August 7, 2026

Economic Espionage: Mission Domain Intelligence Guide

0

Industrial espionage rarely looks like a break-in. It looks like a departing researcher, a joint venture with an unusual data annex, and a competitor product that skips five years of development.

economic-espionage-mission-domain-guide

Industrial espionage rarely looks like a break-in. It looks like a departing researcher, a joint venture with an unusual data annex, and a competitor product that skips five years of development.

What Economic Espionage covers as a mission domain

Economic espionage intelligence covers the theft or unauthorised acquisition of trade secrets, research data, designs and commercially sensitive information, whether by state intelligence services, state-directed entities, competitors or insiders. The domain spans cyber intrusion for intellectual property, insider recruitment and exfiltration, academic and research targeting, talent recruitment programmes used as collection vehicles, acquisitions and joint ventures structured to obtain technology, and open-source collection against a company's people and publications. It sits at the intersection of counterintelligence, cybersecurity, corporate investigation and export-control compliance.

Targeting follows national technology priorities: semiconductors, advanced materials, biotechnology and pharmaceuticals, aerospace, energy systems, agricultural genetics and machine learning. Collection is layered, beginning with lawful acquisition of published information, moving to relationship-building and inducement, and reaching clandestine means only when necessary. Insider threat divides into recruited insiders, self-motivated leavers taking material to a new employer, and unwitting insiders exploited through social engineering or research collaboration.

Why it matters

Losing a core technology position can be terminal for a company and strategically significant for a state, and the harm usually materialises years later as undercut pricing, pre-empted patents and lost market share. Publicly funded research is a particular target because it is open by design and thinly protected. Where technology is dual-use, national security consequences follow. Employees and academics caught in poorly run investigations suffer serious and often unwarranted career and legal damage.

What analysts actually look for

These are the concrete, observable signals that carry weight in this area of work:

  • Bulk access to design repositories, test data or customer lists by an employee within weeks of a resignation, visa change or role dispute.
  • Use of personal cloud storage, removable media or personal email for large transfers of engineering documentation outside established patterns.
  • Unsolicited approaches offering consultancy, speaking fees or research funding to named technical staff working on priority programmes.
  • Joint-venture or licensing terms demanding source code escrow, design files or resident engineer access disproportionate to the commercial deal.
  • Acquisition interest in a small supplier holding a chokepoint technology, funded through opaque intermediaries or stakes structured below review thresholds.
  • Competitor filings or product releases reproducing distinctive internal design choices, naming conventions or documented errors.
  • Spear-phishing tailored to a specific research programme, referencing conference attendance, grant numbers or unpublished paper titles.
  • Academic collaborations with one-way data-sharing obligations, or undisclosed institutional affiliations in grant and publication records.

Where the data comes from

Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:

  • US DOJ National Security Division case records — Indictments and case documents detailing tradecraft, targeting patterns and insider recruitment methods.
  • FBI and CISA advisories — Threat actor behaviour, targeted sectors and defensive guidance spanning counterintelligence and cyber.
  • MITRE ATT&CK — Structured adversary technique catalogue for mapping intrusion behaviour and measuring detection coverage.
  • USPTO and EPO patent databases — Filing timing, inventor movement and claim overlap that can evidence misappropriation of protected work.
  • CFIUS annual report and national investment screening bodies — Trends in reviewed transactions, sectors of concern and typical mitigation conditions imposed.
  • BIS Entity List and export control regulations — Restricted end users and controlled technology categories relevant to deemed-export exposure.
  • Academic publication and grant databases — Co-authorship, funding acknowledgement and affiliation data revealing undisclosed institutional relationships.
  • Corporate registries and procurement records — Ownership of acquirers, intermediaries and suppliers seeking access to protected technology.

