities employee whose presence in the boardroom raises no eyebrows.
Insiders also defeat the perimeter logic on which most corporate security is built. Badges, firewalls and clean-desk policies all assume the threat is outside. The insider is inside every control you own.
How insiders are made
Genuinely ideological insiders are rare in commercial matters. The recruitment patterns we encounter are mundane: financial pressure quietly identified and exploited; grievance after a passed-over promotion or a disciplinary process; departure planning, where a leaver builds value for the next employer; and flattery-based elicitation, in which the target never understands they were recruited at all. Increasingly we also see the "planted" insider, a hire made at a competitor's instigation, a pattern long familiar in state espionage now visible in commercial disputes.
The common denominator is that recruitment exploits circumstances the employer could observe but does not: the signals live in HR systems, expense anomalies, access logs and behavioural change, scattered across functions that never compare notes.
What actually works
Controls that work share a property: they reduce the value of any single insider rather than trying to perfect trust. Compartmentalisation, the intelligence world's oldest control, means pricing committees, deal teams and boards operate on a need-to-know basis even internally. Meeting discipline keeps the most sensitive matters in inspected rooms with controlled attendance. Departure protocols treat the final ninety days of a sensitive employee's tenure as an elevated-risk window. And independent technical assurance, periodic TSCM inspection, addresses the insider's most durable contribution: the device that keeps listening after they have stopped attending.
When loss is suspected, sequence matters more than speed. Confronting a suspect before evidence is preserved converts a solvable problem into an unprovable one. Our response methodology exists to keep every option, employment, civil, criminal, commercial, open until the facts are in.