A working method

A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:

  1. Identify the crown jewels — Define precisely which data, processes and people constitute the technology position worth protecting, because everything else is noise.
  2. Build the targeting picture — Assess who benefits, which state or competitor programmes align, and which staff, sites and partners are most exposed.
  3. Baseline normal behaviour — Establish legitimate access, transfer and travel patterns so that anomalies are measurable rather than intuitive.
  4. Correlate technical and human indicators — Combine data-loss telemetry with role changes, travel and reported external approaches, under documented governance and legal oversight.
  5. Investigate under privilege — Run the case with legal oversight, preserving forensic images and chain of custody for possible criminal or civil proceedings.
  6. Establish the transfer path — Determine whether material left via network, removable media, print, personnel movement or a contractual channel, and what reached whom.
  7. Remediate and harden — Close the specific pathway, revisit partner agreements and export classifications, and feed findings into vetting and monitoring design.

How this connects across the intelligence taxonomy

Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.

Practised with these disciplines

Worked in these data points

  • Company / Organization — A legal entity — corporation, LLC, NGO, or business.
  • Patent — An intellectual property filing granting invention rights.
  • Person / Name — A named individual — the subject of identity resolution and profiling.
  • File / Document — A file or document artifact — malware sample, leaked document, image, or email attachment.
  • Code Repository — A source-code repository — leaks secrets, reveals developers, and anchors supply-chain risk.
  • Email Address — Electronic mail address tied to an individual or organization.

Adjacent mission domains

Inside the platform: where Economic Espionage lives

The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.

The modules that matter most here:

Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.

Automation, playbooks and AI skills

Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.

Relevant playbooks

Of the 14 incident playbooks in playbooks.php, these apply directly to Economic Espionage:

  • Insider Threat Review — a step-checked workflow with the pivots, sources and handling rules already wired in.
  • APT Intrusion Analysis — a step-checked workflow with the pivots, sources and handling rules already wired in.

AI skills that apply

The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:

  • Threat Hunt
  • Correlate Infrastructure
  • Run Alert Rules
  • Summarise (Copilot)
  • Generate Report

Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.

Feeds, data sources and the API

The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.

Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:

STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.

That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.

Use cases

Three ways this entry earns its keep in day-to-day work:

  1. Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Identify the crown jewels is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
  2. Building the picture. A single indicator is rarely the story. Baseline normal behaviour turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
  3. Producing something actionable. Analysis that ends in a document nobody can use is wasted. Remediate and harden feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.

Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.

How each sector uses Economic Espionage

The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.

🎖 Military and defence

Defence organisations face economic espionage against their industrial base rather than against uniformed formations. The analytical product supports supplier and subcontractor vetting, protection of programme information held by small suppliers who lack security resources, and assessment of foreign investment or partnership proposals touching sensitive technology. It also informs personnel security, since researchers and engineers on defence programmes are systematically targeted through conferences, recruitment approaches and academic collaboration. Constraints matter: assessments about individuals feed vetting decisions with career consequences and must meet the relevant fairness standards, and analysis of allied or partner-nation entities carries diplomatic risk that requires clearance before dissemination beyond the security function.

🕵 National intelligence

This is core counterintelligence work. Requirements concern which technologies are being targeted, by which services and proxies, through which vectors, and with what success. Fusion joins cyber intrusion reporting, human reporting, travel and visa data, publication and patent analysis, corporate transaction records and insider incident data. Handling is complex because the material spans classified collection and open commercial sources, and the temptation to fuse them into a single product creates dissemination problems with industry. Priority outputs are protective advisories to affected sectors, support to investment screening decisions, and attribution assessments that can eventually support prosecution or public exposure.

👮 Law enforcement

Prosecutions for trade secret theft require proof that the information was a trade secret, that reasonable measures were taken to protect it, and that it was taken or used without authorisation. Evidence is largely digital forensic: exfiltration artefacts, cloud sync records, USB device history, email to personal accounts, and access logs inconsistent with role. Preservation must begin before the departing employee's devices are reimaged, which is the most common evidential failure. Legal process includes production orders to cloud providers and, for cross-border cases, mutual legal assistance. Charging frequently rests on the clearest artefact rather than the full scope of the loss.

🔍 Private investigation and corporate security

Corporate investigators handle insider exfiltration, departing employee matters, competitor intelligence abuse and support to trade secret litigation. The deliverable establishes what was taken, when, by whom and where it went, in a form usable in civil proceedings. A private actor may not access personal accounts or devices without authorisation, must respect employment and data protection law when reviewing employee activity, and may not conduct surveillance on individuals beyond narrow lawful limits. Employee monitoring must have a documented lawful basis and proportionality assessment, and evidence gathered outside those limits is frequently excluded and can generate a counterclaim larger than the original loss.

📰 Journalism and OSINT media

Reporting requires care to distinguish state-directed espionage from ordinary competitive hiring and from legitimate academic collaboration, a line that is routinely blurred in public discourse with real consequences for individuals. Verify technical claims with independent expertise, and corroborate attribution beyond a single company or government statement. Protect sources inside companies and universities, who face dismissal and immigration consequences. Be alert to the ethnic profiling risk inherent in this subject, and avoid framing that implies suspicion by nationality. Provide right of reply to named companies, universities and individuals, and consider carefully whether naming a researcher is justified by the evidence.

🌍 NGO, humanitarian and human rights

Civil society interest centres on academic freedom, the rights of researchers subject to investigation, and the human consequences of over-broad security responses, including documented cases of wrongful accusation. Documentation should record process failures and discriminatory patterns with the same rigour applied to security claims. Do-no-harm requires protecting researchers who may face visa revocation, deportation or prosecution, and avoiding publication that identifies individuals under investigation. Duty of care extends to staff handling cases with national security dimensions, who may themselves attract attention, and to sources within institutions where retaliation is common and career-ending.

🎓 University and research

Universities are both a target and a research subject. As a subject, work covers technology transfer mechanisms, research security policy and the effectiveness of controls. Methodology can draw on bibliometric and patent data, which is unusually rich and reproducible, and on transaction records for investment analysis. Ethics approval is required for any research involving named individuals under suspicion, given the severe consequences of exposure. Reproducibility is served by publishing bibliometric extraction code and coding rules. Researchers should declare funding sources carefully, since work in this area is frequently commissioned by parties with a policy position, and should resist nationality-based framing that the data does not support.

Playbook: working Economic Espionage end to end

A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.

Phase 1 — Identify what actually needs protecting

Establish the specific information whose loss would cause material harm: process parameters, formulations, source code, test data, customer terms, negotiating positions or research not yet published. This is a much smaller set than everything the organisation marks confidential. Map where each item lives, who can reach it and who has reached it. Output is a crown jewels register with owners and locations. Stop when the list is short enough that controls can actually be applied to it.

Phase 2 — Model the threat against those assets

Determine who would benefit from each asset and what collection routes are available to them: cyber intrusion, insider recruitment, supply chain access, academic collaboration, joint venture, acquisition, conference and recruitment approaches, or lawful open collection. Prioritise by feasibility and payoff rather than by threat actor notoriety. Output is an asset-by-vector matrix that determines where monitoring effort goes.

Phase 3 — Baseline normal access and movement

Establish what routine access, download volume, printing, external transfer and travel look like per role. Without a baseline, every insider indicator generates noise and every genuine anomaly is lost in it. This step also surfaces existing poor practice, such as widespread use of personal cloud storage, which must be fixed before monitoring can mean anything. Stop when you can state, per role, what would be unusual.

Phase 4 — Instrument the exfiltration paths

Cover the routes that matter: email to personal accounts, cloud sync, removable media, printing, screen capture, source code repository cloning, and physical removal. Ensure logging is retained long enough to cover the period between departure and discovery, which is typically months. Establish the lawful basis and proportionality for any employee monitoring before implementing it, with documented consultation. Output is a monitoring design with legal sign-off.

Phase 5 — Run the departure and life-event process

Most trade secret loss is detected around departures. Implement a consistent process: preserve devices and accounts before reimaging, review access and transfer activity for the preceding period, conduct an exit interview that establishes destination and obligations, and confirm return of material. Preservation before reimaging is the single highest-value control in the whole domain. Stop when preservation is automatic rather than requested.

Phase 6 — Assess partnerships and transactions

Review joint ventures, research collaborations, licensing agreements and investment proposals for technology transfer exposure: data annexes, site access, personnel embedding, IP assignment terms and the counterparty's ownership. Identify where a commercial agreement grants what an intelligence service would otherwise have to steal. Output is a transaction risk assessment feeding legal negotiation and, where applicable, investment screening notification.

Phase 7 — Analyse open collection against your own footprint

Examine what an adversary can lawfully assemble: publications, patents, conference presentations, procurement notices, planning applications, staff profiles and supplier announcements. Aggregate them as a collector would. This frequently reveals that the sensitive information is already public in fragments, which changes both the protection strategy and the assessment of any suspected loss.

Phase 8 — Triage insider indicators responsibly

Treat behavioural and technical indicators as prompts for a fair review process, never as findings. Establish a multi-function panel including HR and legal, apply consistent thresholds, and document decisions. Guard explicitly against nationality-based or ethnicity-based triage, which is both unlawful in many jurisdictions and analytically poor, since it generates enormous false positive volume while missing the majority of actual cases.

Phase 9 — Investigate a suspected loss forensically

Where indicators justify it, run a properly scoped forensic investigation: device imaging with continuity, cloud and email audit logs, repository access history, and correlation with travel, communications and the destination organisation's subsequent activity. Establish what was taken and what was merely accessed, since the difference determines both the legal position and the remediation. Output is a forensic report that would withstand civil litigation.

Phase 10 — Assess the harm realistically

Determine what the information is worth to a recipient: whether it materially accelerates their development, what they still lack, and whether the material is complete enough to be usable. Overstated harm assessments are common and undermine credibility with courts, insurers and boards. Stop when you can state the assessed acceleration in concrete terms rather than a headline valuation.

Phase 11 — Choose the response route

Options include civil trade secret proceedings with injunctive relief, criminal referral, contractual enforcement against a partner, export control notification, investment screening intervention, or purely internal remediation. Each has different evidential needs and different disclosure consequences, since litigation may require revealing the very secrets at issue. Output is a recommendation with the disclosure implications made explicit.

Phase 12 — Remediate and close the pathway

Fix the specific route used: access rights, repository controls, contract terms, offboarding process, or partner data handling. Then test that the fix works by attempting the same path. Feed the mechanics into the threat model for other assets. Stop when the pathway has been retested and the crown jewels register updated to reflect the new control state.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

Source register: what to collect from, and how

Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.

Source Access What it gives you How it is used here
FBI counterintelligence and economic espionage resources Open Case reporting, advisories and awareness material on trade secret theft and state-directed collection against industry. Provides documented case precedent on collection methods and the route for US law enforcement referral.
CISA advisories and guidance Open US technical advisories on intrusion activity, insider threat mitigation and critical infrastructure protection. Supplies current technical indicators and control guidance for the cyber vector of technology theft.
UK National Cyber Security Centre and NPSA guidance Open UK guidance on cyber defence, insider risk, personnel security and protecting research and intellectual property. Provides the UK protective security framework for research organisations and industrial suppliers.
MITRE ATT&CK Open Structured knowledge base of adversary tactics, techniques and procedures observed in real intrusions. Frames intrusion analysis in a common vocabulary and identifies which detections cover the observed activity.
US Department of Justice case records Open Indictments, plea agreements and press releases in economic espionage and trade secret prosecutions. Supplies detailed factual accounts of collection tradecraft and the evidential basis that succeeded at trial.
USPTO patent and assignment data Open Full patent text, applicant and inventor data, and assignment records showing transfers of rights over time. Detects filings that closely track a competitor's unpublished work and reveals ownership transfers of key IP.
WIPO PATENTSCOPE and global filing data Open International patent applications and national collections searchable across jurisdictions and languages. Identifies where equivalent technology is being filed abroad and by which entities and inventors.
Lens.org Registration Linked scholarly and patent data allowing analysis across publications, patents and institutional affiliations. Connects researchers, institutions and patent filings to identify collaboration and technology transfer patterns.
OpenAlex and Crossref scholarly metadata Open Open bibliographic data covering publications, authors, affiliations, funders and citation relationships. Maps research collaboration networks and funding relationships around a sensitive technology area.
ORCID researcher identifiers Open Persistent identifiers linking researchers to their affiliations, publications and funding over time. Resolves researcher identity across institutions and detects undisclosed dual affiliations.
OpenCorporates Registration Company registry aggregation with officers, addresses and filing history across jurisdictions. Resolves the ownership of partners, investors and acquirers proposing transactions touching sensitive technology.
ENISA threat landscape reporting Open European agency analysis of cyber threat trends including intrusion sets targeting industry and research. Provides European sector-level threat context for protective advisories and control prioritisation.
ASPI research on technology and research security Open Policy research on international research collaboration, defence-linked institutions and technology competition. Supplies institutional mapping and open-source methodology for assessing research partnership exposure.
Committee on Foreign Investment and national screening regimes Open Frameworks and annual reporting on review of foreign investment for national security implications. Determines whether a proposed transaction requires notification and what factors the screening body assesses.
NIST cybersecurity and supply chain publications Open Standards and practice guides covering security controls, insider threat and protection of controlled information. Provides the recognised control framework against which protection of sensitive information is assessed.
US Bureau of Industry and Security deemed export guidance Open Export control rules covering release of controlled technology to foreign persons, including within a home country. Establishes whether sharing technical data with a foreign national employee or partner requires a licence.

Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.

Tooling

Tools commonly used against Economic Espionage. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.

  • Data loss prevention platforms — Detect and block sensitive data leaving defined channels. Limitation: high false positive rates and easily bypassed by determined insiders who understand the rules.
  • User and entity behaviour analytics — Baselines normal access and flags deviations across accounts and systems. Limitation: needs a clean baseline period and generates unusable noise in organisations with poor data hygiene.
  • Digital forensic suites — Recover device, USB, cloud sync and file access artefacts to court standard. Limitation: requires preservation before reimaging, which is the most commonly missed step.
  • Cloud audit log analysis — Reconstructs download, share and sync activity across collaboration platforms. Limitation: default retention periods are frequently shorter than the discovery lag.
  • Patent and bibliometric analysis platforms — Detects filings and publications tracking your own unpublished work. Limitation: coincidental convergence is common in active fields, so results are leads not findings.
  • Source code repository monitoring — Flags mass cloning, unusual access patterns and public exposure of internal code. Limitation: legitimate developer behaviour resembles exfiltration closely.
  • Corporate registry and transaction research tools — Resolves the ultimate ownership of partners, investors and acquirers. Limitation: layered ownership through low-disclosure jurisdictions frequently defeats resolution.
  • Structured insider risk case management — Ensures consistent, documented and fair handling of indicators across a multi-function panel. Limitation: only prevents bias if thresholds are defined before cases arrive.

AI skills and automation in detail

These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.

  • Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
  • Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
  • Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
  • Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
  • Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.

A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • Protect a short list properly rather than a long list nominally. Organisations that classify everything as confidential cannot demonstrate reasonable measures for anything, which is fatal in trade secret litigation and useless as a control strategy.
  • The forensic case is usually won or lost in the first hours after a departure. Preserve devices and accounts before reimaging as a standing rule, because by the time suspicion crystallises the evidence has typically been overwritten by ordinary IT process.
  • Distinguish taking from accessing. Litigation and prosecution turn on what left the environment and in what form, so the artefacts of transfer, meaning sync records, device connections and outbound mail, carry the case rather than access logs alone.
  • Nationality is not an indicator and using it as one is both unlawful in many jurisdictions and analytically counterproductive. It generates enormous false positive volume, damages the trust the programme depends on, and demonstrably misses the majority of actual insider cases.
  • Aggregate your own open footprint the way a collector would. Publications, patents, procurement notices, planning applications and staff profiles frequently reconstruct the sensitive picture without any clandestine effort, which changes what is worth protecting and what is already lost.
  • Read the data annex, not the headline terms. Joint ventures and research agreements routinely grant access to precisely the information the security function is trying to protect, and the transfer is then contractual and irreversible rather than criminal.
  • Be realistic about harm. A recipient with the design still needs process knowledge, tooling, materials and yield experience, so assess the acceleration actually conferred rather than the notional value of the file, because inflated loss figures fail immediately under scrutiny.
  • Most insider loss is not recruited espionage. It is departing staff taking material they consider theirs to a new employer, and a programme designed only around hostile service recruitment will miss the overwhelming majority of actual incidents.

Measuring whether it is working

Capability claims should be falsifiable. These are the measures that show whether work on Economic Espionage is producing anything, and they are worth baselining before you change process or tooling.

  • Proportion of departures where device and account preservation occurred before reimaging, measured as a compliance rate rather than an aspiration.
  • Coverage of the crown jewels register by specific technical controls, and the number of assets with an identified but unmitigated exfiltration path.
  • Median time from exfiltration event to detection, tracked separately for technical and behavioural detection routes.
  • Proportion of insider indicators resolved through a documented multi-function panel process, with outcome consistency audited for bias.
  • Number of partnership and transaction reviews that resulted in changed contractual terms, as a measure of influence on the commercial process.
  • Rate of retested and closed exfiltration pathways following an incident, rather than count of recommendations issued.
  • Employee reporting rate of suspicious approaches, which indicates whether the security culture supports reporting or suppresses it.

Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.

Common pitfalls

  • Profiling by nationality or ethnicity, which is unlawful, corrosive to trust and empirically poor at identifying actual insiders.
  • Treating every departing employee's file copying as espionage, when most is career-portfolio behaviour, mishandled but not directed.
  • Focusing on cyber intrusion while the actual technology transfer occurs through a lawful joint venture or licensing clause.
  • Assuming technical similarity proves theft, when independent development, reverse engineering and published prior art explain most convergence.
  • Investigating an employee without legal oversight, which contaminates evidence and generates employment and privacy liability.

Legal and ethical considerations

Insider investigations engage employment law, works-council consultation, privacy rules and, in the EU, strict limits on workplace monitoring, so run them under legal privilege with a documented proportionality assessment. Deemed-export rules can make sharing technical data with a foreign national inside your own facility a controlled act. Nationality-based screening breaches discrimination law and invites litigation. Trade-secret claims require demonstrable protective measures, so evidence of your own controls forms part of the case you will need to make.

Data integrity: no fabrication, no drift, no hallucination

Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.

Provenance on every record

Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.

Nothing is invented to fill a gap

If the platform has no data for Economic Espionage, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.

Scoring is deterministic and reproducible

Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.

Where AI is used, and where it is not

Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.

Guarding against drift

Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.

What this means for you

You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.

By the numbers

The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.

This particular entry connects directly to 7 intelligence disciplines, 6 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.

Questions analysts actually ask

Is most technology loss actually espionage?

No. The majority of documented trade secret loss involves departing employees taking material to a new employer, often believing they are entitled to work they created. That is still unlawful and still damaging, but it requires a different response: offboarding process, preservation, clear contractual obligations and prompt civil action rather than counterintelligence investigation. State-directed espionage is real, serious and well documented, but a programme built solely around it will be looking for recruited agents while the routine losses go undetected. Design controls around the common case and escalate to counterintelligence handling when the specific indicators appear.

How do you avoid ethnic profiling in insider risk work?

Define indicators before you look at people and hold to them. Legitimate indicators are behavioural and technical: anomalous access relative to role, mass download before departure, transfer to personal accounts, undisclosed outside affiliations, and unreported foreign funding where disclosure is required. Nationality and ethnicity are neither necessary nor sufficient and their use has produced serious documented injustices as well as failed prosecutions. Audit outcomes for disparate impact, require multi-function review before any adverse action, and treat any triage rule that correlates with nationality as a defect in the rule.

What does reasonable measures mean in trade secret law?

It means the protective steps a court will expect before accepting that information was a secret worth protecting: identification of the specific information, access restriction on a need-to-know basis, confidentiality agreements with employees and partners, marking, technical controls on transfer, offboarding processes and evidence that the measures were actually applied rather than merely documented. The threshold is contextual and proportionate to the value at stake. The practical implication is that protecting a small identified set well is far stronger, legally and operationally, than applying broad confidentiality markings across everything.

When does academic collaboration become a security problem?

When it transfers specific controlled or commercially critical know-how without authorisation, when affiliations or funding that create obligations to another party are undisclosed, or when the collaboration provides access to facilities and data beyond its stated scope. Ordinary international research collaboration is the normal condition of science and treating it as inherently suspect damages both research and security. The workable test is disclosure and scope: are the affiliations and funding declared, is the data sharing within agreed limits, and does anything in the arrangement engage export control or deemed export rules.

Should a company litigate or refer to law enforcement?

It depends on the objective and on disclosure tolerance. Civil proceedings give control, speed and injunctive relief, but discovery may require exposing the very secrets at issue and the process is expensive. Criminal referral shifts cost and carries deterrent weight, but the company loses control of tempo, disclosure and outcome, and prosecutors will select the clearest charge rather than the full loss. Many matters run both. The decision should be taken with the forensic evidence already secured, because the strength of the artefacts determines which route is viable at all.

What is the highest-value control for a small supplier?

Offboarding with preservation, followed by restricting access to the small number of genuinely critical files. Small suppliers to sensitive programmes are targeted precisely because they hold prime-contractor information without prime-contractor security resources. They cannot run behavioural analytics or full data loss prevention, but they can identify their crown jewels, restrict access to them, log transfers, and preserve devices and accounts when someone leaves. Those three steps address the dominant loss pathway at a cost that a small business can actually sustain.

Standards, frameworks and further reading

Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:

  • TRIPS Agreement article on protection of undisclosed information, which underpins trade secret protection across member states.
  • US Defend Trade Secrets Act and Economic Espionage Act, providing civil and criminal routes and defining the elements to be proved.
  • EU Trade Secrets Directive, harmonising the definition of trade secrets and the remedies available across member states.
  • NIST Special Publication 800-171 on protecting controlled unclassified information in non-federal systems, widely imposed through defence contracts.
  • ISO 27001 information security management, and ISO 27002 control guidance, as the general control framework for information protection.
  • US Export Administration Regulations deemed export rules, governing release of controlled technology to foreign persons.
  • National investment screening regimes, including CFIUS in the United States and the UK National Security and Investment Act, governing transaction review.
  • MITRE ATT&CK as the de facto standard vocabulary for describing intrusion tradecraft in technical reporting.

References

Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Economic espionage and trade secret prosecutions — US Department of Justice. Public case records detailing collection tradecraft and evidence relied on.
  2. Protective security guidance for research and industry — UK National Cyber Security Centre. Practical control guidance for protecting research and intellectual property.
  3. ATT&CK knowledge base — MITRE. Structured catalogue of adversary techniques used in intrusion reporting.
  4. Protecting controlled unclassified information — NIST. Control requirements imposed on suppliers handling sensitive government information.
  5. Patent and assignment records — US Patent and Trademark Office. Primary data for detecting technology transfer through filings and ownership changes.
  6. PATENTSCOPE international filing data — World Intellectual Property Organization. Cross-jurisdiction patent search supporting technology tracking.
  7. Threat landscape reports — ENISA. European analysis of intrusion activity targeting industry and research.
  8. Research security and technology competition analysis — Australian Strategic Policy Institute. Open-source institutional mapping methodology for research partnerships.
  9. Deemed export and technology transfer guidance — US Bureau of Industry and Security. Rules governing release of controlled technology to foreign persons.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this entry: correlates insider indicators, partner structures and technology targeting into a defensible counterintelligence picture. Explore the platform, or browse the rest of the library by following any tag above.

Leave a Reply

Your email address will not be published. Required fields are marked *